@wireio/opp-solidity-models
Auto-generated protobuf types for Solidity
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | no-provenance | AI (provenance): Provenance attestation absence is a hygiene concern, not a security risk for this package. | ai |
Versions (showing 33 of 33)
| Version | Deps | Published |
|---|---|---|
| 1.0.38 | 1 / 0 | |
| 1.0.37 | 1 / 0 | |
| 1.0.36 | 1 / 0 | |
| 1.0.35 | 1 / 0 | |
| 1.0.34 | 1 / 0 | |
| 1.0.33 | 1 / 0 | |
| 1.0.32 | 1 / 0 | |
| 1.0.31 | 1 / 0 | |
| 1.0.30 | 1 / 0 | |
| 1.0.29 | 1 / 0 | |
| 1.0.28 | 1 / 0 | |
| 1.0.27 | 1 / 0 | |
| 1.0.26 | 1 / 0 | |
| 1.0.25 | 1 / 0 | |
| 1.0.24 | 1 / 0 | |
| 1.0.23 | 1 / 0 | |
| 1.0.22 | 1 / 0 | |
| 1.0.21 | 1 / 0 | |
| 1.0.20 | 1 / 0 | |
| 1.0.19 | 1 / 0 | |
| 1.0.18 | 1 / 0 | |
| 1.0.17 | 1 / 0 | |
| 1.0.16 | 1 / 0 | |
| 1.0.15 | 1 / 0 | |
| 1.0.14 | 1 / 0 | |
| 1.0.13 | 1 / 0 | |
| 1.0.12 | 1 / 0 | |
| 1.0.11 | 1 / 0 | |
| 1.0.9 | 1 / 0 | |
| 1.0.8 | 1 / 0 | |
| 1.0.7 | 1 / 0 | |
| 1.0.6 | 0 / 0 | |
| 1.0.0 | 0 / 0 |
v1.0.38
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.37
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.36
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.35
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.34
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.33
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.32
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.31
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.30
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.29
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.28
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (wn-user) than the most recent previously approved version (jglanz) on 2026-06-30, but wn-user is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.0.27
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.