@xyo-network/chain-orchestration
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Transition to org account 'xyo' with 3589 approved packages; consistent with org-level publishing consolidation for xylabs packages. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Growth reflects legitimate refactor adding first-party @xyo-network modules, not injected foreign code. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size increase consistent with adding 17 first-party deps and their source files in a monorepo refactor. | ai | |
| provenance | missing-githead | AI (provenance): High-volume trusted publisher; missing gitHead likely reflects CI pipeline change, not malicious publish. | ai | |
| dependencies | unvetted-dep:@xyo-network/chain-sdk | AI (dependencies): Same-org monorepo sibling at matching version; stable false positive for this package. | ai | |
| dependencies | unvetted-dep:@xyo-network/chain-orchestration-storage | AI (dependencies): Same-org monorepo sibling at matching version; stable false positive for this package. | ai | |
| dependencies | unvetted-dep:@xyo-network/chain-orchestration-evm | AI (dependencies): Same-org monorepo sibling at matching version; stable false positive for this package. | ai | |
| dependencies | unvetted-dep:@xyo-network/chain-services | AI (dependencies): Same-org monorepo sibling at matching version; stable false positive for this package. | ai |
Versions (showing 25 of 225)
| Version | Deps | Published |
|---|---|---|
| 1.5.8 | 14 / 6 | |
| 1.5.7 | 14 / 6 | |
| 1.5.6 | 14 / 6 | |
| 1.5.5 | 14 / 6 | |
| 1.5.4 | 14 / 6 | |
| 1.5.3 | 14 / 6 | |
| 1.5.2 | 14 / 6 | |
| 1.5.1 | 14 / 6 | |
| 1.5.0 | 14 / 6 | |
| 1.4.8 | 14 / 6 | |
| 1.4.7 | 14 / 6 | |
| 1.4.6 | 14 / 6 | |
| 1.4.5 | 14 / 6 | |
| 1.4.4 | 14 / 6 | |
| 1.4.3 | 14 / 6 | |
| 1.4.2 | 14 / 6 | |
| 1.4.0 | 14 / 6 | |
| 1.3.31 | 14 / 6 | |
| 1.3.30 | 14 / 6 | |
| 1.3.29 | 14 / 6 | |
| 1.3.28 | 14 / 6 | |
| 1.3.27 | 14 / 6 | |
| 1.3.26 | 14 / 6 | |
| 1.3.25 | 14 / 6 | |
| 1.3.24 | 15 / 6 |
v1.5.8
2 findingsThis version was published by a different npm account than previous versions on 2025-06-02. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.7
2 findingsThis version was published by a different npm account than previous versions on 2025-06-02. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.6
2 findingsThis version was published by a different npm account than previous versions on 2025-06-02. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.5
2 findingsThis version was published by a different npm account than previous versions on 2025-06-02. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.4
2 findingsThis version was published by a different npm account than previous versions on 2025-06-02. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.3
2 findingsThis version was published by a different npm account than previous versions on 2025-06-02. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.2
2 findingsThis version was published by a different npm account than previous versions on 2025-06-02. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.1
2 findingsThis version was published by a different npm account than previous versions on 2025-05-30. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.0
2 findingsThis version was published by a different npm account than previous versions on 2025-05-29. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.7
2 findingsThis version was published by a different npm account than previous versions on 2025-05-23. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.5
2 findingsThis version was published by a different npm account than previous versions on 2025-05-20. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.4
2 findingsThis version was published by a different npm account than previous versions on 2025-05-20. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.3
2 findingsThis version was published by a different npm account than previous versions on 2025-05-20. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2
2 findingsThis version was published by a different npm account than previous versions on 2025-05-20. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.0
2 findingsThis version was published by a different npm account than previous versions on 2025-05-20. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.31
2 findingsThis version was published by a different npm account than previous versions on 2025-05-20. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.30
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.29
2 findingsThis version was published by a different npm account than previous versions on 2025-05-16. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.28
2 findingsThis version was published by a different npm account than previous versions on 2025-05-15. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.27
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.26
2 findingsThis version was published by a different npm account than previous versions on 2025-05-15. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.25
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.24
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.