← Home

micro-eth-signer

34
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

paulmillr

Keywords

ethereumethcreatesignvalidatetransactionaddresstxweb3ethersmicronanosigner

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:micro-rlp AI (dependencies): Author's own sibling library, standard dep for this early version. ai
source-diff obfuscated-file:advanced/clearsig-repo-full.js AI (source-diff): Auto-generated ERC-7730 registry JSON data, not obfuscation; stable pattern for this package. ai
source-diff obfuscated-file:advanced/clearsig-repo.js AI (source-diff): Auto-generated ERC-7730 registry JSON data, not obfuscation; stable pattern for this package. ai
source-diff obfuscated-file:src/advanced/clearsig-repo-full.ts AI (source-diff): TypeScript source of auto-generated registry data; stable pattern. ai
semgrep semgrep:shady-links-tlds AI (semgrep): DeFi protocol URLs in registry data, not C2 endpoints; stable for this package. ai
source-diff encoded-string-file:advanced/abi.js AI (source-diff): Hex-encoded Ethereum tx in JSDoc example, not a hidden payload. ai
source-diff obfuscated-file:src/advanced/clearsig-repo.ts AI (source-diff): TypeScript source of auto-generated registry data; stable pattern. ai
dependencies unvetted-dep:micro-packed AI (dependencies): micro-packed is a legitimate dependency by the same author (Paul Miller); used for binary encoding in Ethereum transaction handling. Stable false positive for this package. ai

Versions (showing 34 of 34)

Version Deps Published
0.19.0 4 / 8
0.18.1 3 / 8
0.17.3 3 / 8
0.17.2 3 / 8
0.17.1 3 / 8
0.17.0 3 / 8
0.16.0 3 / 10
0.15.0 3 / 9
0.14.0 3 / 9
0.13.3 3 / 9
0.13.1 3 / 9
0.13.0 3 / 9
0.12.2 3 / 9
0.12.1 3 / 9
0.12.0 3 / 9
0.11.0 3 / 8
0.10.0 3 / 8
0.9.1 3 / 7
0.9.0 3 / 7
0.6.5 3 / 4
0.6.4 3 / 4
0.6.3 3 / 4
0.6.2 3 / 4
0.6.1 3 / 4
0.6.0 3 / 7
0.5.1 3 / 7
0.5.0 3 / 7
0.4.8 3 / 7
0.4.7 3 / 6
0.4.2 3 / 6
0.2.1 3 / 6
0.1.6 3 / 6
0.1.2 3 / 6
0.1.1 3 / 6

v0.14.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.13.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.13.1

1 finding
HIGH Provenance attestation missing — previous versions had it provenance

This version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. The axios attack (March 2026) exhibited exactly this pattern.

v0.13.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.11.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.10.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.9.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.9.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v0.6.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.4.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.4.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.