← Home

ox

Ethereum Standard Library

70
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

jmoxeyawkweb

Keywords

ethereumstandardlibrarytypescriptevm

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff encoded-string-file:src/tempo/SignatureEnvelope.test.ts AI (source-diff): Hex serialization test fixtures, not payloads. ai
source-diff encoded-string-file:src/tempo/KeyAuthorization.test.ts AI (source-diff): Hex crypto test fixtures (RLP/signature snapshots), not payloads. ai
dependencies unvetted-dep:nclosure AI (dependencies): Legitimate old dependency of this legacy package. ai
semgrep semgrep:new-function-constructor AI (semgrep): Legacy socket.io bundled dependency code, not package's own logic. ai
semgrep semgrep:child-process-import AI (semgrep): Core function of an online terminal/remote-shell tool, not hidden execution. ai
source-diff encoded-string-file:src/core/_test/AbiParameters.decode.test.ts AI (source-diff): Long hex strings are ABI-encoding test vectors, not payloads; stable for this crypto library. ai
publish-pattern new-deps-added AI (publish-pattern): zod is an established validation lib powering ox/zod schema exports. ai
source-diff large-new-source-files AI (source-diff): 1.0 release expands zod schemas + trusted-setup data; not injected code. ai
semgrep semgrep:shady-links-raw-ip AI (semgrep): Raw IP is a test fixture (127.0.0.1:3000) in Siwe.test.ts; stable FP. ai
source-diff obfuscated-file:_esm/erc6492/WrappedSignature.js AI (source-diff): Long line is inline EVM bytecode hex constant for ERC-6492 validator, not obfuscation. ai
source-diff obfuscated-file:erc6492/WrappedSignature.ts AI (source-diff): Long line is inline EVM bytecode hex constant in TS source, not obfuscation. ai
source-diff obfuscated-file:_types/erc6492/WrappedSignature.d.ts AI (source-diff): Long line is inline EVM bytecode hex constant in type decl, not obfuscation. ai
source-diff obfuscated-file:_cjs/erc6492/WrappedSignature.js AI (source-diff): Long line is inline EVM bytecode hex constant for ERC-6492 validator, not obfuscation. ai
source-diff encoded-string-file:_types/erc6492/WrappedSignature.d.ts AI (source-diff): EVM contract bytecode constant for ERC-6492 verification; not obfuscation. ai
source-diff encoded-string-file:_cjs/erc6492/WrappedSignature.js AI (source-diff): EVM contract bytecode constant for ERC-6492 verification; not obfuscation. ai
source-diff encoded-string-file:_esm/erc6492/WrappedSignature.js AI (source-diff): EVM contract bytecode constant for ERC-6492 verification; not obfuscation. ai
source-diff encoded-string-file:erc6492/WrappedSignature.ts AI (source-diff): EVM contract bytecode constant for ERC-6492 verification; not obfuscation. ai
npm-metadata suspicious-initial-version AI (npm-metadata): Legacy placeholder publish for long-established, high-download package. ai
bogus-package bogus-package AI (bogus-package): Empty stub metadata is historical, package is a trusted long-lived project. ai
source-diff encoded-string-file:tempo/SignatureEnvelope.test.ts AI (source-diff): Hex-encoded Ethereum signature fixtures in test files; normal for this package. ai
source-diff encoded-string-file:_esm/tempo/index.js AI (source-diff): Hex-encoded Ethereum tx data in JSDoc examples, not executable payload; stable for this package. ai
source-diff encoded-string-file:tempo/index.ts AI (source-diff): Same JSDoc example hex strings in source; stable false positive. ai
semgrep semgrep:shady-links-tlds AI (semgrep): tempo.xyz is the project's own domain; .xyz TLD is legitimate here. ai
source-diff encoded-string-file:_types/tempo/index.d.ts AI (source-diff): Same JSDoc example hex strings in type declarations; stable false positive. ai
typosquat typosquat.levenshtein:mobx AI (typosquat): 'ox' is a legitimate established package; short-name Levenshtein matches are noise. ai
typosquat typosquat.levenshtein:koa AI (typosquat): 'ox' is a legitimate established package; short-name Levenshtein matches are noise. ai
semgrep semgrep:dynamic-require AI (semgrep): Standard worker_threads lazy-load pattern in a WASM worker pool; not arbitrary code execution. ai
typosquat typosquat.levenshtein:zod AI (typosquat): 'ox' is a legitimate established package; short-name Levenshtein matches are noise. ai
typosquat typosquat.levenshtein:joi AI (typosquat): 'ox' is a legitimate established package; short-name Levenshtein matches are noise. ai
typosquat typosquat.levenshtein:qs AI (typosquat): 'ox' is a legitimate established package; short-name Levenshtein matches are noise. ai
typosquat typosquat.levenshtein:pg AI (typosquat): 'ox' is a legitimate established package; short-name Levenshtein matches are noise. ai
typosquat typosquat.levenshtein:got AI (typosquat): 'ox' is a legitimate established package; short-name Levenshtein matches are noise. ai

Versions (showing 70 of 70)

Version Deps Published
1.0.3 9 / 0
1.0.2 9 / 0
1.0.1 9 / 0
1.0.0 9 / 0
0.14.33 8 / 0
0.14.32 8 / 0
0.14.31 8 / 0
0.14.30 8 / 0
0.14.29 8 / 0
0.14.28 8 / 0
0.14.27 8 / 0
0.14.26 8 / 0
0.14.25 8 / 0
0.14.24 8 / 0
0.14.23 8 / 0
0.14.22 8 / 0
0.14.21 8 / 0
0.14.20 8 / 0
0.14.16 8 / 0
0.14.11 8 / 0
0.14.8 8 / 0
0.14.5 8 / 0
0.14.1 8 / 0
0.12.4 8 / 0
0.12.0 8 / 0
0.9.10 8 / 0
0.9.9 8 / 0
0.9.4 8 / 0
0.8.7 8 / 0
0.8.6 8 / 0
0.8.5 8 / 0
0.8.4 8 / 0
0.8.3 8 / 0
0.8.2 8 / 0
0.7.1 8 / 0
0.7.0 7 / 0
0.6.12 7 / 0
0.6.11 7 / 0
0.6.10 7 / 0
0.6.9 7 / 0
0.6.8 7 / 0
0.6.7 7 / 0
0.6.6 7 / 0
0.6.5 7 / 0
0.6.4 7 / 0
0.6.3 7 / 0
0.6.2 7 / 0
0.6.1 7 / 0
0.6.0 7 / 0
0.5.0 7 / 0
0.4.3 7 / 0
0.4.2 7 / 0
0.4.1 7 / 0
0.4.0 7 / 0
0.3.1 7 / 0
0.3.0 7 / 0
0.2.2 7 / 0
0.2.1 7 / 0
0.2.0 7 / 0
0.1.8 7 / 0
0.1.7 7 / 0
0.1.6 7 / 0
0.1.5 7 / 0
0.1.4 7 / 0
0.1.3 7 / 0
0.1.2 7 / 0
0.1.1 7 / 0
0.1.0 7 / 0
0.0.1 2 / 0
0.0.0 0 / 0

v1.0.3

3 findings
HIGH Provenance attestation missing — previous versions had it provenance

This version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.

HIGH Long encoded string in modified file: src/tempo/KeyAuthorization.test.ts source-diff

Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: src/tempo/SignatureEnvelope.test.ts source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

v1.0.2

1 finding
HIGH Provenance attestation missing — previous versions had it provenance

This version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.

v1.0.1

2 findings
HIGH Provenance attestation missing — previous versions had it provenance

This version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.

HIGH Long encoded string in modified file: src/core/_test/AbiParameters.decode.test.ts source-diff

Modified file contains 37 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

v1.0.0

2 findings
HIGH Provenance attestation missing — previous versions had it provenance

This version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.

HIGH shady-links-raw-ip: src/core/_test/Siwe.test.ts:404 semgrep

HTTP request to raw IP address — legitimate packages use domain names 402 | 'http://example.com:3000', 403 | 'http://localhost:3000', > 404 | 'http://127.0.0.1:3000', 405 | 'foobarbaz', 406 | '-example.com',

v0.14.33

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.14.32

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.14.31

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.14.30

2 findings
HIGH Long encoded string in modified file: tempo/SignatureEnvelope.test.ts source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.0

3 findings
HIGH Long encoded string in modified file: _cjs/erc6492/WrappedSignature.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _esm/erc6492/WrappedSignature.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.12

3 findings
HIGH Long encoded string in modified file: _cjs/erc6492/WrappedSignature.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _esm/erc6492/WrappedSignature.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.11

3 findings
HIGH Long encoded string in modified file: _cjs/erc6492/WrappedSignature.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _esm/erc6492/WrappedSignature.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.10

3 findings
HIGH Long encoded string in modified file: _cjs/erc6492/WrappedSignature.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _esm/erc6492/WrappedSignature.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.9

3 findings
HIGH Long encoded string in modified file: _cjs/erc6492/WrappedSignature.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _esm/erc6492/WrappedSignature.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.8

3 findings
HIGH Long encoded string in modified file: _cjs/erc6492/WrappedSignature.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _esm/erc6492/WrappedSignature.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.7

3 findings
HIGH Long encoded string in modified file: _cjs/erc6492/WrappedSignature.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _esm/erc6492/WrappedSignature.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.6

3 findings
HIGH Long encoded string in modified file: _cjs/erc6492/WrappedSignature.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _esm/erc6492/WrappedSignature.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.5

3 findings
HIGH Long encoded string in modified file: _cjs/erc6492/WrappedSignature.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _esm/erc6492/WrappedSignature.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.4

3 findings
HIGH Long encoded string in modified file: _cjs/erc6492/WrappedSignature.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _esm/erc6492/WrappedSignature.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.3

3 findings
HIGH Long encoded string in modified file: _cjs/erc6492/WrappedSignature.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _esm/erc6492/WrappedSignature.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.2

3 findings
HIGH Long encoded string in modified file: _cjs/erc6492/WrappedSignature.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _esm/erc6492/WrappedSignature.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.1

3 findings
HIGH Long encoded string in modified file: _cjs/erc6492/WrappedSignature.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _esm/erc6492/WrappedSignature.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.0

5 findings
HIGH Long encoded string in modified file: _cjs/erc6492/WrappedSignature.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _esm/erc6492/WrappedSignature.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _types/erc6492/WrappedSignature.d.ts source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: erc6492/WrappedSignature.ts source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.0

5 findings
HIGH Long encoded string in modified file: _cjs/erc6492/WrappedSignature.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _esm/erc6492/WrappedSignature.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _types/erc6492/WrappedSignature.d.ts source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: erc6492/WrappedSignature.ts source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.3

5 findings
HIGH Long encoded string in modified file: _cjs/erc6492/WrappedSignature.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _esm/erc6492/WrappedSignature.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _types/erc6492/WrappedSignature.d.ts source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: erc6492/WrappedSignature.ts source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.2

5 findings
HIGH New obfuscated file: _cjs/erc6492/WrappedSignature.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: _esm/erc6492/WrappedSignature.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: _types/erc6492/WrappedSignature.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: erc6492/WrappedSignature.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.