web3-core-helpers
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-takeover | AI (maintainer-change): Historical 2020 transition, stable on npm 2278 days; not a live takeover. | ai | |
| provenance | publisher-changed-stale | AI (provenance): Same 2020 event, long-stable, generalizes across versions. | ai | |
| dependencies | unvetted-dep:web3-utils | AI (dependencies): web3-utils is a sibling package in the web3.js monorepo; coordinated versioning at 1.10.4 is expected and not a risk signal. | ai | |
| dependencies | unvetted-dep:web3-eth-iban | AI (dependencies): web3-eth-iban is a sibling package in the web3.js monorepo; coordinated versioning at 1.10.4 is expected and not a risk signal. | ai |
Versions (showing 42 of 42)
| Version | Deps | Published |
|---|---|---|
| 1.10.4 | 2 / 3 | |
| 1.10.3 | 2 / 3 | |
| 1.10.2 | 2 / 3 | |
| 1.10.1 | 2 / 3 | |
| 1.10.0 | 2 / 3 | |
| 1.9.0 | 2 / 3 | |
| 1.8.2 | 2 / 3 | |
| 1.8.1 | 2 / 3 | |
| 1.8.0 | 2 / 3 | |
| 1.7.5 | 2 / 3 | |
| 1.7.4 | 2 / 3 | |
| 1.7.3 | 2 / 3 | |
| 1.7.2 | 2 / 3 | |
| 1.7.1 | 2 / 3 | |
| 1.7.0 | 2 / 3 | |
| 1.6.1 | 2 / 3 | |
| 1.6.0 | 2 / 3 | |
| 1.5.3 | 2 / 3 | |
| 1.5.2 | 2 / 3 | |
| 1.5.1 | 2 / 3 | |
| 1.5.0 | 2 / 3 | |
| 1.4.0 | 3 / 3 | |
| 1.3.6 | 3 / 3 | |
| 1.3.5 | 3 / 3 | |
| 1.3.4 | 3 / 3 | |
| 1.3.3 | 3 / 3 | |
| 1.3.2 | 3 / 3 | |
| 1.3.1 | 3 / 3 | |
| 1.3.0 | 3 / 3 | |
| 1.2.11 | 3 / 3 | |
| 1.2.10 | 3 / 3 | |
| 1.2.9 | 3 / 3 | |
| 1.2.8 | 3 / 3 | |
| 1.2.7 | 3 / 3 | |
| 1.2.6 | 3 / 3 | |
| 1.2.5 | 3 / 3 | |
| 1.2.4 | 3 / 3 | |
| 1.2.3 | 3 / 3 | |
| 1.2.2 | 3 / 2 | |
| 1.2.1 | 3 / 0 | |
| 1.2.0 | 3 / 0 | |
| 1.0.0 | 3 / 0 |
v1.10.2
2 findingsThis version was published by a different npm account (jdevcs) than the most recent previously approved version (nivida) on 2023-08-28. It has since remained available on npm for 1058 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.1
2 findingsThis version was published by a different npm account (jdevcs) than the most recent previously approved version (nivida) on 2023-08-14. It has since remained available on npm for 1072 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.0
2 findingsThis version was published by a different npm account (jdevcs) than the most recent previously approved version (nivida) on 2023-05-10. It has since remained available on npm for 1167 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.0
2 findingsThis version was published by a different npm account (jdevcs) than the most recent previously approved version (nivida) on 2023-03-20. It has since remained available on npm for 1218 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.8.2
2 findingsThis version was published by a different npm account (jdevcs) than the most recent previously approved version (nivida) on 2023-01-30. It has since remained available on npm for 1267 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.8.1
2 findingsThis version was published by a different npm account (jdevcs) than the most recent previously approved version (nivida) on 2022-11-10. It has since remained available on npm for 1348 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.8.0
2 findingsThis version was published by a different npm account (jdevcs) than the most recent previously approved version (nivida) on 2022-09-14. It has since remained available on npm for 1406 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.5
2 findingsThis version was published by a different npm account (jdevcs) than the most recent previously approved version (nivida) on 2022-08-01. It has since remained available on npm for 1450 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.4
2 findingsThis version was published by a different npm account (jdevcs) than the most recent previously approved version (nivida) on 2022-06-21. It has since remained available on npm for 1490 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.3
2 findingsThis version was published by a different npm account (jdevcs) than the most recent previously approved version (nivida) on 2022-04-08. It has since remained available on npm for 1565 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.2
2 findingsThis version was published by a different npm account (jdevcs) than the most recent previously approved version (nivida) on 2022-04-07. It has since remained available on npm for 1565 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.1
2 findingsThis version was published by a different npm account (spacesailor) than the most recent previously approved version (nivida) on 2022-03-03. It has since remained available on npm for 1601 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.0
2 findingsThis version was published by a different npm account (spacesailor) than the most recent previously approved version (nivida) on 2022-01-17. It has since remained available on npm for 1645 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.1
2 findingsThis version was published by a different npm account (spacesailor) than the most recent previously approved version (nivida) on 2021-11-15. It has since remained available on npm for 1708 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.0
2 findingsThis version was published by a different npm account (spacesailor) than the most recent previously approved version (nivida) on 2021-09-30. It has since remained available on npm for 1754 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.3
2 findingsThis version was published by a different npm account (spacesailor) than the most recent previously approved version (nivida) on 2021-09-22. It has since remained available on npm for 1763 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.2
2 findingsThis version was published by a different npm account (spacesailor) than the most recent previously approved version (nivida) on 2021-08-15. It has since remained available on npm for 1801 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.1
2 findingsThis version was published by a different npm account (spacesailor) than the most recent previously approved version (nivida) on 2021-08-05. It has since remained available on npm for 1810 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.0
2 findingsThis version was published by a different npm account (spacesailor) than the most recent previously approved version (nivida) on 2021-07-28. It has since remained available on npm for 1818 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.0
2 findingsThis version was published by a different npm account (spacesailor) than the most recent previously approved version (nivida) on 2021-06-30. It has since remained available on npm for 1846 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.6
2 findingsThis version was published by a different npm account (spacesailor) than the most recent previously approved version (nivida) on 2021-05-14. It has since remained available on npm for 1894 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.5
2 findingsThis version was published by a different npm account (spacesailor) than the most recent previously approved version (nivida) on 2021-04-05. It has since remained available on npm for 1932 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.4
2 findingsThis version was published by a different npm account (gregthegreek) than the most recent previously approved version (nivida) on 2021-02-03. It has since remained available on npm for 1993 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.3
2 findingsThis version was published by a different npm account (gregthegreek) than the most recent previously approved version (nivida) on 2021-01-22. It has since remained available on npm for 2005 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.2
2 findingsThis version was published by a different npm account (gregthegreek) than the most recent previously approved version (nivida) on 2021-01-21. It has since remained available on npm for 2006 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.1
2 findingsThis version was published by a different npm account (gregthegreek) than the most recent previously approved version (nivida) on 2020-12-17. It has since remained available on npm for 2041 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.0
2 findingsThis version was published by a different npm account (gregthegreek) than the most recent previously approved version (nivida) on 2020-09-15. It has since remained available on npm for 2134 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.11
2 findingsThis version was published by a different npm account (ralxz) than the most recent previously approved version (nivida) on 2020-07-18. It has since remained available on npm for 2193 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.10
2 findingsThis version was published by a different npm account (ralxz) than the most recent previously approved version (nivida) on 2020-07-17. It has since remained available on npm for 2194 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.9
2 findingsThis version was published by a different npm account (ralxz) than the most recent previously approved version (nivida) on 2020-06-09. It has since remained available on npm for 2232 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.8
2 findingsThis version was published by a different npm account (ralxz) than the most recent previously approved version (nivida) on 2020-05-20. It has since remained available on npm for 2252 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.7
2 findingsThis version was published by a different npm account (ralxz) than the most recent previously approved version (nivida) on 2020-04-24. It has since remained available on npm for 2278 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.