zksync-ethers
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | encoded-string-file:build/utils.js | AI (source-diff): Long hex strings are serialized Ethereum transaction examples in JSDoc comments, not obfuscated payloads. | ai | |
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): 127.0.0.1:3050 is the documented local ZKSync node default; stable false positive for this package. | ai |
Versions (showing 27 of 27)
| Version | Deps | Published |
|---|---|---|
| 6.21.2 | 0 / 16 | |
| 6.21.1 | 0 / 16 | |
| 6.16.2 | 0 / 16 | |
| 6.16.1 | 0 / 16 | |
| 6.16.0 | 0 / 16 | |
| 6.15.4 | 0 / 16 | |
| 6.15.3 | 0 / 16 | |
| 6.15.2 | 0 / 16 | |
| 6.15.1 | 0 / 16 | |
| 6.15.0 | 0 / 16 | |
| 6.14.3 | 0 / 16 | |
| 6.14.2 | 0 / 16 | |
| 6.14.1 | 0 / 16 | |
| 6.14.0 | 0 / 16 | |
| 6.13.1 | 0 / 16 | |
| 6.13.0 | 0 / 16 | |
| 6.12.1 | 0 / 16 | |
| 6.12.0 | 0 / 16 | |
| 6.11.2 | 0 / 16 | |
| 6.11.1 | 0 / 16 | |
| 6.11.0 | 0 / 16 | |
| 6.10.0 | 0 / 16 | |
| 6.9.0 | 0 / 16 | |
| 6.8.0 | 0 / 16 | |
| 6.7.1 | 0 / 16 | |
| 5.11.2 | 1 / 16 | |
| 5.11.1 | 1 / 16 |
v6.16.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.16.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.16.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.15.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.15.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.15.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.15.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.15.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.14.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.14.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.14.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.14.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.13.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.13.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.12.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.12.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.11.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.11.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.11.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.10.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.9.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.8.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.7.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.