@iov/encoding
Encoding helpers for IOV projects
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-removed | AI (maintainer-change): Maintainer changes are within the same IOV SAS organization; publisher iovdave has 139 approved packages and the new maintainer uses the same @iov.one domain. Consistent with internal team restructuring. | ai | |
| provenance | publisher-changed | AI (provenance): Publisher change to albert.andrejev reflects a legitimate IOV SAS organizational transition; albert.andrejev has 130 approved packages and strong track record. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): New maintainers abefernan and albert.andrejev are part of the IOV SAS org; albert.andrejev has an established, clean publishing history. | ai | |
| dependencies | unvetted-dep:readonly-date | AI (dependencies): readonly-date is a minimal utility dependency; stable across versions and poses no material risk. | ai | |
| email-domain | unclaimed-email:iov.one | AI (email-domain): Unclaimed domain risk is stable across versions; publisher has 128 approved packages with no rejections, indicating established legitimacy. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New @cosmjs dependencies are a legitimate refactoring consolidating encoding utilities; all are established packages in the Cosmos ecosystem. | ai |
Versions (showing 55 of 55)
| Version | Deps | Published |
|---|---|---|
| 2.5.0 | 4 / 0 | |
| 2.3.2 | 4 / 2 | |
| 2.2.0 | 4 / 2 | |
| 2.0.2 | 4 / 1 | |
| 2.0.0 | 4 / 1 | |
| 1.2.0 | 4 / 1 | |
| 1.1.0 | 4 / 1 | |
| 1.0.0 | 4 / 1 | |
| 0.17.8 | 4 / 1 | |
| 0.17.7 | 4 / 1 | |
| 0.17.6 | 4 / 1 | |
| 0.17.5 | 4 / 1 | |
| 0.17.4 | 4 / 1 | |
| 0.17.3 | 4 / 1 | |
| 0.17.2 | 4 / 1 | |
| 0.17.1 | 4 / 1 | |
| 0.17.0 | 4 / 1 | |
| 0.16.3 | 4 / 1 | |
| 0.16.2 | 4 / 1 | |
| 0.16.1 | 4 / 1 | |
| 0.16.0 | 4 / 1 | |
| 0.15.0 | 4 / 2 | |
| 0.14.5 | 4 / 2 | |
| 0.14.4 | 4 / 2 | |
| 0.14.3 | 4 / 2 | |
| 0.14.2 | 4 / 2 | |
| 0.14.1 | 4 / 2 | |
| 0.14.0 | 4 / 2 | |
| 0.13.8 | 4 / 2 | |
| 0.13.7 | 4 / 2 | |
| 0.13.6 | 4 / 2 | |
| 0.13.5 | 4 / 2 | |
| 0.13.4 | 4 / 2 | |
| 0.13.3 | 4 / 2 | |
| 0.13.2 | 4 / 2 | |
| 0.13.1 | 4 / 2 | |
| 0.13.0 | 4 / 2 | |
| 0.12.3 | 4 / 2 | |
| 0.12.0 | 4 / 2 | |
| 0.11.0 | 4 / 2 | |
| 0.10.4 | 4 / 2 | |
| 0.10.1 | 4 / 2 | |
| 0.10.0 | 4 / 2 | |
| 0.9.0 | 4 / 2 | |
| 0.8.0 | 4 / 2 | |
| 0.7.1 | 4 / 2 | |
| 0.7.0 | 4 / 2 | |
| 0.6.0 | 2 / 1 | |
| 0.5.3 | 2 / 1 | |
| 0.5.2 | 2 / 1 | |
| 0.5.0 | 2 / 1 | |
| 0.4.0 | 2 / 1 | |
| 0.3.1 | 2 / 1 | |
| 0.3.0 | 2 / 1 | |
| 0.2.0 | 2 / 1 |
v2.5.0
2 findingsMaintainer email '[email protected]' uses domain 'iov.one' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.2
2 findingsThis version was published by a different npm account than previous versions on 2020-02-14. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.0
2 findingsThis version was published by a different npm account than previous versions on 2020-02-13. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2019-11-27. This could indicate a legitimate maintainer transition or an account compromise.
v1.1.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.