@polkadot/util
A collection of useful utilities for @polkadot
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@types/camelcase | AI (dependencies): @types/camelcase is the TypeScript type definitions for the well-known camelcase package; it is benign and consistent with this package's pattern of listing @types/* as runtime deps. | ai | |
| phantom-deps | phantom-dep:@types/camelcase | AI (phantom-deps): Listing @types/* packages as runtime deps without direct imports is a known pattern in this Polkadot TypeScript package; other @types/* phantom deps are already accepted. | ai | |
| phantom-deps | phantom-dep:@types/ip-regex | AI (phantom-deps): @types packages are TypeScript type declarations consumed by tooling, not direct imports; phantom-dep firing on them is a stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@types/xxhashjs | AI (phantom-deps): @types packages are TypeScript type declarations consumed by tooling, not direct imports; phantom-dep firing on them is a stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@types/deasync | AI (phantom-deps): @types packages are TypeScript type declarations consumed by tooling, not direct imports; phantom-dep firing on them is a stable false positive for this package. | ai | |
| dependencies | unvetted-dep:@types/ip-regex | AI (dependencies): @types/ip-regex is a DefinitelyTyped TypeScript type definition package — benign by nature, no runtime code execution risk. | ai | |
| dependencies | unvetted-dep:@types/xxhashjs | AI (dependencies): @types/xxhashjs is a DefinitelyTyped TypeScript type definition package — benign by nature, no runtime code execution risk. | ai | |
| provenance | missing-githead | AI (provenance): Package is from a highly trusted publisher (jacogr, 8095 approved/0 rejected) with a 3000+ day history. Missing gitHead reflects a publish environment change, not a security concern for this package. | ai | |
| source-diff | large-new-source-files | AI (source-diff): @polkadot/util is an actively developed utility library; adding new source files across minor versions is expected organic growth, not injected code. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): bn.js and keccak are well-established cryptographic libraries appropriate for a blockchain utility package; their addition is expected and legitimate. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size increase reflects legitimate addition of crypto utilities (bn.js, keccak wrappers) in a growing blockchain utility library from a trusted publisher. | ai | |
| dependencies | unvetted-dep:keccak | AI (dependencies): keccak is a well-known cryptographic hash library standard in the blockchain/Ethereum ecosystem; legitimate dependency for @polkadot/util. | ai | |
| provenance | no-provenance | AI (provenance): Package predates Sigstore provenance adoption; publisher has 8083 approved packages and strong trust history. Not a meaningful risk signal here. | ai | |
| phantom-deps | phantom-dep:babel-runtime | AI (phantom-deps): babel-runtime is a legitimate runtime dependency used via babel-plugin-transform-runtime (Babel 6 pattern); not a phantom dep for this package. | ai | |
| provenance | publisher-changed | AI (provenance): paritytech-ci is Parity Technologies' CI publishing account with 111 approved packages; the polkadotjs→paritytech-ci transition is a known organizational consolidation, not a compromise. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): paritytech-ci is a verified Parity Technologies CI account with strong track record; addition is a legitimate organizational change. | ai | |
| phantom-deps | phantom-dep:@types/bn.js | AI (phantom-deps): @types/bn.js is a TypeScript type definition used by convention in the polkadot-js ecosystem; phantom dep finding is a stable false positive here. | ai | |
| semgrep | semgrep:hex-decode | AI (semgrep): Hex decoding is core functionality of @polkadot/util; Buffer.from(value, 'hex') is a standard, non-obfuscated utility operation. | ai | |
| typosquat | typosquat.levenshtein:uuid | AI (typosquat): @polkadot/util is a well-known Polkadot ecosystem utility library, not a typosquat of uuid. The name similarity is purely coincidental. | ai |
Versions (showing 100 of 551)
| Version | Deps | Published |
|---|---|---|
| 7.2.1 | 7 / 0 | |
| 7.1.2 | 7 / 0 | |
| 7.1.1 | 7 / 0 | |
| 7.0.3 | 7 / 0 | |
| 7.0.2 | 7 / 0 | |
| 7.0.1 | 7 / 0 | |
| 6.11.1 | 7 / 0 | |
| 6.10.1 | 7 / 0 | |
| 6.9.1 | 7 / 0 | |
| 6.8.1 | 7 / 0 | |
| 6.7.1 | 7 / 0 | |
| 6.6.1 | 7 / 0 | |
| 6.5.1 | 7 / 0 | |
| 6.4.1 | 7 / 0 | |
| 6.3.1 | 7 / 0 | |
| 6.2.1 | 7 / 0 | |
| 6.1.1 | 7 / 0 | |
| 6.0.5 | 7 / 0 | |
| 6.0.4 | 7 / 0 | |
| 6.0.3 | 7 / 0 | |
| 6.0.2 | 7 / 0 | |
| 6.0.1 | 7 / 0 | |
| 5.9.2 | 7 / 0 | |
| 5.9.1 | 7 / 0 | |
| 5.8.1 | 7 / 0 | |
| 5.7.1 | 7 / 0 | |
| 5.6.3 | 7 / 0 | |
| 5.6.2 | 7 / 0 | |
| 5.6.1 | 7 / 0 | |
| 5.5.2 | 7 / 0 | |
| 5.5.1 | 7 / 0 | |
| 5.4.4 | 7 / 0 | |
| 5.4.3 | 7 / 0 | |
| 5.4.2 | 7 / 0 | |
| 5.4.1 | 7 / 0 | |
| 5.3.1 | 7 / 0 | |
| 5.2.3 | 7 / 0 | |
| 5.2.2 | 7 / 0 | |
| 5.2.1 | 7 / 0 | |
| 5.1.1 | 7 / 0 | |
| 5.0.1 | 7 / 0 | |
| 4.2.1 | 7 / 0 | |
| 4.1.1 | 7 / 0 | |
| 4.0.1 | 7 / 0 | |
| 3.7.1 | 7 / 0 | |
| 3.6.1 | 8 / 0 | |
| 3.5.1 | 8 / 0 | |
| 3.4.1 | 6 / 0 | |
| 3.3.1 | 6 / 0 | |
| 3.2.1 | 6 / 0 | |
| 3.1.1 | 6 / 0 | |
| 3.0.1 | 6 / 0 | |
| 2.18.1 | 6 / 0 | |
| 2.17.1 | 6 / 0 | |
| 2.16.1 | 6 / 0 | |
| 2.15.1 | 6 / 0 | |
| 2.14.1 | 6 / 0 | |
| 2.13.1 | 6 / 0 | |
| 2.12.2 | 6 / 0 | |
| 2.12.1 | 6 / 0 | |
| 2.11.1 | 6 / 0 | |
| 2.10.1 | 6 / 0 | |
| 2.9.1 | 6 / 0 | |
| 2.8.1 | 6 / 0 | |
| 2.7.1 | 6 / 0 | |
| 2.6.2 | 6 / 0 | |
| 2.6.1 | 6 / 0 | |
| 2.5.1 | 6 / 0 | |
| 2.4.1 | 6 / 0 | |
| 2.3.1 | 5 / 1 | |
| 2.2.1 | 7 / 0 | |
| 2.1.1 | 7 / 0 | |
| 2.0.1 | 7 / 0 | |
| 1.8.1 | 7 / 0 | |
| 1.7.1 | 7 / 0 | |
| 1.6.1 | 7 / 0 | |
| 1.5.1 | 7 / 0 | |
| 1.4.1 | 7 / 0 | |
| 1.3.1 | 7 / 0 | |
| 1.2.1 | 7 / 0 | |
| 1.1.1 | 7 / 0 | |
| 1.0.1 | 7 / 0 | |
| 0.94.1 | 8 / 0 | |
| 0.93.1 | 8 / 0 | |
| 0.92.1 | 8 / 0 | |
| 0.91.1 | 8 / 0 | |
| 0.90.1 | 9 / 0 | |
| 0.76.1 | 9 / 0 | |
| 0.75.1 | 9 / 0 | |
| 0.43.1 | 9 / 0 | |
| 0.42.1 | 9 / 0 | |
| 0.41.1 | 9 / 0 | |
| 0.40.1 | 9 / 0 | |
| 0.39.1 | 9 / 0 | |
| 0.38.1 | 11 / 0 | |
| 0.37.1 | 11 / 0 | |
| 0.36.3 | 11 / 0 | |
| 0.36.2 | 11 / 0 | |
| 0.36.1 | 11 / 0 | |
| 0.35.10 | 11 / 0 |
v7.2.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.1.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.1.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.0.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.0.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.0.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.11.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.10.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.9.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.8.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.7.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.6.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.5.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.4.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.3.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.2.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.1.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.0.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.0.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.0.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.0.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.0.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.9.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.9.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.8.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.7.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.6.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.6.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.6.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.5.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.5.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.4.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.4.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.4.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.4.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.3.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.2.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.2.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.2.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.1.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.0.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.2.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.1.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.7.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.6.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.4.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.3.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.1
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2020-08-17. This could indicate a legitimate maintainer transition or an account compromise.
v3.1.1
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2020-08-10. This could indicate a legitimate maintainer transition or an account compromise.
v3.0.1
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2020-07-27. This could indicate a legitimate maintainer transition or an account compromise.
v2.18.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.17.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.16.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.15.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.14.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.12.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.12.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.11.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.9.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.8.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.7.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.6.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.6.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.5.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.4.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.8.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.94.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.93.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.92.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.91.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.90.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.76.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.75.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.43.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.42.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.41.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.40.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.39.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.38.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.37.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.36.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.36.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.36.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.35.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.