← Home

@truffle/compile-solidity

Compiler helper and artifact manager for Solidity files

1
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

rizedrjoshuafernandescliffookevinbluergnidanhaltmaneggplantzzzfainashaltscds-amal

Keywords

compileethereumsoliditytruffle

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:child-process-import AI (semgrep): execSync used in Native.ts to invoke system solc binary; expected behavior for a Solidity compiler package. ai
dependencies unvetted-dep:@truffle/config AI (dependencies): First-party @truffle scoped package from the same monorepo; stable false positive. ai
dependencies unvetted-dep:@truffle/expect AI (dependencies): First-party @truffle scoped package from the same monorepo; stable false positive. ai
dependencies unvetted-dep:@truffle/profiler AI (dependencies): First-party @truffle scoped package from the same monorepo; stable false positive. ai
dependencies unvetted-dep:@truffle/compile-common AI (dependencies): First-party @truffle scoped package from the same monorepo; stable false positive. ai
dependencies unvetted-dep:@truffle/contract-sources AI (dependencies): First-party @truffle scoped package from the same monorepo; stable false positive. ai
dependencies unvetted-dep:iter-tools AI (dependencies): Well-known utility library; no malicious indicators. ai
dependencies unvetted-dep:original-require AI (dependencies): Known utility used by Truffle ecosystem; no malicious indicators. ai
dependencies unvetted-dep:node-abort-controller AI (dependencies): Polyfill for AbortController; well-known utility, no malicious indicators. ai

Versions (showing 1 of 1)

Version Deps Published
6.0.79 16 / 16

v6.0.79

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.