@0xsequence/core
core primitives for interacting with the sequence wallet contracts
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | large-new-source-files | AI (source-diff): New dist/ bundle files added; expected for this package's build output pattern. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size increase explained by addition of dist/ bundle files; not injected payload. | ai | |
| source-diff | obfuscated-file:dist/declarations/src/commons/validateEIP6492.d.ts | AI (source-diff): Long line is an inline EIP-6492 bytecode constant in a .d.ts file; expected for this smart-contract library. | ai | |
| source-diff | obfuscated-file:dist/0xsequence-core.cjs.dev.js | AI (source-diff): Standard bundler output (CJS dev build); long lines are minified but readable legitimate code. | ai | |
| source-diff | obfuscated-file:dist/0xsequence-core.cjs.prod.js | AI (source-diff): Standard bundler output (CJS prod build); same pattern as dev build, legitimate. | ai | |
| source-diff | encoded-string-file:dist/0xsequence-core.cjs.dev.js | AI (source-diff): EIP-6492 UniversalSigValidator EVM bytecode constant; legitimate and documented in the Solidity comment above it. | ai | |
| source-diff | encoded-string-file:dist/0xsequence-core.esm.js | AI (source-diff): Same EIP-6492 bytecode constant; stable pattern for this package. | ai | |
| source-diff | encoded-string-file:dist/0xsequence-core.cjs.prod.js | AI (source-diff): Same EIP-6492 bytecode constant; stable pattern for this package. | ai | |
| typosquat | typosquat.levenshtein:cors | AI (typosquat): @0xsequence/core is a scoped package in the 0xsequence monorepo; not a typosquat of cors. | ai |
Versions (showing 95 of 95)
| Version | Deps | Published |
|---|---|---|
| 2.3.44 | 2 / 3 | |
| 2.3.43 | 2 / 3 | |
| 2.3.42 | 2 / 3 | |
| 2.3.41 | 2 / 3 | |
| 2.3.40 | 2 / 3 | |
| 2.3.39 | 2 / 3 | |
| 2.3.38 | 2 / 3 | |
| 2.3.37 | 2 / 3 | |
| 2.3.36 | 2 / 3 | |
| 2.3.35 | 2 / 3 | |
| 2.3.34 | 2 / 3 | |
| 2.3.33 | 2 / 3 | |
| 2.3.32 | 2 / 3 | |
| 2.3.31 | 2 / 3 | |
| 2.3.30 | 2 / 3 | |
| 2.3.29 | 2 / 3 | |
| 2.3.28 | 2 / 3 | |
| 2.3.27 | 2 / 3 | |
| 2.3.26 | 2 / 3 | |
| 2.3.25 | 2 / 3 | |
| 2.3.24 | 2 / 3 | |
| 2.3.23 | 2 / 3 | |
| 2.3.22 | 2 / 3 | |
| 2.3.20 | 2 / 3 | |
| 2.3.19 | 2 / 3 | |
| 2.3.18 | 2 / 3 | |
| 2.3.17 | 2 / 3 | |
| 2.3.15 | 2 / 3 | |
| 2.3.14 | 2 / 3 | |
| 2.3.13 | 2 / 3 | |
| 2.3.12 | 2 / 3 | |
| 2.3.11 | 2 / 3 | |
| 2.3.10 | 2 / 3 | |
| 2.3.9 | 2 / 3 | |
| 2.3.8 | 2 / 3 | |
| 2.3.7 | 2 / 3 | |
| 2.3.6 | 2 / 3 | |
| 2.3.5 | 2 / 3 | |
| 2.3.4 | 2 / 3 | |
| 2.3.3 | 2 / 3 | |
| 2.3.2 | 2 / 3 | |
| 2.3.1 | 2 / 3 | |
| 2.3.0 | 2 / 3 | |
| 2.2.15 | 2 / 3 | |
| 2.2.14 | 2 / 3 | |
| 2.2.13 | 2 / 3 | |
| 2.2.12 | 2 / 3 | |
| 2.2.11 | 2 / 3 | |
| 2.2.10 | 2 / 3 | |
| 2.2.9 | 2 / 3 | |
| 2.2.8 | 2 / 3 | |
| 2.2.7 | 2 / 3 | |
| 2.2.6 | 2 / 3 | |
| 2.2.5 | 2 / 3 | |
| 2.2.4 | 2 / 3 | |
| 2.2.3 | 2 / 3 | |
| 2.2.2 | 2 / 3 | |
| 2.2.1 | 2 / 3 | |
| 2.2.0 | 2 / 3 | |
| 2.1.8 | 2 / 3 | |
| 2.1.7 | 2 / 3 | |
| 2.1.6 | 2 / 3 | |
| 2.1.5 | 2 / 3 | |
| 2.1.4 | 2 / 3 | |
| 2.1.3 | 2 / 3 | |
| 2.1.2 | 2 / 3 | |
| 2.1.1 | 2 / 3 | |
| 2.1.0 | 2 / 3 | |
| 2.0.26 | 2 / 3 | |
| 2.0.25 | 2 / 3 | |
| 2.0.24 | 2 / 3 | |
| 2.0.23 | 2 / 3 | |
| 2.0.22 | 2 / 3 | |
| 2.0.21 | 2 / 3 | |
| 2.0.20 | 2 / 3 | |
| 2.0.19 | 2 / 2 | |
| 2.0.18 | 2 / 2 | |
| 2.0.17 | 2 / 2 | |
| 2.0.16 | 2 / 2 | |
| 2.0.15 | 2 / 2 | |
| 2.0.14 | 2 / 2 | |
| 2.0.13 | 2 / 2 | |
| 2.0.12 | 2 / 2 | |
| 2.0.11 | 2 / 2 | |
| 2.0.10 | 2 / 2 | |
| 2.0.9 | 2 / 2 | |
| 2.0.8 | 2 / 2 | |
| 2.0.7 | 2 / 2 | |
| 2.0.6 | 2 / 2 | |
| 2.0.5 | 2 / 2 | |
| 2.0.4 | 2 / 2 | |
| 2.0.3 | 2 / 2 | |
| 2.0.2 | 2 / 2 | |
| 2.0.1 | 2 / 2 | |
| 2.0.0 | 2 / 2 |
v2.3.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.8
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (pkieltyka) than the most recent previously approved version (taylanpince) on 2025-04-08, but pkieltyka is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.3.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.6
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (taylanpince) than the most recent previously approved version (pkieltyka) on 2025-04-02, but taylanpince is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.3.5
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (taylanpince) than the most recent previously approved version (pkieltyka) on 2025-04-02, but taylanpince is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.3.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (pkieltyka) than the most recent previously approved version (taylanpince) on 2025-03-27, but pkieltyka is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.3.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (pkieltyka) than the most recent previously approved version (taylanpince) on 2025-03-26, but pkieltyka is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.2.15
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.6
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (taylanpince) than the most recent previously approved version (naivesheep) on 2025-01-14, but taylanpince is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.2.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.3
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (naivesheep) than the most recent previously approved version (pkieltyka) on 2024-12-17, but naivesheep is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.2.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (pkieltyka) than the most recent previously approved version (taylanpince) on 2024-12-12, but pkieltyka is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.2.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (naivesheep) than the most recent previously approved version (taylanpince) on 2024-12-11, but naivesheep is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.1.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.7
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (naivesheep) than the most recent previously approved version (taylanpince) on 2024-12-06, but naivesheep is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.1.6
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (taylanpince) than the most recent previously approved version (naivesheep) on 2024-12-04, but taylanpince is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.1.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.3
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (pkieltyka) than the most recent previously approved version (naivesheep) on 2024-11-29, but pkieltyka is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.1.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (taylanpince) than the most recent previously approved version (naivesheep) on 2024-11-27, but taylanpince is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.1.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.26
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.25
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (naivesheep) than the most recent previously approved version (taylanpince) on 2024-11-07, but naivesheep is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.0.24
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (naivesheep) than the most recent previously approved version (taylanpince) on 2024-11-07, but naivesheep is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.0.23
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (taylanpince) than the most recent previously approved version (naivesheep) on 2024-11-06, but taylanpince is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.0.22
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (taylanpince) than the most recent previously approved version (naivesheep) on 2024-10-31, but taylanpince is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.0.21
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (naivesheep) than the most recent previously approved version (taylanpince) on 2024-10-24, but naivesheep is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.0.20
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (pkieltyka) than the most recent previously approved version (taylanpince) on 2024-10-24, but pkieltyka is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.0.19
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (taylanpince) than the most recent previously approved version (pkieltyka) on 2024-10-24, but taylanpince is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.0.18
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (naivesheep) than the most recent previously approved version (pkieltyka) on 2024-10-22, but naivesheep is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.0.17
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (pkieltyka) than the most recent previously approved version (naivesheep) on 2024-10-17, but pkieltyka is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.0.16
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (taylanpince) than the most recent previously approved version (naivesheep) on 2024-10-17, but taylanpince is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.0.15
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.9
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (naivesheep) than the most recent previously approved version (pkieltyka) on 2024-09-24, but naivesheep is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.0.8
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (naivesheep) than the most recent previously approved version (pkieltyka) on 2024-09-19, but naivesheep is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.0.7
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (pkieltyka) than the most recent previously approved version (naivesheep) on 2024-09-18, but pkieltyka is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.0.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.