@argonprotocol/bitcoin
A client for interop with bitcoin in nodejs.
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | encoded-string-file:browser/index.js | AI (source-diff): Base64-embedded wasm binary from rust bindings build, not obfuscated payload. | ai | |
| source-diff | obfuscated-file:browser/index.js | AI (source-diff): Bundled tsup/wasm-pack output, not true obfuscation; matches build scripts. | ai | |
| npm-metadata | bundled-binaries | AI (npm-metadata): WASM binary is the documented wasm-pack build artifact for bitcoin bindings. | ai | |
| semgrep | semgrep:hex-decode | AI (semgrep): Standard hex key parsing in Bitcoin library; not a malicious payload pattern. | ai | |
| phantom-deps | phantom-dep:bignumber.js | AI (phantom-deps): bignumber.js is a declared runtime dependency; phantom-dep is a false positive for this package. | ai |
Versions (showing 28 of 28)
| Version | Deps | Published |
|---|---|---|
| 1.4.9 | 6 / 6 | |
| 1.4.8 | 6 / 6 | |
| 1.4.7 | 6 / 6 | |
| 1.4.6 | 6 / 6 | |
| 1.4.5 | 6 / 6 | |
| 1.4.4 | 6 / 6 | |
| 1.4.3 | 6 / 7 | |
| 1.4.2 | 6 / 7 | |
| 1.4.1 | 6 / 7 | |
| 1.4.0 | 6 / 7 | |
| 1.3.27 | 6 / 7 | |
| 1.3.26 | 6 / 7 | |
| 1.3.25 | 6 / 7 | |
| 1.3.24 | 6 / 7 | |
| 1.3.23 | 6 / 7 | |
| 1.3.22 | 6 / 7 | |
| 1.3.21 | 6 / 7 | |
| 1.3.20 | 6 / 7 | |
| 1.3.19 | 6 / 7 | |
| 1.3.18 | 6 / 7 | |
| 1.3.17 | 6 / 7 | |
| 1.3.16 | 6 / 7 | |
| 1.3.15 | 6 / 7 | |
| 1.3.14 | 6 / 7 | |
| 1.3.13 | 6 / 7 | |
| 1.3.2 | 6 / 7 | |
| 1.3.1 | 6 / 7 | |
| 1.3.0 | 6 / 7 |
v1.4.9
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.5
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.2
4 findingsPackage contains compiled binaries that could be backdoors: • lib/bitcoin_bindings_bg-R6I7INCI.wasm
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (blakebyrnes) on 2026-03-24, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v1.4.1
4 findingsPackage contains compiled binaries that could be backdoors: • lib/bitcoin_bindings_bg-6TUA4LTN.wasm
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (blakebyrnes) on 2026-03-20, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v1.4.0
4 findingsPackage contains compiled binaries that could be backdoors: • lib/bitcoin_bindings_bg-YHPBJNYF.wasm
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (blakebyrnes) on 2026-02-22, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v1.3.27
3 findingsPackage contains compiled binaries that could be backdoors: • lib/bitcoin_bindings_bg-CY7AADGN.wasm
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.3.26
3 findingsPackage contains compiled binaries that could be backdoors: • lib/bitcoin_bindings_bg-JD75G3Y4.wasm
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.3.25
3 findingsPackage contains compiled binaries that could be backdoors: • lib/bitcoin_bindings_bg-7NZS3DL5.wasm
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.3.24
3 findingsPackage contains compiled binaries that could be backdoors: • lib/bitcoin_bindings_bg-65Q2YUNH.wasm
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.3.23
3 findingsPackage contains compiled binaries that could be backdoors: • lib/bitcoin_bindings_bg-ILDL3KBX.wasm
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.3.22
3 findingsPackage contains compiled binaries that could be backdoors: • lib/bitcoin_bindings_bg-NPFLJ74Q.wasm
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.3.21
3 findingsPackage contains compiled binaries that could be backdoors: • lib/bitcoin_bindings_bg-UYGS223Z.wasm
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.3.20
3 findingsPackage contains compiled binaries that could be backdoors: • lib/bitcoin_bindings_bg-A4SFAJYQ.wasm
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.3.19
3 findingsPackage contains compiled binaries that could be backdoors: • lib/bitcoin_bindings_bg-KI7YVKAR.wasm
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.3.18
3 findingsPackage contains compiled binaries that could be backdoors: • lib/bitcoin_bindings_bg-EESA65GU.wasm
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.3.17
3 findingsPackage contains compiled binaries that could be backdoors: • lib/bitcoin_bindings_bg-AEJANSMA.wasm
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.3.16
3 findingsPackage contains compiled binaries that could be backdoors: • lib/bitcoin_bindings_bg-5OPF4IUB.wasm
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.3.15
3 findingsPackage contains compiled binaries that could be backdoors: • lib/bitcoin_bindings_bg-VCAFIU4A.wasm
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.3.14
3 findingsPackage contains compiled binaries that could be backdoors: • lib/bitcoin_bindings_bg-3JMAZZYC.wasm
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.3.13
3 findingsPackage contains compiled binaries that could be backdoors: • lib/bitcoin_bindings_bg-3FFGFDPO.wasm
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.