← Home

@bitgo/abstract-utxo

BitGo SDK coin library for UTXO base implementation

37
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

louib-bitgobitgobot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/cjs/test/unit/transaction/descriptor/verifyTransactionQr.js AI (source-diff): TypeScript CJS compiled test file; long lines are tsc boilerplate, not obfuscation. ai
source-diff obfuscated-file:dist/cjs/test/unit/deriveKeyWithSeed.js AI (source-diff): TypeScript CJS compiled test file; long lines are tsc boilerplate, not obfuscation. ai
source-diff obfuscated-file:dist/cjs/test/unit/transaction/descriptor/signTransactionGuard.js AI (source-diff): TypeScript-compiled test file with standard CJS boilerplate; long lines from test fixtures, not malicious obfuscation. ai
source-diff obfuscated-file:dist/cjs/test/unit/transaction/descriptor/signTransactionE2E.js AI (source-diff): TypeScript-compiled test file with standard CJS boilerplate; long lines from test fixtures, not malicious obfuscation. ai
source-diff large-new-source-files AI (source-diff): New dual CJS+ESM build structure explains the 502 new files; expected for this package. ai
source-diff source-size-tripled AI (source-diff): Size increase from adding ESM build alongside CJS; expected structural change. ai
source-diff obfuscated-file:dist/esm/recovery/backupKeyRecovery.js AI (source-diff): Standard tsc ESM output for recovery module; not obfuscated. ai
source-diff obfuscated-file:dist/cjs/src/abstractUtxoCoin.js AI (source-diff): Standard tsc CJS output; readable TypeScript-compiled JS with BitGo imports, not obfuscated. ai
source-diff obfuscated-file:dist/esm/abstractUtxoCoin.js AI (source-diff): Standard tsc ESM output; readable TypeScript-compiled JS with BitGo imports, not obfuscated. ai
source-diff obfuscated-file:dist/cjs/src/recovery/backupKeyRecovery.js AI (source-diff): Standard tsc CJS output for recovery module; not obfuscated. ai
source-diff obfuscated-file:dist/cjs/test/unit/webauthn.js AI (source-diff): Standard CJS compiled test file; long lines are test data, not malicious obfuscation. ai
source-diff obfuscated-file:dist/cjs/test/unit/pendingApprovalTxHexPsbt.js AI (source-diff): Long lines are inline PSBT/hex test data in compiled test fixtures, not obfuscation. ai
phantom-deps phantom-dep:@types/lodash AI (phantom-deps): Type-only dev dependency declared for TypeScript consumers; not directly imported at runtime. ai
phantom-deps phantom-dep:@types/superagent AI (phantom-deps): Type-only dependency for superagent typings; not directly imported at runtime. ai

Versions (showing 37 of 37)

Version Deps Published
12.0.5 15 / 3
12.0.4 15 / 3
12.0.3 15 / 3
12.0.1 15 / 3
12.0.0 15 / 3
11.7.5 15 / 3
11.7.4 15 / 3
11.7.3 15 / 3
11.7.2 15 / 3
11.7.1 15 / 3
11.7.0 15 / 3
11.6.1 15 / 2
11.6.0 15 / 2
11.5.1 15 / 2
11.5.0 15 / 2
11.4.0 15 / 2
11.3.0 14 / 2
11.2.0 14 / 2
11.1.0 14 / 2
11.0.0 14 / 2
10.25.0 14 / 2
10.18.1 16 / 2
10.17.0 17 / 2
10.14.0 17 / 2
10.13.0 17 / 2
10.12.0 17 / 2
10.11.0 17 / 2
10.10.0 17 / 2
10.9.0 17 / 2
10.6.0 17 / 2
10.5.0 17 / 2
10.4.0 17 / 2
10.3.0 17 / 2
10.2.0 17 / 2
10.1.0 17 / 2
10.0.1 16 / 0
10.0.0 16 / 0

v12.0.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v12.0.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v12.0.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v12.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v12.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v11.7.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v11.7.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.