@bitgo/abstract-utxo
BitGo SDK coin library for UTXO base implementation
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/cjs/test/unit/transaction/descriptor/verifyTransactionQr.js | AI (source-diff): TypeScript CJS compiled test file; long lines are tsc boilerplate, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/cjs/test/unit/deriveKeyWithSeed.js | AI (source-diff): TypeScript CJS compiled test file; long lines are tsc boilerplate, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/cjs/test/unit/transaction/descriptor/signTransactionGuard.js | AI (source-diff): TypeScript-compiled test file with standard CJS boilerplate; long lines from test fixtures, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:dist/cjs/test/unit/transaction/descriptor/signTransactionE2E.js | AI (source-diff): TypeScript-compiled test file with standard CJS boilerplate; long lines from test fixtures, not malicious obfuscation. | ai | |
| source-diff | large-new-source-files | AI (source-diff): New dual CJS+ESM build structure explains the 502 new files; expected for this package. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size increase from adding ESM build alongside CJS; expected structural change. | ai | |
| source-diff | obfuscated-file:dist/esm/recovery/backupKeyRecovery.js | AI (source-diff): Standard tsc ESM output for recovery module; not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/cjs/src/abstractUtxoCoin.js | AI (source-diff): Standard tsc CJS output; readable TypeScript-compiled JS with BitGo imports, not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/esm/abstractUtxoCoin.js | AI (source-diff): Standard tsc ESM output; readable TypeScript-compiled JS with BitGo imports, not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/cjs/src/recovery/backupKeyRecovery.js | AI (source-diff): Standard tsc CJS output for recovery module; not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/cjs/test/unit/webauthn.js | AI (source-diff): Standard CJS compiled test file; long lines are test data, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:dist/cjs/test/unit/pendingApprovalTxHexPsbt.js | AI (source-diff): Long lines are inline PSBT/hex test data in compiled test fixtures, not obfuscation. | ai | |
| phantom-deps | phantom-dep:@types/lodash | AI (phantom-deps): Type-only dev dependency declared for TypeScript consumers; not directly imported at runtime. | ai | |
| phantom-deps | phantom-dep:@types/superagent | AI (phantom-deps): Type-only dependency for superagent typings; not directly imported at runtime. | ai |
Versions (showing 37 of 37)
| Version | Deps | Published |
|---|---|---|
| 12.0.5 | 15 / 3 | |
| 12.0.4 | 15 / 3 | |
| 12.0.3 | 15 / 3 | |
| 12.0.1 | 15 / 3 | |
| 12.0.0 | 15 / 3 | |
| 11.7.5 | 15 / 3 | |
| 11.7.4 | 15 / 3 | |
| 11.7.3 | 15 / 3 | |
| 11.7.2 | 15 / 3 | |
| 11.7.1 | 15 / 3 | |
| 11.7.0 | 15 / 3 | |
| 11.6.1 | 15 / 2 | |
| 11.6.0 | 15 / 2 | |
| 11.5.1 | 15 / 2 | |
| 11.5.0 | 15 / 2 | |
| 11.4.0 | 15 / 2 | |
| 11.3.0 | 14 / 2 | |
| 11.2.0 | 14 / 2 | |
| 11.1.0 | 14 / 2 | |
| 11.0.0 | 14 / 2 | |
| 10.25.0 | 14 / 2 | |
| 10.18.1 | 16 / 2 | |
| 10.17.0 | 17 / 2 | |
| 10.14.0 | 17 / 2 | |
| 10.13.0 | 17 / 2 | |
| 10.12.0 | 17 / 2 | |
| 10.11.0 | 17 / 2 | |
| 10.10.0 | 17 / 2 | |
| 10.9.0 | 17 / 2 | |
| 10.6.0 | 17 / 2 | |
| 10.5.0 | 17 / 2 | |
| 10.4.0 | 17 / 2 | |
| 10.3.0 | 17 / 2 | |
| 10.2.0 | 17 / 2 | |
| 10.1.0 | 17 / 2 | |
| 10.0.1 | 16 / 0 | |
| 10.0.0 | 16 / 0 |
v12.0.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v12.0.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v12.0.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v12.0.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v12.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.7.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.7.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.