@bitgo/sdk-coin-ada
BitGo SDK coin library for Ada
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-takeover | AI (maintainer-change): bitgobot is BitGo's known automated publisher across the @bitgo/* monorepo. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Routine BitGo monorepo publisher rotation to bitgobot. | ai | |
| source-diff | obfuscated-file:dist/src/lib/messages/cip8/utils.js | AI (source-diff): Compiled TS helper file, not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/src/lib/messages/cip8/cip8Message.js | AI (source-diff): Compiled TS source, standard tsc boilerplate. | ai | |
| source-diff | obfuscated-file:dist/test/unit/ada.js | AI (source-diff): Compiled TS test file with sourcemap, not obfuscation. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): BitGo monorepo maintainer list normalization via trusted bitgobot publisher. | ai | |
| provenance | publisher-changed | AI (provenance): bitgobot is BitGo's trusted CI publisher with strong track record. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): bs58/cbor are standard encoding libs needed for new Cardano vote delegation feature. | ai | |
| source-diff | obfuscated-file:dist/src/lib/voteDelegationBuilder.js | AI (source-diff): tsc-compiled boilerplate, not true obfuscation; part of legit BitGo coin library. | ai | |
| phantom-deps | phantom-dep:@emurgo/cardano-serialization-lib-browser | AI (phantom-deps): Cardano serialization lib browser variant is a declared dep used conditionally; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:lodash | AI (phantom-deps): lodash is a declared runtime dependency; phantom-dep heuristic fires incorrectly for this package. | ai |
Versions (showing 51 of 116)
| Version | Deps | Published |
|---|---|---|
| 4.25.11 | 12 / 2 | |
| 4.25.10 | 12 / 2 | |
| 4.25.9 | 12 / 2 | |
| 4.25.8 | 12 / 2 | |
| 4.25.7 | 12 / 2 | |
| 4.25.6 | 12 / 2 | |
| 4.25.5 | 12 / 2 | |
| 4.25.4 | 12 / 2 | |
| 4.25.3 | 12 / 2 | |
| 4.25.2 | 12 / 2 | |
| 4.25.1 | 12 / 2 | |
| 4.25.0 | 12 / 2 | |
| 4.24.5 | 12 / 2 | |
| 4.24.4 | 12 / 2 | |
| 4.24.3 | 12 / 2 | |
| 4.24.2 | 12 / 2 | |
| 4.18.1 | 12 / 2 | |
| 4.17.3 | 12 / 2 | |
| 4.17.0 | 12 / 2 | |
| 4.16.2 | 12 / 2 | |
| 4.15.2 | 12 / 2 | |
| 4.15.1 | 12 / 2 | |
| 4.15.0 | 12 / 2 | |
| 4.14.0 | 12 / 2 | |
| 4.13.3 | 12 / 2 | |
| 4.13.2 | 12 / 2 | |
| 4.13.1 | 12 / 2 | |
| 4.13.0 | 12 / 2 | |
| 4.12.8 | 12 / 2 | |
| 4.12.7 | 12 / 2 | |
| 4.12.6 | 12 / 2 | |
| 4.12.5 | 12 / 2 | |
| 4.12.4 | 12 / 2 | |
| 4.12.3 | 12 / 2 | |
| 4.12.2 | 12 / 2 | |
| 4.12.1 | 12 / 2 | |
| 4.12.0 | 12 / 2 | |
| 4.11.5 | 12 / 2 | |
| 4.11.4 | 12 / 2 | |
| 4.11.3 | 12 / 2 | |
| 4.11.2 | 12 / 2 | |
| 4.11.1 | 12 / 2 | |
| 4.11.0 | 12 / 2 | |
| 4.10.0 | 12 / 2 | |
| 4.9.13 | 12 / 2 | |
| 4.9.12 | 12 / 2 | |
| 4.9.11 | 12 / 2 | |
| 4.9.10 | 12 / 2 | |
| 4.9.9 | 12 / 2 | |
| 4.9.8 | 12 / 2 | |
| 4.9.7 | 12 / 2 |
v4.25.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.25.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.9.8
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (mohammadalfaiyaz_bitgo) than the most recent previously approved version (margueriteblair) on 2025-04-25, but mohammadalfaiyaz_bitgo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.9.7
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (pranavjain) than the most recent previously approved version (margueriteblair) on 2025-04-15, but pranavjain is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.