@bitgo/sdk-coin-ada
BitGo SDK coin library for Ada
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-takeover | AI (maintainer-change): bitgobot is BitGo's known automated publisher across the @bitgo/* monorepo. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Routine BitGo monorepo publisher rotation to bitgobot. | ai | |
| source-diff | obfuscated-file:dist/src/lib/messages/cip8/utils.js | AI (source-diff): Compiled TS helper file, not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/src/lib/messages/cip8/cip8Message.js | AI (source-diff): Compiled TS source, standard tsc boilerplate. | ai | |
| source-diff | obfuscated-file:dist/test/unit/ada.js | AI (source-diff): Compiled TS test file with sourcemap, not obfuscation. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): BitGo monorepo maintainer list normalization via trusted bitgobot publisher. | ai | |
| provenance | publisher-changed | AI (provenance): bitgobot is BitGo's trusted CI publisher with strong track record. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): bs58/cbor are standard encoding libs needed for new Cardano vote delegation feature. | ai | |
| source-diff | obfuscated-file:dist/src/lib/voteDelegationBuilder.js | AI (source-diff): tsc-compiled boilerplate, not true obfuscation; part of legit BitGo coin library. | ai | |
| phantom-deps | phantom-dep:@emurgo/cardano-serialization-lib-browser | AI (phantom-deps): Cardano serialization lib browser variant is a declared dep used conditionally; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:lodash | AI (phantom-deps): lodash is a declared runtime dependency; phantom-dep heuristic fires incorrectly for this package. | ai |
Versions (showing 100 of 116)
| Version | Deps | Published |
|---|---|---|
| 4.25.11 | 12 / 2 | |
| 4.25.10 | 12 / 2 | |
| 4.25.9 | 12 / 2 | |
| 4.25.8 | 12 / 2 | |
| 4.25.7 | 12 / 2 | |
| 4.25.6 | 12 / 2 | |
| 4.25.5 | 12 / 2 | |
| 4.25.4 | 12 / 2 | |
| 4.25.3 | 12 / 2 | |
| 4.25.2 | 12 / 2 | |
| 4.25.1 | 12 / 2 | |
| 4.25.0 | 12 / 2 | |
| 4.24.5 | 12 / 2 | |
| 4.24.4 | 12 / 2 | |
| 4.24.3 | 12 / 2 | |
| 4.24.2 | 12 / 2 | |
| 4.18.1 | 12 / 2 | |
| 4.17.3 | 12 / 2 | |
| 4.17.0 | 12 / 2 | |
| 4.16.2 | 12 / 2 | |
| 4.15.2 | 12 / 2 | |
| 4.15.1 | 12 / 2 | |
| 4.15.0 | 12 / 2 | |
| 4.14.0 | 12 / 2 | |
| 4.13.3 | 12 / 2 | |
| 4.13.2 | 12 / 2 | |
| 4.13.1 | 12 / 2 | |
| 4.13.0 | 12 / 2 | |
| 4.12.8 | 12 / 2 | |
| 4.12.7 | 12 / 2 | |
| 4.12.6 | 12 / 2 | |
| 4.12.5 | 12 / 2 | |
| 4.12.4 | 12 / 2 | |
| 4.12.3 | 12 / 2 | |
| 4.12.2 | 12 / 2 | |
| 4.12.1 | 12 / 2 | |
| 4.12.0 | 12 / 2 | |
| 4.11.5 | 12 / 2 | |
| 4.11.4 | 12 / 2 | |
| 4.11.3 | 12 / 2 | |
| 4.11.2 | 12 / 2 | |
| 4.11.1 | 12 / 2 | |
| 4.11.0 | 12 / 2 | |
| 4.10.0 | 12 / 2 | |
| 4.9.13 | 12 / 2 | |
| 4.9.12 | 12 / 2 | |
| 4.9.11 | 12 / 2 | |
| 4.9.10 | 12 / 2 | |
| 4.9.9 | 12 / 2 | |
| 4.9.8 | 12 / 2 | |
| 4.9.7 | 12 / 2 | |
| 4.9.6 | 12 / 2 | |
| 4.9.5 | 12 / 2 | |
| 4.9.4 | 12 / 2 | |
| 4.9.3 | 12 / 2 | |
| 4.9.2 | 12 / 2 | |
| 4.9.1 | 12 / 2 | |
| 4.9.0 | 12 / 2 | |
| 4.8.0 | 12 / 2 | |
| 4.7.0 | 12 / 2 | |
| 4.6.6 | 12 / 2 | |
| 4.6.5 | 12 / 2 | |
| 4.6.4 | 12 / 2 | |
| 4.6.3 | 12 / 2 | |
| 4.6.2 | 12 / 2 | |
| 4.6.1 | 12 / 2 | |
| 4.6.0 | 10 / 2 | |
| 4.5.5 | 10 / 2 | |
| 4.5.4 | 10 / 2 | |
| 4.5.3 | 10 / 2 | |
| 4.5.2 | 10 / 2 | |
| 4.5.1 | 10 / 2 | |
| 4.5.0 | 10 / 2 | |
| 4.3.11 | 10 / 2 | |
| 4.3.10 | 10 / 2 | |
| 4.3.9 | 10 / 2 | |
| 4.3.8 | 10 / 2 | |
| 4.3.7 | 10 / 2 | |
| 4.3.6 | 10 / 2 | |
| 4.3.5 | 10 / 2 | |
| 4.3.4 | 10 / 2 | |
| 4.3.3 | 10 / 2 | |
| 4.3.2 | 10 / 2 | |
| 4.3.1 | 10 / 2 | |
| 4.3.0 | 10 / 2 | |
| 4.2.18 | 10 / 2 | |
| 4.2.17 | 10 / 2 | |
| 4.2.16 | 10 / 2 | |
| 4.2.15 | 10 / 2 | |
| 4.2.14 | 10 / 2 | |
| 4.2.13 | 10 / 2 | |
| 4.2.12 | 10 / 2 | |
| 4.2.11 | 10 / 2 | |
| 4.2.10 | 10 / 2 | |
| 4.2.9 | 10 / 2 | |
| 4.2.8 | 10 / 2 | |
| 4.2.7 | 10 / 2 | |
| 4.2.6 | 10 / 2 | |
| 4.2.5 | 10 / 2 | |
| 4.2.4 | 10 / 2 |
v4.25.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.25.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.9.8
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (mohammadalfaiyaz_bitgo) than the most recent previously approved version (margueriteblair) on 2025-04-25, but mohammadalfaiyaz_bitgo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.9.7
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (pranavjain) than the most recent previously approved version (margueriteblair) on 2025-04-15, but pranavjain is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.9.6
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (mohammadalfaiyaz_bitgo) than the most recent previously approved version (margueriteblair) on 2025-04-04, but mohammadalfaiyaz_bitgo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.9.5
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (mohammadalfaiyaz_bitgo) than the most recent previously approved version (margueriteblair) on 2025-04-02, but mohammadalfaiyaz_bitgo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.9.4
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (mohammadalfaiyaz_bitgo) than the most recent previously approved version (margueriteblair) on 2025-03-28, but mohammadalfaiyaz_bitgo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.9.3
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (pranavjain) than the most recent previously approved version (margueriteblair) on 2025-03-20, but pranavjain is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.9.2
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (pranavjain) than the most recent previously approved version (margueriteblair) on 2025-03-18, but pranavjain is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.9.1
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alebusse) than the most recent previously approved version (margueriteblair) on 2025-03-06, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.9.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.8.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.7.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.6.6
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.6.5
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.6.4
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.6.3
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.6.2
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.6.1
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.6.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.5.5
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alebusse) than the most recent previously approved version (margueriteblair) on 2025-01-15, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.5.4
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.5.3
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alebusse) than the most recent previously approved version (margueriteblair) on 2025-01-03, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.5.2
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.5.1
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.5.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.11
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (margueriteblair) than the most recent previously approved version (alebusse) on 2024-12-12, but margueriteblair is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.3.10
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alebusse) than the most recent previously approved version (margueriteblair) on 2024-12-11, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.3.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.5
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (margueriteblair) than the most recent previously approved version (pengyuc_bitgo) on 2024-11-14, but margueriteblair is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.3.4
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (pengyuc_bitgo) than the most recent previously approved version (pranavjain) on 2024-11-08, but pengyuc_bitgo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.3.3
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (pranavjain) than the most recent previously approved version (alebusse) on 2024-11-07, but pranavjain is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.3.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alebusse) than the most recent previously approved version (margueriteblair) on 2024-11-01, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.3.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (margueriteblair) than the most recent previously approved version (pengyuc_bitgo) on 2024-10-15, but margueriteblair is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.2.18
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.2.17
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (pengyuc_bitgo) than the most recent previously approved version (alebusse) on 2024-10-04, but pengyuc_bitgo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.2.16
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alebusse) than the most recent previously approved version (pranavjain) on 2024-09-24, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.2.15
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (pranavjain) than the most recent previously approved version (zahin-mohammad) on 2024-09-19, but pranavjain is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.2.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.2.13
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (zahin-mohammad) than the most recent previously approved version (pengyuc_bitgo) on 2024-09-10, but zahin-mohammad is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.2.12
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (pengyuc_bitgo) than the most recent previously approved version (margueriteblair) on 2024-09-03, but pengyuc_bitgo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.2.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.2.10
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (margueriteblair) than the most recent previously approved version (pengyuc_bitgo) on 2024-08-27, but margueriteblair is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.2.9
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (pengyuc_bitgo) than the most recent previously approved version (margueriteblair) on 2024-08-20, but pengyuc_bitgo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.2.8
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (pengyuc_bitgo) than the most recent previously approved version (margueriteblair) on 2024-08-13, but pengyuc_bitgo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.2.7
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (margueriteblair) than the most recent previously approved version (pengyuc_bitgo) on 2024-08-07, but margueriteblair is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.2.6
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (margueriteblair) than the most recent previously approved version (pengyuc_bitgo) on 2024-07-30, but margueriteblair is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.2.5
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (pengyuc_bitgo) than the most recent previously approved version (mohammadalfaiyaz_bitgo) on 2024-07-24, but pengyuc_bitgo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.2.4
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alebusse) than the most recent previously approved version (mohammadalfaiyaz_bitgo) on 2024-07-16, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.