@bitgo/sdk-coin-ada
BitGo SDK coin library for Ada
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-takeover | AI (maintainer-change): bitgobot is BitGo's known automated publisher across the @bitgo/* monorepo. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Routine BitGo monorepo publisher rotation to bitgobot. | ai | |
| source-diff | obfuscated-file:dist/src/lib/messages/cip8/utils.js | AI (source-diff): Compiled TS helper file, not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/src/lib/messages/cip8/cip8Message.js | AI (source-diff): Compiled TS source, standard tsc boilerplate. | ai | |
| source-diff | obfuscated-file:dist/test/unit/ada.js | AI (source-diff): Compiled TS test file with sourcemap, not obfuscation. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): BitGo monorepo maintainer list normalization via trusted bitgobot publisher. | ai | |
| provenance | publisher-changed | AI (provenance): bitgobot is BitGo's trusted CI publisher with strong track record. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): bs58/cbor are standard encoding libs needed for new Cardano vote delegation feature. | ai | |
| source-diff | obfuscated-file:dist/src/lib/voteDelegationBuilder.js | AI (source-diff): tsc-compiled boilerplate, not true obfuscation; part of legit BitGo coin library. | ai | |
| phantom-deps | phantom-dep:@emurgo/cardano-serialization-lib-browser | AI (phantom-deps): Cardano serialization lib browser variant is a declared dep used conditionally; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:lodash | AI (phantom-deps): lodash is a declared runtime dependency; phantom-dep heuristic fires incorrectly for this package. | ai |
Versions (showing 16 of 116)
| Version | Deps | Published |
|---|---|---|
| 4.2.3 | 10 / 2 | |
| 4.2.2 | 10 / 2 | |
| 4.2.1 | 10 / 2 | |
| 4.2.0 | 10 / 2 | |
| 4.1.19 | 10 / 2 | |
| 4.1.18 | 10 / 2 | |
| 4.1.17 | 10 / 2 | |
| 4.1.16 | 10 / 2 | |
| 4.1.15 | 10 / 2 | |
| 4.1.14 | 10 / 2 | |
| 4.1.13 | 10 / 2 | |
| 4.1.12 | 10 / 2 | |
| 4.1.11 | 10 / 2 | |
| 4.1.10 | 10 / 2 | |
| 4.1.9 | 10 / 2 | |
| 4.1.8 | 10 / 2 |
v4.2.3
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (mohammadalfaiyaz_bitgo) than the most recent previously approved version (alebusse) on 2024-07-04, but mohammadalfaiyaz_bitgo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.2.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (mohammadalfaiyaz_bitgo) than the most recent previously approved version (alebusse) on 2024-07-02, but mohammadalfaiyaz_bitgo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.2.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.2.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.1.19
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alebusse) than the most recent previously approved version (margueriteblair) on 2024-06-21, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.1.18
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alebusse) than the most recent previously approved version (margueriteblair) on 2024-06-20, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.1.17
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.1.16
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (pengyuc_bitgo) than the most recent previously approved version (margueriteblair) on 2024-06-11, but pengyuc_bitgo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.1.15
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (margueriteblair) than the most recent previously approved version (zahin-mohammad) on 2024-06-05, but margueriteblair is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.1.14
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alebusse) than the most recent previously approved version (zahin-mohammad) on 2024-05-31, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.1.13
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (zahin-mohammad) than the most recent previously approved version (margueriteblair) on 2024-05-28, but zahin-mohammad is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.1.12
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (pengyuc_bitgo) than the most recent previously approved version (margueriteblair) on 2024-05-22, but pengyuc_bitgo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.1.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.1.10
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (margueriteblair) than the most recent previously approved version (pengyuc_bitgo) on 2024-05-13, but margueriteblair is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.1.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.1.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.