@bitgo/sdk-coin-algo
BitGo SDK coin library for Algorand
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | encoded-string-file:dist/test/fixtures/resources.d.ts | AI (source-diff): TypeScript declaration file mirroring the same Algorand test fixture hex strings; benign. | ai | |
| source-diff | encoded-string-file:dist/test/fixtures/resources.js | AI (source-diff): Long hex strings are Algorand transaction test fixtures (msgpack-encoded txns), not obfuscated payloads. | ai | |
| provenance | publisher-changed | AI (provenance): BitGo migrated publishing to GitHub Actions CI/CD; SLSA attestation confirms integrity. Stable pattern for this package. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): louib-bitgo is a BitGo org account; addition consistent with normal team maintenance of the BitGoJS monorepo. | ai | |
| source-diff | obfuscated-file:dist/test/fixtures/resources.js | AI (source-diff): TypeScript-compiled test fixtures; long lines are inline test data. | ai | |
| source-diff | obfuscated-file:dist/test/unit/algoIsWalletAddress.js | AI (source-diff): TypeScript-compiled test file; long lines are test case arrays. | ai | |
| source-diff | obfuscated-file:dist/test/unit/lib/transactionBuilder/keyRegistrationBuilder.js | AI (source-diff): TypeScript-compiled test file; standard TS boilerplate. | ai | |
| source-diff | obfuscated-file:dist/test/unit/lib/keyPair.js | AI (source-diff): TypeScript-compiled test file; standard TS boilerplate. | ai | |
| source-diff | obfuscated-file:dist/test/unit/lib/transactionBuilder/base.js | AI (source-diff): TypeScript-compiled test file; standard TS boilerplate. | ai | |
| source-diff | obfuscated-file:dist/test/unit/lib/utils.js | AI (source-diff): TypeScript-compiled test file; standard TS boilerplate. | ai | |
| source-diff | obfuscated-file:dist/test/unit/algoToken.js | AI (source-diff): TypeScript-compiled test file; standard TS boilerplate. | ai | |
| source-diff | obfuscated-file:dist/test/integration/algo.integration.js | AI (source-diff): TypeScript-compiled test file; long lines are test data arrays, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/test/fixtures/algo.js | AI (source-diff): TypeScript-compiled test fixtures; long lines are inline test data objects. | ai | |
| source-diff | obfuscated-file:dist/test/unit/algo.js | AI (source-diff): TypeScript-compiled test file; standard TS boilerplate with test data. | ai | |
| source-diff | obfuscated-file:dist/test/unit/lib/transactionBuilder/assetTransferBuilder.js | AI (source-diff): TypeScript-compiled test file; standard TS boilerplate. | ai | |
| source-diff | obfuscated-file:dist/test/unit/lib/transactionBuilder/transferBuilder.js | AI (source-diff): TypeScript-compiled test file; standard TS boilerplate. | ai | |
| source-diff | obfuscated-file:dist/test/unit/lib/transactionBuilder/transactionBuilderFactory.js | AI (source-diff): TypeScript-compiled test file; standard TS boilerplate. | ai | |
| source-diff | obfuscated-file:dist/test/unit/lib/transaction.js | AI (source-diff): TypeScript-compiled test file; standard TS boilerplate. | ai | |
| source-diff | encoded-string-file:dist/test/unit/algo.js | AI (source-diff): Long base64 strings are Algorand transaction fixtures in test files; stable false positive for this package. | ai | |
| source-diff | obfuscated-file:dist/src/lib/transactionBuilderFactory.js | AI (source-diff): Standard TypeScript compiled output. | ai | |
| source-diff | obfuscated-file:dist/src/algo.js | AI (source-diff): Standard TypeScript compiled output; long lines from TS boilerplate, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/src/algoToken.js | AI (source-diff): Standard TypeScript compiled output. | ai | |
| source-diff | obfuscated-file:dist/src/lib/assetTransferBuilder.js | AI (source-diff): Standard TypeScript compiled output. | ai | |
| source-diff | obfuscated-file:dist/src/lib/keyPair.js | AI (source-diff): Standard TypeScript compiled output. | ai | |
| source-diff | obfuscated-file:dist/src/lib/keyRegistrationBuilder.js | AI (source-diff): Standard TypeScript compiled output. | ai | |
| source-diff | obfuscated-file:dist/src/lib/seedEncoding.js | AI (source-diff): Standard TypeScript compiled output. | ai | |
| source-diff | obfuscated-file:dist/src/seedValidator.js | AI (source-diff): Standard TypeScript compiled output. | ai | |
| source-diff | obfuscated-file:dist/src/lib/transaction.js | AI (source-diff): Standard TypeScript compiled output. | ai | |
| source-diff | obfuscated-file:dist/src/lib/transactionBuilder.js | AI (source-diff): Standard TypeScript compiled output. | ai | |
| source-diff | obfuscated-file:dist/src/lib/transferBuilder.js | AI (source-diff): Standard TypeScript compiled output. | ai | |
| source-diff | obfuscated-file:dist/src/lib/txnSchema.js | AI (source-diff): Standard TypeScript compiled output. | ai | |
| source-diff | obfuscated-file:dist/src/lib/utils.js | AI (source-diff): Standard TypeScript compiled output. | ai | |
| source-diff | large-new-source-files | AI (source-diff): New dist/ files are TS build artifacts for a new package version; expected for BitGo SDK modules. | ai | |
| source-diff | source-size-tripled | AI (source-diff): First version with compiled dist/ output included; size increase reflects TS build artifacts, not injected payloads. | ai | |
| source-diff | obfuscated-file:dist/test/unit/verifyTransaction.js | AI (source-diff): Compiled TypeScript test output; long lines are TS boilerplate, not obfuscation. Stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@hashgraph/cryptography | AI (phantom-deps): Legitimate runtime dep in a TS package; phantom-dep heuristic fires on compiled output. | ai | |
| phantom-deps | phantom-dep:@stablelib/hex | AI (phantom-deps): Legitimate runtime dep in a TS package; phantom-dep heuristic fires on compiled output. | ai | |
| phantom-deps | phantom-dep:@bitgo/sdk-core | AI (phantom-deps): Same-org dep; phantom-dep heuristic fires on compiled output. | ai | |
| phantom-deps | phantom-dep:@bitgo/statics | AI (phantom-deps): Same-org dep; phantom-dep heuristic fires on compiled output. | ai | |
| phantom-deps | phantom-dep:bignumber.js | AI (phantom-deps): Legitimate runtime dep in a TS package; phantom-dep heuristic fires on compiled output. | ai | |
| phantom-deps | phantom-dep:stellar-sdk | AI (phantom-deps): Legitimate runtime dep in a TS package; phantom-dep heuristic fires on compiled output. | ai | |
| phantom-deps | phantom-dep:tweetnacl | AI (phantom-deps): Legitimate runtime dep in a TS package; phantom-dep heuristic fires on compiled output. | ai | |
| phantom-deps | phantom-dep:js-sha512 | AI (phantom-deps): Legitimate runtime dep in a TS package; phantom-dep heuristic fires on compiled output. | ai | |
| phantom-deps | phantom-dep:hi-base32 | AI (phantom-deps): Legitimate runtime dep in a TS package; phantom-dep heuristic fires on compiled output. | ai | |
| phantom-deps | phantom-dep:algosdk | AI (phantom-deps): Core Algorand SDK dep; phantom-dep heuristic fires on compiled output. | ai | |
| phantom-deps | phantom-dep:joi | AI (phantom-deps): Legitimate runtime dep in a TS package; phantom-dep heuristic fires on compiled output. | ai | |
| phantom-deps | phantom-dep:lodash | AI (phantom-deps): Legitimate runtime dep in a TS package; phantom-dep heuristic fires on compiled output. | ai | |
| provenance | no-provenance | AI (provenance): BitGo monorepo packages consistently lack Sigstore provenance; stable false positive for this package family. | ai | |
| dependencies | unvetted-dep:@bitgo/sdk-core | AI (dependencies): Sibling package in the BitGo monorepo; same publisher and trust chain as this package. | ai |
Versions (showing 54 of 154)
| Version | Deps | Published |
|---|---|---|
| 2.1.62 | 12 / 4 | |
| 2.1.61 | 12 / 4 | |
| 2.1.60 | 12 / 4 | |
| 2.1.59 | 12 / 4 | |
| 2.1.58 | 12 / 4 | |
| 2.1.57 | 12 / 4 | |
| 2.1.56 | 12 / 4 | |
| 2.1.55 | 12 / 4 | |
| 2.1.54 | 12 / 4 | |
| 2.1.53 | 12 / 4 | |
| 2.1.52 | 12 / 4 | |
| 2.1.50 | 12 / 4 | |
| 2.1.49 | 12 / 4 | |
| 2.1.48 | 12 / 4 | |
| 2.1.47 | 12 / 4 | |
| 2.1.46 | 12 / 4 | |
| 2.1.45 | 12 / 4 | |
| 2.1.44 | 12 / 4 | |
| 2.1.43 | 12 / 4 | |
| 2.1.42 | 12 / 4 | |
| 2.1.41 | 12 / 4 | |
| 2.1.40 | 12 / 4 | |
| 2.1.39 | 12 / 4 | |
| 2.1.38 | 12 / 4 | |
| 2.1.37 | 12 / 4 | |
| 2.1.36 | 12 / 4 | |
| 2.1.35 | 12 / 4 | |
| 2.1.34 | 12 / 4 | |
| 2.1.33 | 12 / 4 | |
| 2.1.32 | 12 / 4 | |
| 2.1.31 | 12 / 4 | |
| 2.1.30 | 12 / 4 | |
| 2.1.29 | 12 / 4 | |
| 2.1.28 | 12 / 4 | |
| 2.1.27 | 12 / 4 | |
| 2.1.26 | 12 / 4 | |
| 2.1.25 | 12 / 4 | |
| 2.1.24 | 12 / 4 | |
| 2.1.23 | 12 / 4 | |
| 2.1.22 | 12 / 4 | |
| 2.1.21 | 12 / 4 | |
| 2.1.20 | 12 / 4 | |
| 2.1.19 | 12 / 4 | |
| 2.1.18 | 12 / 4 | |
| 2.1.17 | 12 / 4 | |
| 2.1.16 | 12 / 4 | |
| 2.1.15 | 12 / 4 | |
| 2.1.14 | 12 / 4 | |
| 2.1.13 | 12 / 4 | |
| 2.1.12 | 12 / 4 | |
| 2.1.11 | 12 / 4 | |
| 2.1.10 | 12 / 4 | |
| 2.1.9 | 12 / 4 | |
| 2.1.8 | 12 / 4 |
v2.1.62
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.61
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.60
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.59
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.58
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.57
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.56
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.55
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.54
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.53
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.52
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.50
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.49
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.48
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.47
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.46
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.45
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.44
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.43
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.42
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.41
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.40
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.39
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.38
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.37
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.36
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.35
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.34
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.33
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.32
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.31
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.30
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.29
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.28
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.27
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.26
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.25
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.24
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.23
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.22
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.21
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.20
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.19
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.18
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.17
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.16
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.15
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.