@bitgo/sdk-coin-apt
BitGo SDK coin library for APT (Aptos) coin
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/src/lib/utils/validation.js | AI (source-diff): Standard tsc CJS output for validation utility; long lines from validation regex/data, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/test/unit/transactionBuilder/digitalAssetTransferBuilder.js | AI (source-diff): Standard tsc CJS output for test file. | ai | |
| source-diff | obfuscated-file:dist/test/unit/transactionBuilder/fungibleAssetTransferBuilder.js | AI (source-diff): Standard tsc CJS output for test file. | ai | |
| source-diff | obfuscated-file:dist/test/unit/keyPair.js | AI (source-diff): Standard tsc CJS output for test file. | ai | |
| source-diff | obfuscated-file:dist/test/unit/transactionBuilder/transferBuilder.js | AI (source-diff): Standard tsc CJS output for test file. | ai | |
| source-diff | obfuscated-file:dist/test/unit/utils.js | AI (source-diff): Standard tsc CJS output for test file. | ai | |
| source-diff | obfuscated-file:dist/test/resources/apt.js | AI (source-diff): TypeScript compiler output with readable test fixture data; long lines from serialized hex strings, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/test/unit/apt.js | AI (source-diff): Standard tsc CJS output for test file; long lines are test data strings, not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/test/unit/aptToken.js | AI (source-diff): Standard tsc CJS output for test file. | ai | |
| source-diff | obfuscated-file:dist/src/lib/transaction/customTransaction.js | AI (source-diff): Readable TypeScript-compiled source for new CustomTransaction feature class. | ai | |
| source-diff | obfuscated-file:dist/test/unit/customTransaction.test.js | AI (source-diff): Standard tsc CJS output for test file. | ai | |
| source-diff | obfuscated-file:dist/src/lib/transactionBuilder/customTransactionBuilder.js | AI (source-diff): Readable TypeScript-compiled source for new CustomTransactionBuilder feature class. | ai | |
| source-diff | obfuscated-file:dist/test/unit/transactionBuilder/customTransactionBuilder.js | AI (source-diff): Standard tsc CJS output for test file. | ai | |
| provenance | no-provenance | AI (provenance): BitGo monorepo packages consistently lack Sigstore provenance; stable false positive for this package family. | ai | |
| provenance | publisher-changed | AI (provenance): BitGo migrated publishing to GitHub Actions CI with SLSA attestation; this is the expected new publisher for this org. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): louib-bitgo follows BitGo org naming convention; consistent with legitimate team expansion. | ai | |
| dependencies | unvetted-dep:@bitgo/sdk-core | AI (dependencies): Internal BitGo monorepo dependency; stable pattern across all @bitgo/sdk-coin-* packages. | ai | |
| dependencies | unvetted-dep:@bitgo/logger | AI (dependencies): Internal BitGo monorepo dependency; stable pattern across all @bitgo/sdk-coin-* packages. | ai |
Versions (showing 77 of 77)
| Version | Deps | Published |
|---|---|---|
| 2.12.26 | 6 / 3 | |
| 2.12.25 | 6 / 3 | |
| 2.12.23 | 6 / 3 | |
| 2.12.22 | 6 / 3 | |
| 2.12.21 | 6 / 3 | |
| 2.12.20 | 6 / 3 | |
| 2.12.19 | 6 / 3 | |
| 2.12.18 | 6 / 3 | |
| 2.12.17 | 6 / 3 | |
| 2.12.16 | 6 / 3 | |
| 2.12.15 | 6 / 3 | |
| 2.12.14 | 6 / 3 | |
| 2.12.13 | 6 / 3 | |
| 2.12.12 | 6 / 3 | |
| 2.12.11 | 6 / 3 | |
| 2.12.10 | 6 / 3 | |
| 2.12.9 | 6 / 3 | |
| 2.12.8 | 6 / 3 | |
| 2.12.7 | 6 / 3 | |
| 2.12.6 | 6 / 3 | |
| 2.12.5 | 6 / 3 | |
| 2.12.4 | 6 / 3 | |
| 2.12.3 | 6 / 3 | |
| 2.12.2 | 6 / 3 | |
| 2.12.1 | 6 / 3 | |
| 2.12.0 | 6 / 3 | |
| 2.11.8 | 6 / 3 | |
| 2.11.7 | 6 / 3 | |
| 2.11.6 | 6 / 3 | |
| 2.11.5 | 6 / 3 | |
| 2.11.4 | 6 / 3 | |
| 2.11.3 | 6 / 3 | |
| 2.11.2 | 6 / 3 | |
| 2.11.1 | 6 / 3 | |
| 2.11.0 | 6 / 3 | |
| 2.9.0 | 5 / 3 | |
| 2.6.8 | 5 / 3 | |
| 2.6.7 | 5 / 3 | |
| 2.6.6 | 5 / 3 | |
| 2.6.5 | 5 / 3 | |
| 2.6.4 | 5 / 3 | |
| 2.6.3 | 5 / 3 | |
| 2.6.2 | 5 / 3 | |
| 2.6.1 | 5 / 3 | |
| 2.6.0 | 5 / 3 | |
| 2.5.4 | 5 / 3 | |
| 2.5.3 | 5 / 3 | |
| 2.5.2 | 5 / 3 | |
| 2.5.1 | 5 / 3 | |
| 2.5.0 | 5 / 3 | |
| 2.4.15 | 5 / 3 | |
| 2.4.14 | 5 / 3 | |
| 2.4.13 | 5 / 3 | |
| 2.4.12 | 5 / 3 | |
| 2.4.11 | 5 / 3 | |
| 2.4.10 | 5 / 3 | |
| 2.4.9 | 5 / 3 | |
| 2.4.8 | 5 / 3 | |
| 2.4.7 | 5 / 3 | |
| 2.4.6 | 5 / 3 | |
| 2.4.5 | 5 / 3 | |
| 2.4.4 | 5 / 3 | |
| 2.4.3 | 5 / 3 | |
| 2.4.2 | 5 / 3 | |
| 2.4.1 | 5 / 3 | |
| 2.4.0 | 5 / 3 | |
| 2.3.0 | 5 / 3 | |
| 2.2.2 | 5 / 3 | |
| 2.2.1 | 5 / 3 | |
| 2.2.0 | 5 / 3 | |
| 2.1.2 | 5 / 3 | |
| 2.1.1 | 5 / 3 | |
| 2.1.0 | 5 / 3 | |
| 2.0.3 | 5 / 3 | |
| 2.0.2 | 5 / 3 | |
| 2.0.1 | 5 / 3 | |
| 2.0.0 | 5 / 3 |
v2.12.26
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.12.25
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.12.23
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.12.22
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.12.21
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.12.20
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.