@bitgo/sdk-coin-asi
BitGo SDK coin library for Fetch Native (ASI)
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): bitgobot is BitGo's official CI publisher with 889 approved packages; transition from individual maintainer is expected. | ai | |
| source-diff | obfuscated-file:dist/test/resources/asi.js | AI (source-diff): Compiled TypeScript test fixture with base64 tx data; long lines are test vectors, not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/test/unit/asi.js | AI (source-diff): Compiled TypeScript unit test; long lines are standard TypeScript boilerplate and test data. | ai | |
| source-diff | obfuscated-file:dist/test/unit/keyPair.js | AI (source-diff): Compiled TypeScript unit test for key pair functionality; no malicious content. | ai | |
| source-diff | obfuscated-file:dist/test/unit/transactionBuilder/StakingActivateBuilder.js | AI (source-diff): Compiled TypeScript unit test for staking builder; long lines are test boilerplate. | ai | |
| source-diff | obfuscated-file:dist/test/unit/transactionBuilder/StakingDeactivateBuilder.js | AI (source-diff): Compiled TypeScript unit test; no malicious content. | ai | |
| source-diff | obfuscated-file:dist/test/unit/transactionBuilder/StakingRedelegateBuilder.js | AI (source-diff): Compiled TypeScript unit test; no malicious content. | ai | |
| source-diff | obfuscated-file:dist/test/unit/transaction.js | AI (source-diff): Compiled TypeScript unit test; no malicious content. | ai | |
| source-diff | obfuscated-file:dist/test/unit/transactionBuilder/transactionBuilder.js | AI (source-diff): Compiled TypeScript unit test; no malicious content. | ai | |
| source-diff | obfuscated-file:dist/test/unit/transactionBuilder/transferBuilder.js | AI (source-diff): Compiled TypeScript unit test; no malicious content. | ai | |
| source-diff | obfuscated-file:dist/test/unit/utils.js | AI (source-diff): Compiled TypeScript unit test; no malicious content. | ai | |
| maintainer-change | maintainer-takeover | AI (maintainer-change): BitGo monorepo CI/CD migration to bitgobot/louib-bitgo with SLSA provenance; consistent with org-wide maintainer consolidation. | ai | |
| source-diff | obfuscated-file:dist/test/unit/transactionBuilder/StakingWithdrawRewardsBuilder.js | AI (source-diff): Compiled TypeScript unit test; no malicious content. | ai | |
| phantom-deps | phantom-dep:@cosmjs/encoding | AI (phantom-deps): @cosmjs/encoding is a declared runtime dep used in config/type references; stable false positive for this package. | ai |
Versions (showing 47 of 47)
| Version | Deps | Published |
|---|---|---|
| 1.7.26 | 7 / 2 | |
| 1.7.25 | 7 / 2 | |
| 1.7.23 | 7 / 2 | |
| 1.7.22 | 7 / 2 | |
| 1.7.21 | 7 / 2 | |
| 1.7.20 | 7 / 2 | |
| 1.7.19 | 7 / 2 | |
| 1.7.18 | 7 / 2 | |
| 1.7.17 | 7 / 2 | |
| 1.7.16 | 7 / 2 | |
| 1.7.15 | 7 / 2 | |
| 1.7.14 | 7 / 2 | |
| 1.7.13 | 7 / 2 | |
| 1.7.12 | 7 / 2 | |
| 1.7.11 | 7 / 2 | |
| 1.7.10 | 7 / 2 | |
| 1.7.9 | 7 / 2 | |
| 1.7.8 | 7 / 2 | |
| 1.7.7 | 7 / 2 | |
| 1.7.6 | 7 / 2 | |
| 1.7.4 | 7 / 2 | |
| 1.5.24 | 7 / 2 | |
| 1.5.9 | 7 / 2 | |
| 1.5.7 | 7 / 2 | |
| 1.5.2 | 7 / 2 | |
| 1.5.1 | 7 / 2 | |
| 1.5.0 | 7 / 2 | |
| 1.4.3 | 7 / 2 | |
| 1.4.2 | 7 / 2 | |
| 1.4.1 | 7 / 2 | |
| 1.4.0 | 7 / 2 | |
| 1.3.3 | 7 / 2 | |
| 1.3.2 | 7 / 2 | |
| 1.3.1 | 7 / 2 | |
| 1.3.0 | 7 / 2 | |
| 1.2.6 | 7 / 2 | |
| 1.2.5 | 7 / 2 | |
| 1.2.4 | 7 / 2 | |
| 1.2.3 | 7 / 2 | |
| 1.2.2 | 7 / 2 | |
| 1.2.1 | 7 / 2 | |
| 1.2.0 | 7 / 2 | |
| 1.1.4 | 7 / 2 | |
| 1.1.3 | 7 / 2 | |
| 1.1.2 | 7 / 2 | |
| 1.1.1 | 7 / 2 | |
| 1.1.0 | 7 / 2 |
v1.7.26
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.7.25
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.7.23
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.7.22
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.7.21
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.7.20
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.