@bitgo/sdk-coin-bera
BitGo SDK coin library for Bera
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | source-size-tripled | AI (source-diff): Size increase explained by newly included compiled test files in dist/test/. | ai | |
| maintainer-change | maintainer-takeover | AI (maintainer-change): bitgobot is BitGo's automation account with strong approval track record; org-wide publisher consolidation. | ai | |
| source-diff | obfuscated-file:dist/test/resources.d.ts | AI (source-diff): Same pattern: hex bytecode constant in TypeScript declaration file. | ai | |
| source-diff | obfuscated-file:dist/test/unit/bera.js | AI (source-diff): Compiled TypeScript test file; long lines are inline sourcemaps. | ai | |
| source-diff | obfuscated-file:dist/test/unit/beraToken.js | AI (source-diff): Compiled TypeScript test file; long lines are inline sourcemaps. | ai | |
| source-diff | obfuscated-file:dist/test/unit/transactionBuilder/addressInitialization.js | AI (source-diff): Compiled TypeScript test file; long lines are inline sourcemaps. | ai | |
| source-diff | obfuscated-file:dist/test/unit/transactionBuilder/send.js | AI (source-diff): Compiled TypeScript test file; long lines are inline sourcemaps. | ai | |
| source-diff | obfuscated-file:dist/test/fixtures/bera.js | AI (source-diff): Compiled TypeScript test fixture; long lines are hex bytecode constants. | ai | |
| provenance | publisher-changed | AI (provenance): BitGo migrated to bitgobot publisher account; consistent with 118 approved packages from same account. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): BitGo org-wide maintainer consolidation to bitgobot; not a takeover signal. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): BitGo org-wide maintainer consolidation; removals paired with known bot account addition. | ai | |
| source-diff | obfuscated-file:dist/test/unit/transaction.js | AI (source-diff): Compiled TypeScript test file; long lines are inline sourcemaps. | ai | |
| source-diff | obfuscated-file:dist/test/resources.js | AI (source-diff): Long lines are hex-encoded Ethereum bytecode in test fixtures, not obfuscation. | ai | |
| phantom-deps | phantom-dep:@bitgo/secp256k1 | AI (phantom-deps): Same-org dependency declared in package.json; stable false positive for this BitGo package. | ai |
Versions (showing 51 of 154)
| Version | Deps | Published |
|---|---|---|
| 2.8.26 | 5 / 2 | |
| 2.8.25 | 5 / 2 | |
| 2.8.23 | 5 / 2 | |
| 2.8.22 | 5 / 2 | |
| 2.8.21 | 5 / 2 | |
| 2.8.20 | 5 / 2 | |
| 2.8.19 | 5 / 2 | |
| 2.8.18 | 5 / 2 | |
| 2.8.17 | 5 / 2 | |
| 2.8.16 | 5 / 2 | |
| 2.8.15 | 5 / 2 | |
| 2.8.14 | 5 / 2 | |
| 2.8.13 | 5 / 2 | |
| 2.8.12 | 5 / 2 | |
| 2.8.11 | 5 / 2 | |
| 2.8.10 | 5 / 2 | |
| 2.8.9 | 5 / 2 | |
| 2.8.8 | 5 / 2 | |
| 2.8.7 | 5 / 2 | |
| 2.8.6 | 5 / 2 | |
| 2.8.5 | 5 / 2 | |
| 2.8.4 | 5 / 2 | |
| 2.8.3 | 5 / 2 | |
| 2.8.2 | 5 / 2 | |
| 2.8.1 | 5 / 2 | |
| 2.8.0 | 5 / 2 | |
| 2.7.9 | 5 / 2 | |
| 2.7.8 | 5 / 2 | |
| 2.7.7 | 5 / 2 | |
| 2.7.6 | 5 / 2 | |
| 2.7.5 | 5 / 2 | |
| 2.7.4 | 5 / 2 | |
| 2.7.3 | 5 / 2 | |
| 2.7.2 | 5 / 2 | |
| 2.7.1 | 5 / 2 | |
| 2.7.0 | 5 / 2 | |
| 2.6.24 | 5 / 2 | |
| 2.6.22 | 5 / 2 | |
| 2.6.21 | 5 / 2 | |
| 2.6.20 | 5 / 2 | |
| 2.6.19 | 5 / 2 | |
| 2.6.18 | 5 / 2 | |
| 2.6.17 | 5 / 2 | |
| 2.6.16 | 5 / 2 | |
| 2.6.15 | 5 / 2 | |
| 2.6.14 | 5 / 2 | |
| 2.6.13 | 5 / 2 | |
| 2.6.12 | 5 / 2 | |
| 2.6.11 | 5 / 2 | |
| 2.6.10 | 5 / 2 | |
| 2.6.9 | 5 / 2 |
v2.8.26
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.8.25
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.8.23
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.8.22
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.8.21
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.8.20
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.