@bitgo/sdk-coin-dot
BitGo SDK coin library for Polkadot
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | large-new-source-files | AI (source-diff): New compiled test/dist files from normal build output, not injected code. | ai | |
| source-diff | obfuscated-file:dist/test/unit/address.js | AI (source-diff): Long-line compiled test fixture, not true obfuscation; no malicious payload. | ai | |
| source-diff | encoded-string-file:dist/src/resources/westend.d.ts | AI (source-diff): Type declaration mirrors the same benign hex metadata constant. | ai | |
| source-diff | encoded-string-file:dist/src/resources/mainnet.js | AI (source-diff): SCALE-encoded Polkadot chain metadata, not obfuscation. | ai | |
| source-diff | encoded-string-file:dist/src/resources/westend.js | AI (source-diff): SCALE-encoded Polkadot chain metadata, not obfuscation. | ai | |
| source-diff | encoded-string-file:dist/src/resources/mainnet.d.ts | AI (source-diff): Type declaration mirrors the same benign hex metadata constant. | ai | |
| phantom-deps | phantom-dep:@polkadot/keyring | AI (phantom-deps): Transitive dependency via @polkadot modules; declared and used indirectly. | ai | |
| phantom-deps | phantom-dep:@bitgo/sdk-lib-mpc | AI (phantom-deps): Same-org dependency; used transitively through @bitgo/sdk-core. | ai | |
| phantom-deps | phantom-dep:@polkadot/api-augment | AI (phantom-deps): Transitive dependency via @polkadot/api; declared and used indirectly. | ai | |
| phantom-deps | phantom-dep:@polkadot/util-crypto | AI (phantom-deps): Transitive dependency via @polkadot modules; declared and used indirectly. | ai | |
| phantom-deps | phantom-dep:@substrate/txwrapper-core | AI (phantom-deps): Direct dependency for Substrate integration; used via re-exports. | ai | |
| phantom-deps | phantom-dep:@substrate/txwrapper-polkadot | AI (phantom-deps): Direct dependency for Polkadot transaction wrapping; used via re-exports. | ai | |
| phantom-deps | phantom-dep:joi | AI (phantom-deps): Transitive dependency via @bitgo/sdk-core; declared and used indirectly. | ai | |
| phantom-deps | phantom-dep:bs58 | AI (phantom-deps): Transitive dependency via @bitgo/sdk-core; declared and used indirectly. | ai | |
| phantom-deps | phantom-dep:lodash | AI (phantom-deps): Transitive dependency via @bitgo/sdk-core; declared and used indirectly. | ai | |
| phantom-deps | phantom-dep:hi-base32 | AI (phantom-deps): Transitive dependency via @polkadot modules; declared and used indirectly. | ai | |
| phantom-deps | phantom-dep:bignumber.js | AI (phantom-deps): Transitive dependency via @bitgo/sdk-core; declared and used indirectly. | ai | |
| phantom-deps | phantom-dep:tweetnacl | AI (phantom-deps): Transitive dependency via @polkadot/util-crypto; declared and used indirectly. | ai | |
| phantom-deps | phantom-dep:@polkadot/api | AI (phantom-deps): Direct dependency for Polkadot integration; used via re-exports. | ai | |
| phantom-deps | phantom-dep:@bitgo/statics | AI (phantom-deps): Same-org dependency; used transitively through @bitgo/sdk-core. | ai | |
| phantom-deps | phantom-dep:@polkadot/util | AI (phantom-deps): Transitive dependency via @polkadot modules; declared and used indirectly. | ai | |
| phantom-deps | phantom-dep:@bitgo/sdk-core | AI (phantom-deps): Same-org dependency; primary peer for this coin module. | ai | |
| phantom-deps | phantom-dep:@polkadot/types | AI (phantom-deps): Transitive dependency via @polkadot modules; declared and used indirectly. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Previous maintainers were BitGo employees; removal is part of org-wide CI migration. | ai | |
| source-diff | obfuscated-file:dist/cjs/src/resources/mainnet.js | AI (source-diff): Long lines are Polkadot chain metadata JSON, not obfuscation; stable pattern for this package. | ai | |
| source-diff | obfuscated-file:dist/esm/resources/mainnet.js | AI (source-diff): Same as CJS counterpart — chain metadata, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/cjs/src/resources/polkadotAssetHub.js | AI (source-diff): Polkadot AssetHub chain metadata; long lines expected. | ai | |
| source-diff | obfuscated-file:dist/esm/resources/polkadotAssetHub.js | AI (source-diff): Polkadot AssetHub chain metadata; long lines expected. | ai | |
| source-diff | obfuscated-file:dist/cjs/src/lib/addressInitializationBuilder.js | AI (source-diff): Standard TypeScript CJS compiled output; readable source visible in sample. | ai | |
| source-diff | obfuscated-file:dist/esm/lib/addressInitializationBuilder.js | AI (source-diff): Standard TypeScript ESM compiled output; readable source visible in sample. | ai | |
| source-diff | obfuscated-file:dist/cjs/src/lib/batchTransactionBuilder.js | AI (source-diff): Standard TypeScript CJS compiled output; readable source visible in sample. | ai | |
| source-diff | obfuscated-file:dist/esm/lib/batchTransactionBuilder.js | AI (source-diff): Standard TypeScript ESM compiled output; readable source visible in sample. | ai | |
| provenance | publisher-changed | AI (provenance): BitGo migrated to GitHub Actions CI publishing with SLSA provenance; expected pattern. | ai | |
| maintainer-change | maintainer-takeover | AI (maintainer-change): BitGo internal maintainer rotation to CI bot accounts; SLSA provenance confirms legitimate CI publish. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): louib-bitgo and bitgobot are BitGo org accounts; consistent with CI automation. | ai | |
| provenance | no-provenance | AI (provenance): BitGo monorepo packages consistently lack Sigstore provenance; stable false positive for this package family. | ai | |
| dependencies | unvetted-dep:@bitgo/sdk-core | AI (dependencies): Core BitGo SDK dependency; expected and stable for this package family. | ai | |
| dependencies | unvetted-dep:@substrate/txwrapper-polkadot | AI (dependencies): Official Substrate/Polkadot transaction wrapper; expected for this coin SDK. | ai | |
| dependencies | unvetted-dep:@substrate/txwrapper-core | AI (dependencies): Official Substrate transaction wrapper; expected for Polkadot coin support. | ai | |
| dependencies | unvetted-dep:@bitgo/sdk-lib-mpc | AI (dependencies): BitGo MPC library; standard dependency across BitGo SDK coin modules. | ai | |
| dependencies | unvetted-dep:@bitgo/wasm-dot | AI (dependencies): BitGo-owned WASM module for Polkadot; expected dependency for this coin SDK. | ai |
Versions (showing 100 of 117)
| Version | Deps | Published |
|---|---|---|
| 5.0.4 | 18 / 3 | |
| 5.0.3 | 18 / 3 | |
| 5.0.1 | 18 / 3 | |
| 5.0.0 | 18 / 3 | |
| 4.16.11 | 18 / 3 | |
| 4.16.10 | 18 / 3 | |
| 4.16.9 | 18 / 3 | |
| 4.16.8 | 18 / 3 | |
| 4.16.7 | 18 / 3 | |
| 4.16.6 | 18 / 3 | |
| 4.16.5 | 18 / 3 | |
| 4.16.4 | 18 / 3 | |
| 4.16.3 | 18 / 3 | |
| 4.16.2 | 18 / 3 | |
| 4.16.1 | 18 / 3 | |
| 4.16.0 | 18 / 3 | |
| 4.15.4 | 18 / 3 | |
| 4.15.3 | 18 / 3 | |
| 4.15.2 | 18 / 3 | |
| 4.15.1 | 18 / 3 | |
| 4.14.4 | 18 / 3 | |
| 4.14.3 | 18 / 3 | |
| 4.7.4 | 17 / 3 | |
| 4.7.3 | 17 / 3 | |
| 4.7.2 | 17 / 3 | |
| 4.4.4 | 17 / 3 | |
| 4.4.3 | 17 / 3 | |
| 4.4.2 | 17 / 3 | |
| 4.4.1 | 17 / 3 | |
| 4.4.0 | 17 / 3 | |
| 4.3.15 | 17 / 3 | |
| 4.3.14 | 17 / 3 | |
| 4.3.13 | 17 / 3 | |
| 4.3.12 | 17 / 3 | |
| 4.3.11 | 17 / 3 | |
| 4.3.10 | 17 / 3 | |
| 4.3.9 | 17 / 3 | |
| 4.3.8 | 17 / 3 | |
| 4.3.7 | 17 / 3 | |
| 4.3.6 | 17 / 3 | |
| 4.3.5 | 17 / 3 | |
| 4.3.4 | 17 / 3 | |
| 4.3.3 | 17 / 3 | |
| 4.3.2 | 17 / 3 | |
| 4.3.1 | 17 / 3 | |
| 4.3.0 | 17 / 3 | |
| 4.2.0 | 17 / 3 | |
| 4.1.60 | 17 / 3 | |
| 4.1.59 | 17 / 3 | |
| 4.1.58 | 17 / 3 | |
| 4.1.57 | 17 / 3 | |
| 4.1.56 | 17 / 3 | |
| 4.1.55 | 17 / 3 | |
| 4.1.54 | 17 / 3 | |
| 4.1.53 | 17 / 3 | |
| 4.1.52 | 17 / 3 | |
| 4.1.51 | 17 / 3 | |
| 4.1.50 | 17 / 3 | |
| 4.1.49 | 17 / 3 | |
| 4.1.48 | 17 / 3 | |
| 4.1.47 | 17 / 3 | |
| 4.1.46 | 17 / 3 | |
| 4.1.45 | 17 / 3 | |
| 4.1.44 | 17 / 3 | |
| 4.1.43 | 17 / 3 | |
| 4.1.42 | 17 / 3 | |
| 4.1.41 | 17 / 3 | |
| 4.1.40 | 17 / 3 | |
| 4.1.39 | 17 / 3 | |
| 4.1.38 | 17 / 3 | |
| 4.1.37 | 17 / 3 | |
| 4.1.36 | 17 / 3 | |
| 4.1.35 | 17 / 3 | |
| 4.1.34 | 17 / 3 | |
| 4.1.33 | 17 / 3 | |
| 4.1.32 | 17 / 3 | |
| 4.1.30 | 17 / 3 | |
| 4.1.29 | 17 / 3 | |
| 4.1.28 | 17 / 3 | |
| 4.1.27 | 17 / 3 | |
| 4.1.26 | 17 / 3 | |
| 4.1.25 | 17 / 3 | |
| 4.1.24 | 17 / 3 | |
| 4.1.23 | 17 / 3 | |
| 4.1.22 | 17 / 3 | |
| 4.1.21 | 17 / 3 | |
| 4.1.20 | 17 / 3 | |
| 4.1.19 | 17 / 3 | |
| 4.1.18 | 17 / 3 | |
| 4.1.17 | 17 / 3 | |
| 4.1.16 | 17 / 3 | |
| 4.1.15 | 17 / 3 | |
| 4.1.14 | 17 / 3 | |
| 4.1.13 | 17 / 3 | |
| 4.1.12 | 17 / 3 | |
| 4.1.11 | 17 / 3 | |
| 4.1.10 | 17 / 3 | |
| 4.1.9 | 17 / 3 | |
| 4.1.8 | 17 / 3 | |
| 4.1.7 | 17 / 3 |
v5.0.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.0.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.0.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.16.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.16.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.7.4
26 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2025-11-13. This could indicate a legitimate maintainer transition or an account compromise.
v4.7.3
26 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2025-11-12. This could indicate a legitimate maintainer transition or an account compromise.
v4.7.2
26 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2025-11-06. This could indicate a legitimate maintainer transition or an account compromise.
v4.1.55
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (mohammadalfaiyaz_bitgo) than the most recent previously approved version (pranavjain) on 2025-04-25, but mohammadalfaiyaz_bitgo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.1.54
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (pranavjain) than the most recent previously approved version (mohammadalfaiyaz_bitgo) on 2025-04-15, but pranavjain is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.1.53
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.1.52
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.1.51
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (mohammadalfaiyaz_bitgo) than the most recent previously approved version (pranavjain) on 2025-03-28, but mohammadalfaiyaz_bitgo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.1.50
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (pranavjain) than the most recent previously approved version (alebusse) on 2025-03-20, but pranavjain is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.1.49
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (pranavjain) than the most recent previously approved version (alebusse) on 2025-03-18, but pranavjain is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.1.48
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alebusse) than the most recent previously approved version (margueriteblair) on 2025-03-06, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.1.47
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.1.46
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.1.45
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.1.44
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.1.43
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.1.42
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.1.41
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.1.40
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.1.39
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.1.38
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.1.37
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alebusse) than the most recent previously approved version (margueriteblair) on 2025-01-15, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.1.36
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.1.35
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alebusse) than the most recent previously approved version (margueriteblair) on 2025-01-03, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.1.34
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.1.33
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.1.32
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.1.30
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (margueriteblair) than the most recent previously approved version (alebusse) on 2024-12-12, but margueriteblair is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.1.29
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alebusse) than the most recent previously approved version (margueriteblair) on 2024-12-11, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.1.28
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.1.27
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.1.26
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.1.25
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.1.24
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (margueriteblair) than the most recent previously approved version (pranavjain) on 2024-11-14, but margueriteblair is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.1.23
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (pengyuc_bitgo) than the most recent previously approved version (pranavjain) on 2024-11-08, but pengyuc_bitgo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.1.22
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (pranavjain) than the most recent previously approved version (margueriteblair) on 2024-11-07, but pranavjain is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.1.21
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alebusse) than the most recent previously approved version (margueriteblair) on 2024-11-01, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.1.20
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (margueriteblair) than the most recent previously approved version (pengyuc_bitgo) on 2024-10-22, but margueriteblair is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.1.19
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (margueriteblair) than the most recent previously approved version (pengyuc_bitgo) on 2024-10-15, but margueriteblair is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.1.18
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.1.17
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (pengyuc_bitgo) than the most recent previously approved version (alebusse) on 2024-10-04, but pengyuc_bitgo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.1.16
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alebusse) than the most recent previously approved version (pranavjain) on 2024-09-24, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.1.15
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (pranavjain) than the most recent previously approved version (zahin-mohammad) on 2024-09-19, but pranavjain is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.1.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.1.13
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (zahin-mohammad) than the most recent previously approved version (pengyuc_bitgo) on 2024-09-10, but zahin-mohammad is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.1.12
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (pengyuc_bitgo) than the most recent previously approved version (margueriteblair) on 2024-09-03, but pengyuc_bitgo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.1.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.1.10
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (margueriteblair) than the most recent previously approved version (pengyuc_bitgo) on 2024-08-27, but margueriteblair is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.1.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.1.8
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (pengyuc_bitgo) than the most recent previously approved version (margueriteblair) on 2024-08-13, but pengyuc_bitgo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.1.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.