@bitgo/sdk-coin-dot
BitGo SDK coin library for Polkadot
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | large-new-source-files | AI (source-diff): New compiled test/dist files from normal build output, not injected code. | ai | |
| source-diff | obfuscated-file:dist/test/unit/address.js | AI (source-diff): Long-line compiled test fixture, not true obfuscation; no malicious payload. | ai | |
| source-diff | encoded-string-file:dist/src/resources/westend.d.ts | AI (source-diff): Type declaration mirrors the same benign hex metadata constant. | ai | |
| source-diff | encoded-string-file:dist/src/resources/mainnet.js | AI (source-diff): SCALE-encoded Polkadot chain metadata, not obfuscation. | ai | |
| source-diff | encoded-string-file:dist/src/resources/westend.js | AI (source-diff): SCALE-encoded Polkadot chain metadata, not obfuscation. | ai | |
| source-diff | encoded-string-file:dist/src/resources/mainnet.d.ts | AI (source-diff): Type declaration mirrors the same benign hex metadata constant. | ai | |
| phantom-deps | phantom-dep:@polkadot/keyring | AI (phantom-deps): Transitive dependency via @polkadot modules; declared and used indirectly. | ai | |
| phantom-deps | phantom-dep:@bitgo/sdk-lib-mpc | AI (phantom-deps): Same-org dependency; used transitively through @bitgo/sdk-core. | ai | |
| phantom-deps | phantom-dep:@polkadot/api-augment | AI (phantom-deps): Transitive dependency via @polkadot/api; declared and used indirectly. | ai | |
| phantom-deps | phantom-dep:@polkadot/util-crypto | AI (phantom-deps): Transitive dependency via @polkadot modules; declared and used indirectly. | ai | |
| phantom-deps | phantom-dep:@substrate/txwrapper-core | AI (phantom-deps): Direct dependency for Substrate integration; used via re-exports. | ai | |
| phantom-deps | phantom-dep:@substrate/txwrapper-polkadot | AI (phantom-deps): Direct dependency for Polkadot transaction wrapping; used via re-exports. | ai | |
| phantom-deps | phantom-dep:joi | AI (phantom-deps): Transitive dependency via @bitgo/sdk-core; declared and used indirectly. | ai | |
| phantom-deps | phantom-dep:bs58 | AI (phantom-deps): Transitive dependency via @bitgo/sdk-core; declared and used indirectly. | ai | |
| phantom-deps | phantom-dep:lodash | AI (phantom-deps): Transitive dependency via @bitgo/sdk-core; declared and used indirectly. | ai | |
| phantom-deps | phantom-dep:hi-base32 | AI (phantom-deps): Transitive dependency via @polkadot modules; declared and used indirectly. | ai | |
| phantom-deps | phantom-dep:bignumber.js | AI (phantom-deps): Transitive dependency via @bitgo/sdk-core; declared and used indirectly. | ai | |
| phantom-deps | phantom-dep:tweetnacl | AI (phantom-deps): Transitive dependency via @polkadot/util-crypto; declared and used indirectly. | ai | |
| phantom-deps | phantom-dep:@polkadot/api | AI (phantom-deps): Direct dependency for Polkadot integration; used via re-exports. | ai | |
| phantom-deps | phantom-dep:@bitgo/statics | AI (phantom-deps): Same-org dependency; used transitively through @bitgo/sdk-core. | ai | |
| phantom-deps | phantom-dep:@polkadot/util | AI (phantom-deps): Transitive dependency via @polkadot modules; declared and used indirectly. | ai | |
| phantom-deps | phantom-dep:@bitgo/sdk-core | AI (phantom-deps): Same-org dependency; primary peer for this coin module. | ai | |
| phantom-deps | phantom-dep:@polkadot/types | AI (phantom-deps): Transitive dependency via @polkadot modules; declared and used indirectly. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Previous maintainers were BitGo employees; removal is part of org-wide CI migration. | ai | |
| source-diff | obfuscated-file:dist/cjs/src/resources/mainnet.js | AI (source-diff): Long lines are Polkadot chain metadata JSON, not obfuscation; stable pattern for this package. | ai | |
| source-diff | obfuscated-file:dist/esm/resources/mainnet.js | AI (source-diff): Same as CJS counterpart — chain metadata, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/cjs/src/resources/polkadotAssetHub.js | AI (source-diff): Polkadot AssetHub chain metadata; long lines expected. | ai | |
| source-diff | obfuscated-file:dist/esm/resources/polkadotAssetHub.js | AI (source-diff): Polkadot AssetHub chain metadata; long lines expected. | ai | |
| source-diff | obfuscated-file:dist/cjs/src/lib/addressInitializationBuilder.js | AI (source-diff): Standard TypeScript CJS compiled output; readable source visible in sample. | ai | |
| source-diff | obfuscated-file:dist/esm/lib/addressInitializationBuilder.js | AI (source-diff): Standard TypeScript ESM compiled output; readable source visible in sample. | ai | |
| source-diff | obfuscated-file:dist/cjs/src/lib/batchTransactionBuilder.js | AI (source-diff): Standard TypeScript CJS compiled output; readable source visible in sample. | ai | |
| source-diff | obfuscated-file:dist/esm/lib/batchTransactionBuilder.js | AI (source-diff): Standard TypeScript ESM compiled output; readable source visible in sample. | ai | |
| provenance | publisher-changed | AI (provenance): BitGo migrated to GitHub Actions CI publishing with SLSA provenance; expected pattern. | ai | |
| maintainer-change | maintainer-takeover | AI (maintainer-change): BitGo internal maintainer rotation to CI bot accounts; SLSA provenance confirms legitimate CI publish. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): louib-bitgo and bitgobot are BitGo org accounts; consistent with CI automation. | ai | |
| provenance | no-provenance | AI (provenance): BitGo monorepo packages consistently lack Sigstore provenance; stable false positive for this package family. | ai | |
| dependencies | unvetted-dep:@bitgo/sdk-core | AI (dependencies): Core BitGo SDK dependency; expected and stable for this package family. | ai | |
| dependencies | unvetted-dep:@substrate/txwrapper-polkadot | AI (dependencies): Official Substrate/Polkadot transaction wrapper; expected for this coin SDK. | ai | |
| dependencies | unvetted-dep:@substrate/txwrapper-core | AI (dependencies): Official Substrate transaction wrapper; expected for Polkadot coin support. | ai | |
| dependencies | unvetted-dep:@bitgo/sdk-lib-mpc | AI (dependencies): BitGo MPC library; standard dependency across BitGo SDK coin modules. | ai | |
| dependencies | unvetted-dep:@bitgo/wasm-dot | AI (dependencies): BitGo-owned WASM module for Polkadot; expected dependency for this coin SDK. | ai |
Versions (showing 17 of 117)
| Version | Deps | Published |
|---|---|---|
| 4.1.6 | 17 / 3 | |
| 4.1.5 | 17 / 3 | |
| 4.1.2 | 17 / 3 | |
| 4.1.1 | 16 / 3 | |
| 4.1.0 | 16 / 3 | |
| 4.0.21 | 16 / 3 | |
| 4.0.20 | 16 / 3 | |
| 4.0.19 | 16 / 3 | |
| 4.0.18 | 16 / 3 | |
| 4.0.17 | 16 / 3 | |
| 4.0.16 | 16 / 3 | |
| 4.0.15 | 16 / 3 | |
| 4.0.14 | 16 / 3 | |
| 4.0.13 | 16 / 3 | |
| 4.0.12 | 16 / 3 | |
| 4.0.11 | 16 / 3 | |
| 4.0.10 | 16 / 3 |
v4.1.6
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2024-07-30. This could indicate a legitimate maintainer transition or an account compromise.
v4.1.5
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2024-07-24. This could indicate a legitimate maintainer transition or an account compromise.
v4.1.2
6 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2024-07-02. This could indicate a legitimate maintainer transition or an account compromise.
v4.1.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.1.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.21
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.20
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alebusse) than the most recent previously approved version (pengyuc_bitgo) on 2024-06-20, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.0.19
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (margueriteblair) than the most recent previously approved version (pengyuc_bitgo) on 2024-06-14, but margueriteblair is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.0.18
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (pengyuc_bitgo) than the most recent previously approved version (alebusse) on 2024-06-11, but pengyuc_bitgo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.0.17
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (margueriteblair) than the most recent previously approved version (alebusse) on 2024-06-05, but margueriteblair is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.0.16
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alebusse) than the most recent previously approved version (zahin-mohammad) on 2024-05-31, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.0.15
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (zahin-mohammad) than the most recent previously approved version (pengyuc_bitgo) on 2024-05-28, but zahin-mohammad is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.0.14
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (pengyuc_bitgo) than the most recent previously approved version (margueriteblair) on 2024-05-22, but pengyuc_bitgo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.0.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.12
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (margueriteblair) than the most recent previously approved version (pengyuc_bitgo) on 2024-05-13, but margueriteblair is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.0.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.