@bitgo/sdk-coin-kaspa
BitGo's SDK coin library for Kaspa (KASPA)
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/src/lib/pskt.js | AI (source-diff): Compiled TypeScript with long fixture/data lines; not obfuscated. Stable pattern for this BitGo SDK package. | ai | |
| source-diff | obfuscated-file:dist/test/unit/pskt.test.js | AI (source-diff): Compiled test file with long fixture data; not obfuscated. Stable pattern for this BitGo SDK package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Stub placeholder by established @bitgo publisher; sparse metadata is expected for initial namespace reservation. | ai | |
| dependencies | unvetted-dep:@bitgo/sdk-core | AI (dependencies): Internal BitGo monorepo dependency; stable false positive for all @bitgo/sdk-coin-kaspa versions. | ai |
Versions (showing 23 of 23)
| Version | Deps | Published |
|---|---|---|
| 1.3.18 | 6 / 0 | |
| 1.3.17 | 6 / 0 | |
| 1.3.16 | 6 / 0 | |
| 1.3.14 | 6 / 0 | |
| 1.3.13 | 6 / 0 | |
| 1.3.12 | 6 / 0 | |
| 1.3.11 | 6 / 0 | |
| 1.3.10 | 6 / 0 | |
| 1.3.9 | 6 / 0 | |
| 1.3.8 | 6 / 0 | |
| 1.3.7 | 6 / 0 | |
| 1.3.6 | 6 / 0 | |
| 1.3.5 | 6 / 0 | |
| 1.3.4 | 6 / 0 | |
| 1.3.3 | 6 / 0 | |
| 1.3.2 | 6 / 0 | |
| 1.3.1 | 6 / 0 | |
| 1.3.0 | 6 / 0 | |
| 1.2.0 | 5 / 0 | |
| 1.1.2 | 5 / 0 | |
| 1.1.1 | 5 / 0 | |
| 1.1.0 | 5 / 0 | |
| 0.0.1 | 0 / 0 |
v1.3.18
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.3.17
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.3.16
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.3.14
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.3.13
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.3.12
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.3.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.