@bitgo/sdk-coin-mantra
BitGo SDK coin library for Mantra
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): zahin-mohammad → bitgobot is a legitimate BitGo org consolidation, not a compromise. | ai | |
| source-diff | obfuscated-file:dist/test/unit/keyPair.js | AI (source-diff): Compiled TypeScript test file; long lines are base64 test fixtures, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/test/resources/mantra.js | AI (source-diff): Test resource file with base64-encoded transaction fixtures; benign for this package. | ai | |
| source-diff | obfuscated-file:dist/test/unit/mantra.js | AI (source-diff): Compiled TypeScript test file; long lines are test data, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/test/unit/transaction.js | AI (source-diff): Compiled TypeScript test file; standard pattern, not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/test/unit/transactionBuilder/transactionBuilder.js | AI (source-diff): Compiled TypeScript test file; standard pattern, not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/test/unit/transactionBuilder/transferBuilder.js | AI (source-diff): Compiled TypeScript test file; standard pattern, not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/test/unit/utils.js | AI (source-diff): Compiled TypeScript test file; standard pattern, not obfuscated. | ai | |
| maintainer-change | maintainer-takeover | AI (maintainer-change): BitGo consolidating to bitgobot publisher; consistent with 118 approved packages under same account. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): bitgobot is BitGo's established bot publisher with strong track record. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Removal of individual maintainers in favor of bitgobot is a known BitGo org-wide pattern. | ai | |
| phantom-deps | phantom-dep:@cosmjs/encoding | AI (phantom-deps): @cosmjs/encoding is a declared runtime dep used in config/type references; stable false positive for this package. | ai |
Versions (showing 51 of 91)
| Version | Deps | Published |
|---|---|---|
| 1.5.26 | 7 / 2 | |
| 1.5.25 | 7 / 2 | |
| 1.5.23 | 7 / 2 | |
| 1.5.22 | 7 / 2 | |
| 1.5.21 | 7 / 2 | |
| 1.5.20 | 7 / 2 | |
| 1.5.19 | 7 / 2 | |
| 1.5.18 | 7 / 2 | |
| 1.5.17 | 7 / 2 | |
| 1.5.16 | 7 / 2 | |
| 1.5.15 | 7 / 2 | |
| 1.5.14 | 7 / 2 | |
| 1.5.13 | 7 / 2 | |
| 1.5.12 | 7 / 2 | |
| 1.5.11 | 7 / 2 | |
| 1.5.10 | 7 / 2 | |
| 1.5.9 | 7 / 2 | |
| 1.5.8 | 7 / 2 | |
| 1.5.7 | 7 / 2 | |
| 1.5.6 | 7 / 2 | |
| 1.5.5 | 7 / 2 | |
| 1.5.4 | 7 / 2 | |
| 1.5.3 | 7 / 2 | |
| 1.5.2 | 7 / 2 | |
| 1.5.1 | 7 / 2 | |
| 1.5.0 | 7 / 2 | |
| 1.4.9 | 7 / 2 | |
| 1.4.8 | 7 / 2 | |
| 1.4.7 | 7 / 2 | |
| 1.4.6 | 7 / 2 | |
| 1.4.5 | 7 / 2 | |
| 1.4.4 | 7 / 2 | |
| 1.4.3 | 7 / 2 | |
| 1.4.2 | 7 / 2 | |
| 1.4.1 | 7 / 2 | |
| 1.4.0 | 7 / 2 | |
| 1.3.24 | 7 / 2 | |
| 1.3.22 | 7 / 2 | |
| 1.3.21 | 7 / 2 | |
| 1.3.20 | 7 / 2 | |
| 1.3.19 | 7 / 2 | |
| 1.3.18 | 7 / 2 | |
| 1.3.17 | 7 / 2 | |
| 1.3.16 | 7 / 2 | |
| 1.3.15 | 7 / 2 | |
| 1.3.14 | 7 / 2 | |
| 1.3.13 | 7 / 2 | |
| 1.3.12 | 7 / 2 | |
| 1.3.11 | 7 / 2 | |
| 1.3.10 | 7 / 2 | |
| 1.3.9 | 7 / 2 |
v1.5.26
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.5.25
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.5.23
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.5.22
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.5.21
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.5.20
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.