@bitgo/sdk-coin-near
BitGo SDK coin library for Near
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/src/lib/fungibleTokenTransferBuilder.js | AI (source-diff): Standard tsc-compiled CommonJS output; long lines are TypeScript boilerplate, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/src/lib/storageDepositTransferBuilder.js | AI (source-diff): Standard tsc-compiled CommonJS output; long lines are TypeScript boilerplate, not obfuscation. | ai | |
| phantom-deps | phantom-dep:@bitgo/sdk-lib-mpc | AI (phantom-deps): Same org scope; phantom-dep heuristic unreliable for transpiled/bundled output. | ai | |
| phantom-deps | phantom-dep:bs58 | AI (phantom-deps): TypeScript SDK package; phantom-dep heuristic unreliable for transpiled/bundled output. | ai | |
| phantom-deps | phantom-dep:lodash | AI (phantom-deps): TypeScript SDK package; phantom-dep heuristic unreliable for transpiled/bundled output. | ai | |
| phantom-deps | phantom-dep:js-sha256 | AI (phantom-deps): TypeScript SDK package; phantom-dep heuristic unreliable for transpiled/bundled output. | ai | |
| phantom-deps | phantom-dep:tweetnacl | AI (phantom-deps): TypeScript SDK package; phantom-dep heuristic unreliable for transpiled/bundled output. | ai | |
| phantom-deps | phantom-dep:superagent | AI (phantom-deps): TypeScript SDK package; phantom-dep heuristic unreliable for transpiled/bundled output. | ai | |
| phantom-deps | phantom-dep:near-api-js | AI (phantom-deps): TypeScript SDK package; phantom-dep heuristic unreliable for transpiled/bundled output. | ai | |
| phantom-deps | phantom-dep:bignumber.js | AI (phantom-deps): TypeScript SDK package; phantom-dep heuristic unreliable for transpiled/bundled output. | ai | |
| phantom-deps | phantom-dep:@bitgo/statics | AI (phantom-deps): Same org scope; phantom-dep heuristic unreliable for transpiled/bundled output. | ai | |
| phantom-deps | phantom-dep:@stablelib/hex | AI (phantom-deps): TypeScript SDK package; phantom-dep heuristic unreliable for transpiled/bundled output. | ai | |
| phantom-deps | phantom-dep:@bitgo/sdk-core | AI (phantom-deps): Same org scope; phantom-dep heuristic unreliable for transpiled/bundled output. | ai | |
| phantom-deps | phantom-dep:@near-js/crypto | AI (phantom-deps): TypeScript SDK package; phantom-dep heuristic unreliable for transpiled/bundled output. | ai | |
| phantom-deps | phantom-dep:@near-js/transactions | AI (phantom-deps): TypeScript SDK package; phantom-dep heuristic unreliable for transpiled/bundled output. | ai | |
| source-diff | obfuscated-file:dist/test/unit/transactionBuilder/metaPoolWithdrawBuilder.js | AI (source-diff): Compiled TypeScript test file; standard TS boilerplate with test fixtures. | ai | |
| source-diff | obfuscated-file:dist/test/unit/transactionBuilder/fungibleTokenTransferBuilder.js | AI (source-diff): TypeScript-compiled test file; long lines from inline test data, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/test/unit/keyPair.js | AI (source-diff): TypeScript-compiled test file; standard TS boilerplate pattern. | ai | |
| source-diff | obfuscated-file:dist/test/fixtures/near.js | AI (source-diff): Test fixture file with long inline data strings; not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/test/resources/near.js | AI (source-diff): Test resource file with long inline data strings; not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/test/unit/near.js | AI (source-diff): TypeScript-compiled test file; standard TS boilerplate pattern. | ai | |
| source-diff | obfuscated-file:dist/test/unit/nep141Token.js | AI (source-diff): TypeScript-compiled test file; standard TS boilerplate pattern. | ai | |
| source-diff | obfuscated-file:dist/test/unit/transactionBuilder/stakingActivateBuilder.js | AI (source-diff): TypeScript-compiled test file; standard TS boilerplate pattern. | ai | |
| source-diff | obfuscated-file:dist/test/unit/transactionBuilder/stakingDeactivateBuilder.js | AI (source-diff): TypeScript-compiled test file; standard TS boilerplate pattern. | ai | |
| source-diff | obfuscated-file:dist/test/unit/transactionBuilder/stakingWithdrawBuilder.js | AI (source-diff): TypeScript-compiled test file; standard TS boilerplate pattern. | ai | |
| source-diff | obfuscated-file:dist/test/unit/transactionBuilder/storageDepositTransferBuilder.js | AI (source-diff): TypeScript-compiled test file; standard TS boilerplate pattern. | ai | |
| source-diff | obfuscated-file:dist/test/unit/tokenEnablementValidation.js | AI (source-diff): TypeScript-compiled test file; standard TS boilerplate pattern. | ai | |
| source-diff | obfuscated-file:dist/test/unit/transaction.js | AI (source-diff): TypeScript-compiled test file; standard TS boilerplate pattern. | ai | |
| source-diff | obfuscated-file:dist/test/unit/transactionBuilder/transactionBuilder.js | AI (source-diff): TypeScript-compiled test file; standard TS boilerplate pattern. | ai | |
| source-diff | obfuscated-file:dist/test/unit/transactionBuilder/transferBuilder.js | AI (source-diff): TypeScript-compiled test file; standard TS boilerplate pattern. | ai | |
| source-diff | obfuscated-file:dist/test/unit/utils.js | AI (source-diff): TypeScript-compiled test file; standard TS boilerplate pattern. | ai | |
| maintainer-change | maintainer-takeover | AI (maintainer-change): BitGo consolidating to bitgobot CI account; consistent with 498 approved packages from same publisher. | ai | |
| provenance | publisher-changed | AI (provenance): Both publishers are BitGo org accounts; transition appears to be an internal maintainer rotation. | ai | |
| provenance | no-provenance | AI (provenance): BitGo monorepo packages consistently lack Sigstore provenance; stable false positive for this package family. | ai | |
| dependencies | unvetted-dep:@bitgo/sdk-lib-mpc | AI (dependencies): Internal BitGo monorepo dependency; expected and stable for this package family. | ai | |
| dependencies | unvetted-dep:@bitgo/sdk-core | AI (dependencies): Internal BitGo monorepo dependency; expected and stable for this package family. | ai |
Versions (showing 100 of 152)
| Version | Deps | Published |
|---|---|---|
| 3.0.4 | 13 / 3 | |
| 3.0.3 | 13 / 3 | |
| 3.0.1 | 13 / 3 | |
| 3.0.0 | 13 / 3 | |
| 2.18.11 | 13 / 3 | |
| 2.18.10 | 13 / 3 | |
| 2.18.9 | 13 / 3 | |
| 2.18.8 | 13 / 3 | |
| 2.18.7 | 13 / 3 | |
| 2.18.6 | 13 / 3 | |
| 2.18.5 | 13 / 3 | |
| 2.18.4 | 13 / 3 | |
| 2.18.3 | 13 / 3 | |
| 2.18.2 | 13 / 3 | |
| 2.18.1 | 13 / 3 | |
| 2.18.0 | 13 / 3 | |
| 2.17.9 | 13 / 3 | |
| 2.17.8 | 13 / 3 | |
| 2.17.7 | 13 / 3 | |
| 2.17.6 | 13 / 3 | |
| 2.17.5 | 13 / 3 | |
| 2.17.4 | 13 / 3 | |
| 2.17.3 | 13 / 3 | |
| 2.17.2 | 13 / 3 | |
| 2.17.1 | 13 / 3 | |
| 2.17.0 | 13 / 3 | |
| 2.16.5 | 13 / 3 | |
| 2.16.4 | 13 / 3 | |
| 2.16.3 | 13 / 3 | |
| 2.16.2 | 13 / 3 | |
| 2.16.1 | 13 / 3 | |
| 2.16.0 | 13 / 3 | |
| 2.15.3 | 13 / 3 | |
| 2.15.2 | 13 / 3 | |
| 2.15.1 | 13 / 3 | |
| 2.15.0 | 13 / 3 | |
| 2.14.4 | 13 / 3 | |
| 2.14.2 | 13 / 3 | |
| 2.14.1 | 13 / 3 | |
| 2.14.0 | 13 / 3 | |
| 2.13.10 | 13 / 3 | |
| 2.13.9 | 13 / 3 | |
| 2.13.8 | 13 / 3 | |
| 2.13.7 | 13 / 3 | |
| 2.13.6 | 13 / 3 | |
| 2.13.5 | 13 / 3 | |
| 2.13.4 | 13 / 3 | |
| 2.13.3 | 13 / 3 | |
| 2.13.2 | 13 / 3 | |
| 2.13.1 | 13 / 3 | |
| 2.13.0 | 13 / 3 | |
| 2.12.0 | 13 / 3 | |
| 2.11.7 | 13 / 3 | |
| 2.11.6 | 13 / 3 | |
| 2.11.5 | 13 / 3 | |
| 2.11.4 | 13 / 3 | |
| 2.11.3 | 13 / 3 | |
| 2.11.2 | 13 / 3 | |
| 2.11.1 | 13 / 3 | |
| 2.11.0 | 13 / 3 | |
| 2.10.4 | 13 / 3 | |
| 2.10.3 | 13 / 3 | |
| 2.10.2 | 13 / 3 | |
| 2.10.1 | 13 / 3 | |
| 2.10.0 | 13 / 3 | |
| 2.9.4 | 13 / 3 | |
| 2.9.3 | 13 / 3 | |
| 2.9.2 | 13 / 3 | |
| 2.9.1 | 13 / 3 | |
| 2.9.0 | 13 / 3 | |
| 2.8.3 | 13 / 3 | |
| 2.8.2 | 13 / 3 | |
| 2.8.1 | 13 / 3 | |
| 2.8.0 | 13 / 3 | |
| 2.7.0 | 13 / 3 | |
| 2.6.1 | 13 / 3 | |
| 2.6.0 | 13 / 3 | |
| 2.4.1 | 12 / 3 | |
| 2.4.0 | 12 / 3 | |
| 2.3.0 | 12 / 3 | |
| 2.2.1 | 11 / 3 | |
| 2.2.0 | 11 / 3 | |
| 2.1.5 | 11 / 3 | |
| 2.1.4 | 11 / 3 | |
| 2.1.3 | 11 / 3 | |
| 2.1.2 | 11 / 3 | |
| 2.1.1 | 11 / 3 | |
| 2.1.0 | 11 / 3 | |
| 2.0.74 | 11 / 3 | |
| 2.0.73 | 11 / 3 | |
| 2.0.72 | 11 / 3 | |
| 2.0.71 | 11 / 3 | |
| 2.0.70 | 11 / 3 | |
| 2.0.69 | 11 / 3 | |
| 2.0.68 | 11 / 3 | |
| 2.0.67 | 11 / 3 | |
| 2.0.66 | 11 / 3 | |
| 2.0.65 | 11 / 3 | |
| 2.0.64 | 11 / 3 | |
| 2.0.63 | 11 / 3 |
v3.0.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.0.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.0.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.18.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.18.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.74
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.73
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.72
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.71
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.70
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.69
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.68
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.67
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.66
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.65
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.64
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.63
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.