@bitgo/sdk-coin-near
BitGo SDK coin library for Near
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/src/lib/fungibleTokenTransferBuilder.js | AI (source-diff): Standard tsc-compiled CommonJS output; long lines are TypeScript boilerplate, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/src/lib/storageDepositTransferBuilder.js | AI (source-diff): Standard tsc-compiled CommonJS output; long lines are TypeScript boilerplate, not obfuscation. | ai | |
| phantom-deps | phantom-dep:@bitgo/sdk-lib-mpc | AI (phantom-deps): Same org scope; phantom-dep heuristic unreliable for transpiled/bundled output. | ai | |
| phantom-deps | phantom-dep:bs58 | AI (phantom-deps): TypeScript SDK package; phantom-dep heuristic unreliable for transpiled/bundled output. | ai | |
| phantom-deps | phantom-dep:lodash | AI (phantom-deps): TypeScript SDK package; phantom-dep heuristic unreliable for transpiled/bundled output. | ai | |
| phantom-deps | phantom-dep:js-sha256 | AI (phantom-deps): TypeScript SDK package; phantom-dep heuristic unreliable for transpiled/bundled output. | ai | |
| phantom-deps | phantom-dep:tweetnacl | AI (phantom-deps): TypeScript SDK package; phantom-dep heuristic unreliable for transpiled/bundled output. | ai | |
| phantom-deps | phantom-dep:superagent | AI (phantom-deps): TypeScript SDK package; phantom-dep heuristic unreliable for transpiled/bundled output. | ai | |
| phantom-deps | phantom-dep:near-api-js | AI (phantom-deps): TypeScript SDK package; phantom-dep heuristic unreliable for transpiled/bundled output. | ai | |
| phantom-deps | phantom-dep:bignumber.js | AI (phantom-deps): TypeScript SDK package; phantom-dep heuristic unreliable for transpiled/bundled output. | ai | |
| phantom-deps | phantom-dep:@bitgo/statics | AI (phantom-deps): Same org scope; phantom-dep heuristic unreliable for transpiled/bundled output. | ai | |
| phantom-deps | phantom-dep:@stablelib/hex | AI (phantom-deps): TypeScript SDK package; phantom-dep heuristic unreliable for transpiled/bundled output. | ai | |
| phantom-deps | phantom-dep:@bitgo/sdk-core | AI (phantom-deps): Same org scope; phantom-dep heuristic unreliable for transpiled/bundled output. | ai | |
| phantom-deps | phantom-dep:@near-js/crypto | AI (phantom-deps): TypeScript SDK package; phantom-dep heuristic unreliable for transpiled/bundled output. | ai | |
| phantom-deps | phantom-dep:@near-js/transactions | AI (phantom-deps): TypeScript SDK package; phantom-dep heuristic unreliable for transpiled/bundled output. | ai | |
| source-diff | obfuscated-file:dist/test/unit/transactionBuilder/metaPoolWithdrawBuilder.js | AI (source-diff): Compiled TypeScript test file; standard TS boilerplate with test fixtures. | ai | |
| source-diff | obfuscated-file:dist/test/unit/transactionBuilder/fungibleTokenTransferBuilder.js | AI (source-diff): TypeScript-compiled test file; long lines from inline test data, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/test/unit/keyPair.js | AI (source-diff): TypeScript-compiled test file; standard TS boilerplate pattern. | ai | |
| source-diff | obfuscated-file:dist/test/fixtures/near.js | AI (source-diff): Test fixture file with long inline data strings; not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/test/resources/near.js | AI (source-diff): Test resource file with long inline data strings; not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/test/unit/near.js | AI (source-diff): TypeScript-compiled test file; standard TS boilerplate pattern. | ai | |
| source-diff | obfuscated-file:dist/test/unit/nep141Token.js | AI (source-diff): TypeScript-compiled test file; standard TS boilerplate pattern. | ai | |
| source-diff | obfuscated-file:dist/test/unit/transactionBuilder/stakingActivateBuilder.js | AI (source-diff): TypeScript-compiled test file; standard TS boilerplate pattern. | ai | |
| source-diff | obfuscated-file:dist/test/unit/transactionBuilder/stakingDeactivateBuilder.js | AI (source-diff): TypeScript-compiled test file; standard TS boilerplate pattern. | ai | |
| source-diff | obfuscated-file:dist/test/unit/transactionBuilder/stakingWithdrawBuilder.js | AI (source-diff): TypeScript-compiled test file; standard TS boilerplate pattern. | ai | |
| source-diff | obfuscated-file:dist/test/unit/transactionBuilder/storageDepositTransferBuilder.js | AI (source-diff): TypeScript-compiled test file; standard TS boilerplate pattern. | ai | |
| source-diff | obfuscated-file:dist/test/unit/tokenEnablementValidation.js | AI (source-diff): TypeScript-compiled test file; standard TS boilerplate pattern. | ai | |
| source-diff | obfuscated-file:dist/test/unit/transaction.js | AI (source-diff): TypeScript-compiled test file; standard TS boilerplate pattern. | ai | |
| source-diff | obfuscated-file:dist/test/unit/transactionBuilder/transactionBuilder.js | AI (source-diff): TypeScript-compiled test file; standard TS boilerplate pattern. | ai | |
| source-diff | obfuscated-file:dist/test/unit/transactionBuilder/transferBuilder.js | AI (source-diff): TypeScript-compiled test file; standard TS boilerplate pattern. | ai | |
| source-diff | obfuscated-file:dist/test/unit/utils.js | AI (source-diff): TypeScript-compiled test file; standard TS boilerplate pattern. | ai | |
| maintainer-change | maintainer-takeover | AI (maintainer-change): BitGo consolidating to bitgobot CI account; consistent with 498 approved packages from same publisher. | ai | |
| provenance | publisher-changed | AI (provenance): Both publishers are BitGo org accounts; transition appears to be an internal maintainer rotation. | ai | |
| provenance | no-provenance | AI (provenance): BitGo monorepo packages consistently lack Sigstore provenance; stable false positive for this package family. | ai | |
| dependencies | unvetted-dep:@bitgo/sdk-lib-mpc | AI (dependencies): Internal BitGo monorepo dependency; expected and stable for this package family. | ai | |
| dependencies | unvetted-dep:@bitgo/sdk-core | AI (dependencies): Internal BitGo monorepo dependency; expected and stable for this package family. | ai |
Versions (showing 52 of 152)
| Version | Deps | Published |
|---|---|---|
| 2.0.62 | 11 / 3 | |
| 2.0.61 | 11 / 3 | |
| 2.0.60 | 11 / 3 | |
| 2.0.59 | 11 / 3 | |
| 2.0.58 | 11 / 3 | |
| 2.0.57 | 11 / 3 | |
| 2.0.56 | 11 / 3 | |
| 2.0.55 | 11 / 3 | |
| 2.0.54 | 11 / 3 | |
| 2.0.52 | 11 / 3 | |
| 2.0.51 | 11 / 3 | |
| 2.0.50 | 11 / 3 | |
| 2.0.49 | 11 / 3 | |
| 2.0.48 | 11 / 3 | |
| 2.0.47 | 11 / 3 | |
| 2.0.46 | 11 / 3 | |
| 2.0.45 | 11 / 3 | |
| 2.0.44 | 11 / 3 | |
| 2.0.43 | 11 / 3 | |
| 2.0.42 | 11 / 3 | |
| 2.0.41 | 11 / 3 | |
| 2.0.40 | 11 / 3 | |
| 2.0.39 | 11 / 3 | |
| 2.0.38 | 11 / 3 | |
| 2.0.37 | 11 / 3 | |
| 2.0.36 | 11 / 3 | |
| 2.0.35 | 11 / 3 | |
| 2.0.34 | 11 / 3 | |
| 2.0.33 | 11 / 3 | |
| 2.0.32 | 11 / 3 | |
| 2.0.31 | 11 / 3 | |
| 2.0.30 | 11 / 3 | |
| 2.0.29 | 11 / 3 | |
| 2.0.28 | 11 / 3 | |
| 2.0.27 | 11 / 3 | |
| 2.0.26 | 11 / 3 | |
| 2.0.25 | 11 / 3 | |
| 2.0.24 | 11 / 3 | |
| 2.0.23 | 11 / 3 | |
| 2.0.22 | 11 / 3 | |
| 2.0.21 | 11 / 3 | |
| 2.0.20 | 11 / 3 | |
| 2.0.19 | 11 / 3 | |
| 2.0.18 | 11 / 3 | |
| 2.0.17 | 11 / 3 | |
| 2.0.16 | 11 / 3 | |
| 2.0.15 | 11 / 3 | |
| 2.0.14 | 11 / 3 | |
| 2.0.13 | 11 / 3 | |
| 2.0.12 | 11 / 3 | |
| 2.0.11 | 11 / 3 | |
| 2.0.10 | 11 / 3 |
v2.0.62
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.61
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.60
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.59
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.58
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.57
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.56
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.55
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.54
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.52
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.51
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.50
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.49
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.48
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.47
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.46
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.45
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.44
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.43
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.42
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.41
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.40
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.39
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.38
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.37
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.36
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.35
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.34
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.33
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.32
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.31
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.30
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.29
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.28
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.27
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.26
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.25
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.24
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.23
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.22
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.21
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.20
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.19
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.18
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.17
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.16
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.15
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.