@bitgo/sdk-coin-sui
BitGo SDK coin library for Sui
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | encoded-string-file:dist/test/unit/sui.js | AI (source-diff): Long hex strings in test fixtures are blockchain transaction data and addresses, not obfuscated payloads. Stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@mysten/bcs | AI (phantom-deps): Monorepo package; deps referenced in config files are a stable false positive pattern for this package. | ai | |
| phantom-deps | phantom-dep:@bitgo/statics | AI (phantom-deps): Same-org monorepo dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@bitgo/sdk-core | AI (phantom-deps): Same-org monorepo dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@bitgo/sdk-lib-mpc | AI (phantom-deps): Same-org monorepo dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:bs58 | AI (phantom-deps): Monorepo package; deps referenced in config files are a stable false positive pattern for this package. | ai | |
| phantom-deps | phantom-dep:lodash | AI (phantom-deps): Monorepo package; deps referenced in config files are a stable false positive pattern for this package. | ai | |
| phantom-deps | phantom-dep:tweetnacl | AI (phantom-deps): Monorepo package; deps referenced in config files are a stable false positive pattern for this package. | ai | |
| phantom-deps | phantom-dep:superagent | AI (phantom-deps): Monorepo package; deps referenced in config files are a stable false positive pattern for this package. | ai | |
| phantom-deps | phantom-dep:superstruct | AI (phantom-deps): Monorepo package; deps referenced in config files are a stable false positive pattern for this package. | ai | |
| phantom-deps | phantom-dep:bignumber.js | AI (phantom-deps): Monorepo package; deps referenced in config files are a stable false positive pattern for this package. | ai | |
| phantom-deps | phantom-dep:@bitgo/blake2b | AI (phantom-deps): Same-org monorepo dep; stable false positive for this package. | ai | |
| provenance | no-provenance | AI (provenance): BitGo SDK packages consistently publish without Sigstore provenance; stable pattern across all versions. | ai | |
| dependencies | unvetted-dep:@bitgo/sdk-core | AI (dependencies): Internal BitGo monorepo dependency; expected and stable for this package family. | ai | |
| dependencies | unvetted-dep:@bitgo/sdk-lib-mpc | AI (dependencies): Internal BitGo monorepo dependency; expected and stable for this package family. | ai |
Versions (showing 31 of 131)
| Version | Deps | Published |
|---|---|---|
| 5.7.3 | 11 / 5 | |
| 5.7.2 | 11 / 5 | |
| 5.7.1 | 11 / 5 | |
| 5.7.0 | 11 / 5 | |
| 5.6.4 | 11 / 5 | |
| 5.6.3 | 11 / 5 | |
| 5.6.2 | 11 / 5 | |
| 5.6.1 | 11 / 5 | |
| 5.6.0 | 11 / 5 | |
| 5.5.0 | 11 / 5 | |
| 5.4.1 | 11 / 5 | |
| 5.4.0 | 11 / 5 | |
| 5.3.1 | 10 / 5 | |
| 5.3.0 | 10 / 5 | |
| 5.2.0 | 10 / 5 | |
| 5.1.8 | 10 / 5 | |
| 5.1.7 | 10 / 5 | |
| 5.1.6 | 10 / 5 | |
| 5.1.5 | 10 / 5 | |
| 5.1.4 | 10 / 5 | |
| 5.1.3 | 10 / 5 | |
| 5.1.2 | 10 / 5 | |
| 5.1.1 | 10 / 5 | |
| 5.1.0 | 10 / 5 | |
| 5.0.16 | 10 / 5 | |
| 5.0.15 | 10 / 5 | |
| 5.0.14 | 10 / 5 | |
| 5.0.13 | 10 / 5 | |
| 5.0.12 | 10 / 5 | |
| 5.0.11 | 10 / 5 | |
| 5.0.10 | 10 / 5 |
v5.7.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.7.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.7.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.7.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.6.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.6.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.6.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.6.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.6.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.5.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.4.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.4.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.3.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.3.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.2.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.1.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.1.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.1.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.1.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.1.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.1.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.1.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.1.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.1.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.0.16
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.0.15
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.0.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.0.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.0.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.0.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.0.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.