@bitgo/sdk-coin-ton
BitGo SDK coin library for Ton
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | encoded-string-file:dist/test/unit/transferBuilder.js | AI (source-diff): Long base64 strings are TON transaction test vectors; expected pattern for blockchain SDK test fixtures. | ai | |
| source-diff | obfuscated-file:dist/src/lib/tonWhalesVestingWithdrawBuilder.js | AI (source-diff): Standard tsc output with inline sourcemap; readable class logic, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:dist/test/unit/tonWhalesVestingWithdrawBuilder.js | AI (source-diff): Standard tsc-compiled test file with inline sourcemap; no malicious content. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Mass removal consistent with BitGo consolidating to CI bot publishing; not indicative of takeover. | ai | |
| source-diff | obfuscated-file:dist/src/lib/tokenTransferBuilder.js | AI (source-diff): Readable TypeScript-compiled output; long lines from builder pattern, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/src/lib/tokenTransaction.js | AI (source-diff): Readable TypeScript-compiled output; long lines from tonweb cell serialization, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/src/jettonToken.js | AI (source-diff): Readable TypeScript-compiled output; long lines from serialization logic, not obfuscation. Stable pattern for this package. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): bitgobot addition is consistent with BitGo monorepo CI bot consolidation pattern. | ai | |
| source-diff | encoded-string-file:dist/test/resources/ton.js | AI (source-diff): Long strings are TON transaction blobs and test fixture data, not obfuscated payloads. | ai | |
| source-diff | obfuscated-file:dist/src/lib/utils.js | AI (source-diff): Standard tsc-compiled output; readable class code, no obfuscation. | ai | |
| source-diff | obfuscated-file:dist/src/lib/transactionBuilderFactory.js | AI (source-diff): Standard tsc-compiled output; readable class code, no obfuscation. | ai | |
| source-diff | obfuscated-file:dist/src/lib/transactionBuilder.js | AI (source-diff): Standard tsc-compiled output; readable class code, no obfuscation. | ai | |
| source-diff | obfuscated-file:dist/src/lib/transaction.js | AI (source-diff): Standard tsc-compiled output; readable class code, no obfuscation. | ai | |
| source-diff | obfuscated-file:dist/src/lib/keyPair.js | AI (source-diff): Standard tsc-compiled output; readable class code, no obfuscation. | ai | |
| source-diff | obfuscated-file:dist/src/ton.js | AI (source-diff): Standard tsc-compiled output; readable class code, no obfuscation. | ai | |
| provenance | publisher-changed | AI (provenance): pranavjain is an established BitGo publisher (321 approved, 0 rejected); routine team rotation within the org. | ai | |
| source-diff | encoded-string-file:dist/test/unit/singleNominatorWithdrawBuilder.js | AI (source-diff): Long strings are serialized TON transaction test fixtures (te6cck... BOC format), not payloads. | ai | |
| source-diff | obfuscated-file:dist/src/lib/explainTransactionWasm.js | AI (source-diff): Standard tsc CommonJS output with readable logic; long lines are TypeScript boilerplate, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/test/unit/explainTransactionWasm.js | AI (source-diff): Standard tsc CommonJS output; long lines are TypeScript boilerplate helpers. | ai | |
| source-diff | obfuscated-file:dist/test/unit/wasmCrossCompatibility.js | AI (source-diff): Standard tsc CommonJS output; long lines are TypeScript boilerplate helpers. | ai | |
| source-diff | encoded-string-file:dist/src/lib/constants.js | AI (source-diff): Long string is TON vesting contract bytecode (base64 BOC), a legitimate domain constant. | ai | |
| source-diff | encoded-string-file:dist/src/lib/constants.d.ts | AI (source-diff): Same TON contract BOC constant in the TypeScript declaration file; benign. | ai | |
| source-diff | encoded-string-file:dist/test/unit/ton.js | AI (source-diff): Long strings are encrypted key fixtures and TON transaction BOC data used in unit tests. | ai | |
| phantom-deps | phantom-dep:lodash | AI (phantom-deps): Monorepo package; deps referenced in config files is a stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:bn.js | AI (phantom-deps): Monorepo package; deps referenced in config files is a stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@bitgo/sdk-lib-mpc | AI (phantom-deps): Same-org monorepo dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@bitgo/sdk-core | AI (phantom-deps): Same-org monorepo dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@bitgo/statics | AI (phantom-deps): Same-org monorepo dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:bignumber.js | AI (phantom-deps): Monorepo package; deps referenced in config files is a stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:tweetnacl | AI (phantom-deps): Monorepo package; deps referenced in config files is a stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:tonweb | AI (phantom-deps): Monorepo package; deps referenced in config files is a stable false positive for this package. | ai | |
| provenance | no-provenance | AI (provenance): BitGo SDK packages consistently publish without Sigstore provenance; stable pattern across all versions. | ai | |
| dependencies | unvetted-dep:@bitgo/sdk-lib-mpc | AI (dependencies): Internal BitGo MPC library; expected for this package. | ai | |
| dependencies | unvetted-dep:tonweb | AI (dependencies): Standard TON blockchain JS library; expected dependency for TON coin support. | ai | |
| dependencies | unvetted-dep:@bitgo/wasm-ton | AI (dependencies): BitGo-owned WASM binding for TON; expected for this coin SDK. | ai | |
| dependencies | unvetted-dep:@bitgo/sdk-core | AI (dependencies): Core BitGo SDK dep; expected for all @bitgo/sdk-coin-* packages. | ai |
Versions (showing 100 of 139)
| Version | Deps | Published |
|---|---|---|
| 4.0.4 | 9 / 2 | |
| 4.0.3 | 9 / 2 | |
| 4.0.1 | 9 / 2 | |
| 4.0.0 | 9 / 2 | |
| 3.20.11 | 9 / 2 | |
| 3.20.10 | 9 / 2 | |
| 3.20.9 | 9 / 2 | |
| 3.20.8 | 9 / 2 | |
| 3.20.7 | 9 / 2 | |
| 3.20.6 | 9 / 2 | |
| 3.20.5 | 9 / 2 | |
| 3.20.4 | 9 / 2 | |
| 3.20.3 | 9 / 2 | |
| 3.20.2 | 9 / 2 | |
| 3.20.1 | 9 / 2 | |
| 3.20.0 | 9 / 2 | |
| 3.19.8 | 9 / 2 | |
| 3.19.7 | 9 / 2 | |
| 3.19.6 | 9 / 2 | |
| 3.19.5 | 9 / 2 | |
| 3.19.4 | 9 / 2 | |
| 3.19.3 | 9 / 2 | |
| 3.19.2 | 9 / 2 | |
| 3.19.1 | 9 / 2 | |
| 3.19.0 | 9 / 2 | |
| 3.18.0 | 8 / 2 | |
| 3.17.1 | 8 / 2 | |
| 3.17.0 | 8 / 2 | |
| 3.16.4 | 8 / 2 | |
| 3.16.3 | 8 / 2 | |
| 3.16.2 | 8 / 2 | |
| 3.16.1 | 8 / 2 | |
| 3.16.0 | 8 / 2 | |
| 3.15.1 | 8 / 2 | |
| 3.15.0 | 8 / 2 | |
| 3.14.0 | 8 / 2 | |
| 3.13.3 | 8 / 2 | |
| 3.13.1 | 8 / 2 | |
| 3.13.0 | 8 / 2 | |
| 3.12.0 | 8 / 2 | |
| 3.11.5 | 8 / 2 | |
| 3.11.4 | 8 / 2 | |
| 3.11.3 | 8 / 2 | |
| 3.11.2 | 8 / 2 | |
| 3.11.1 | 8 / 2 | |
| 3.11.0 | 8 / 2 | |
| 3.10.5 | 8 / 2 | |
| 3.10.4 | 8 / 2 | |
| 3.10.3 | 8 / 2 | |
| 3.10.2 | 8 / 2 | |
| 3.10.1 | 8 / 2 | |
| 3.10.0 | 8 / 2 | |
| 3.9.7 | 8 / 2 | |
| 3.9.6 | 8 / 2 | |
| 3.9.5 | 8 / 2 | |
| 3.9.4 | 8 / 2 | |
| 3.9.3 | 8 / 2 | |
| 3.9.2 | 8 / 2 | |
| 3.9.1 | 8 / 2 | |
| 3.9.0 | 8 / 2 | |
| 3.8.4 | 8 / 2 | |
| 3.8.3 | 8 / 2 | |
| 3.8.2 | 8 / 2 | |
| 3.8.1 | 8 / 2 | |
| 3.8.0 | 8 / 2 | |
| 3.7.15 | 8 / 2 | |
| 3.7.14 | 8 / 2 | |
| 3.7.13 | 8 / 2 | |
| 3.7.12 | 8 / 2 | |
| 3.7.11 | 8 / 2 | |
| 3.7.10 | 8 / 2 | |
| 3.7.9 | 8 / 2 | |
| 3.7.8 | 8 / 2 | |
| 3.7.7 | 8 / 2 | |
| 3.7.6 | 8 / 2 | |
| 3.7.5 | 8 / 2 | |
| 3.7.4 | 8 / 2 | |
| 3.7.3 | 8 / 2 | |
| 3.7.2 | 8 / 2 | |
| 3.7.1 | 8 / 2 | |
| 3.7.0 | 8 / 2 | |
| 3.6.0 | 8 / 2 | |
| 3.5.5 | 8 / 2 | |
| 3.5.4 | 8 / 2 | |
| 3.5.3 | 8 / 2 | |
| 3.5.2 | 8 / 2 | |
| 3.5.1 | 8 / 2 | |
| 3.5.0 | 8 / 2 | |
| 3.4.33 | 8 / 2 | |
| 3.4.32 | 8 / 2 | |
| 3.4.31 | 8 / 2 | |
| 3.4.30 | 8 / 2 | |
| 3.4.29 | 8 / 2 | |
| 3.4.28 | 8 / 2 | |
| 3.4.27 | 8 / 2 | |
| 3.4.26 | 8 / 2 | |
| 3.4.25 | 8 / 2 | |
| 3.4.24 | 8 / 2 | |
| 3.4.23 | 8 / 2 | |
| 3.4.22 | 8 / 2 |
v4.0.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.0.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.0.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.20.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.20.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.5.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.4.33
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.4.32
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.4.31
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.4.30
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.4.29
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.4.28
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.4.27
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.4.26
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.4.25
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.4.24
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.4.23
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.4.22
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.