@bitgo/sdk-coin-ton
BitGo SDK coin library for Ton
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | encoded-string-file:dist/test/unit/transferBuilder.js | AI (source-diff): Long base64 strings are TON transaction test vectors; expected pattern for blockchain SDK test fixtures. | ai | |
| source-diff | obfuscated-file:dist/src/lib/tonWhalesVestingWithdrawBuilder.js | AI (source-diff): Standard tsc output with inline sourcemap; readable class logic, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:dist/test/unit/tonWhalesVestingWithdrawBuilder.js | AI (source-diff): Standard tsc-compiled test file with inline sourcemap; no malicious content. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Mass removal consistent with BitGo consolidating to CI bot publishing; not indicative of takeover. | ai | |
| source-diff | obfuscated-file:dist/src/lib/tokenTransferBuilder.js | AI (source-diff): Readable TypeScript-compiled output; long lines from builder pattern, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/src/lib/tokenTransaction.js | AI (source-diff): Readable TypeScript-compiled output; long lines from tonweb cell serialization, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/src/jettonToken.js | AI (source-diff): Readable TypeScript-compiled output; long lines from serialization logic, not obfuscation. Stable pattern for this package. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): bitgobot addition is consistent with BitGo monorepo CI bot consolidation pattern. | ai | |
| source-diff | encoded-string-file:dist/test/resources/ton.js | AI (source-diff): Long strings are TON transaction blobs and test fixture data, not obfuscated payloads. | ai | |
| source-diff | obfuscated-file:dist/src/lib/utils.js | AI (source-diff): Standard tsc-compiled output; readable class code, no obfuscation. | ai | |
| source-diff | obfuscated-file:dist/src/lib/transactionBuilderFactory.js | AI (source-diff): Standard tsc-compiled output; readable class code, no obfuscation. | ai | |
| source-diff | obfuscated-file:dist/src/lib/transactionBuilder.js | AI (source-diff): Standard tsc-compiled output; readable class code, no obfuscation. | ai | |
| source-diff | obfuscated-file:dist/src/lib/transaction.js | AI (source-diff): Standard tsc-compiled output; readable class code, no obfuscation. | ai | |
| source-diff | obfuscated-file:dist/src/lib/keyPair.js | AI (source-diff): Standard tsc-compiled output; readable class code, no obfuscation. | ai | |
| source-diff | obfuscated-file:dist/src/ton.js | AI (source-diff): Standard tsc-compiled output; readable class code, no obfuscation. | ai | |
| provenance | publisher-changed | AI (provenance): pranavjain is an established BitGo publisher (321 approved, 0 rejected); routine team rotation within the org. | ai | |
| source-diff | encoded-string-file:dist/test/unit/singleNominatorWithdrawBuilder.js | AI (source-diff): Long strings are serialized TON transaction test fixtures (te6cck... BOC format), not payloads. | ai | |
| source-diff | obfuscated-file:dist/src/lib/explainTransactionWasm.js | AI (source-diff): Standard tsc CommonJS output with readable logic; long lines are TypeScript boilerplate, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/test/unit/explainTransactionWasm.js | AI (source-diff): Standard tsc CommonJS output; long lines are TypeScript boilerplate helpers. | ai | |
| source-diff | obfuscated-file:dist/test/unit/wasmCrossCompatibility.js | AI (source-diff): Standard tsc CommonJS output; long lines are TypeScript boilerplate helpers. | ai | |
| source-diff | encoded-string-file:dist/src/lib/constants.js | AI (source-diff): Long string is TON vesting contract bytecode (base64 BOC), a legitimate domain constant. | ai | |
| source-diff | encoded-string-file:dist/src/lib/constants.d.ts | AI (source-diff): Same TON contract BOC constant in the TypeScript declaration file; benign. | ai | |
| source-diff | encoded-string-file:dist/test/unit/ton.js | AI (source-diff): Long strings are encrypted key fixtures and TON transaction BOC data used in unit tests. | ai | |
| phantom-deps | phantom-dep:lodash | AI (phantom-deps): Monorepo package; deps referenced in config files is a stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:bn.js | AI (phantom-deps): Monorepo package; deps referenced in config files is a stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@bitgo/sdk-lib-mpc | AI (phantom-deps): Same-org monorepo dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@bitgo/sdk-core | AI (phantom-deps): Same-org monorepo dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@bitgo/statics | AI (phantom-deps): Same-org monorepo dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:bignumber.js | AI (phantom-deps): Monorepo package; deps referenced in config files is a stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:tweetnacl | AI (phantom-deps): Monorepo package; deps referenced in config files is a stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:tonweb | AI (phantom-deps): Monorepo package; deps referenced in config files is a stable false positive for this package. | ai | |
| provenance | no-provenance | AI (provenance): BitGo SDK packages consistently publish without Sigstore provenance; stable pattern across all versions. | ai | |
| dependencies | unvetted-dep:@bitgo/sdk-lib-mpc | AI (dependencies): Internal BitGo MPC library; expected for this package. | ai | |
| dependencies | unvetted-dep:tonweb | AI (dependencies): Standard TON blockchain JS library; expected dependency for TON coin support. | ai | |
| dependencies | unvetted-dep:@bitgo/wasm-ton | AI (dependencies): BitGo-owned WASM binding for TON; expected for this coin SDK. | ai | |
| dependencies | unvetted-dep:@bitgo/sdk-core | AI (dependencies): Core BitGo SDK dep; expected for all @bitgo/sdk-coin-* packages. | ai |
Versions (showing 39 of 139)
| Version | Deps | Published |
|---|---|---|
| 3.4.21 | 8 / 2 | |
| 3.4.20 | 8 / 2 | |
| 3.4.19 | 8 / 2 | |
| 3.4.18 | 8 / 2 | |
| 3.4.17 | 8 / 2 | |
| 3.4.16 | 8 / 2 | |
| 3.4.15 | 8 / 2 | |
| 3.4.14 | 8 / 2 | |
| 3.4.13 | 8 / 2 | |
| 3.4.12 | 8 / 2 | |
| 3.4.11 | 8 / 2 | |
| 3.4.9 | 8 / 2 | |
| 3.4.8 | 8 / 2 | |
| 3.4.7 | 8 / 2 | |
| 3.4.6 | 8 / 2 | |
| 3.4.5 | 8 / 2 | |
| 3.4.4 | 8 / 2 | |
| 3.4.3 | 8 / 2 | |
| 3.4.2 | 8 / 2 | |
| 3.4.1 | 8 / 2 | |
| 3.4.0 | 8 / 2 | |
| 3.3.3 | 8 / 2 | |
| 3.3.2 | 8 / 2 | |
| 3.3.1 | 8 / 2 | |
| 3.3.0 | 8 / 2 | |
| 3.2.11 | 8 / 2 | |
| 3.2.10 | 8 / 2 | |
| 3.2.9 | 8 / 2 | |
| 3.2.8 | 8 / 2 | |
| 3.2.7 | 8 / 2 | |
| 3.2.6 | 8 / 2 | |
| 3.2.5 | 8 / 2 | |
| 3.2.4 | 8 / 2 | |
| 3.2.3 | 8 / 2 | |
| 3.2.2 | 8 / 2 | |
| 3.2.1 | 8 / 2 | |
| 3.2.0 | 8 / 2 | |
| 3.1.0 | 8 / 2 | |
| 3.0.0 | 8 / 2 |
v3.4.21
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.4.20
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.4.19
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.4.18
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.4.17
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.4.16
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.4.15
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.4.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.4.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.4.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.4.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.4.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.4.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.4.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.4.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.4.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.4.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.4.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.4.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.4.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.4.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.3.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.3.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.3.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.3.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.2.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.2.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.2.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.2.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.2.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.2.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.2.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.2.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.2.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.2.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.2.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.2.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.1.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.0.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.