@bitgo/sdk-coin-xtz
BitGo SDK coin library for Tezos
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | encoded-string-file:dist/test/unit/offlineTransactionBuilder.js | AI (source-diff): Long hex strings are Tezos transaction broadcast format test vectors, not obfuscated payloads. | ai | |
| source-diff | encoded-string-file:dist/test/unit/transactionBuilder.js | AI (source-diff): Long encoded strings are Tezos tx hex and base58 signatures used as test fixtures; stable false positive for this package. | ai | |
| source-diff | obfuscated-file:dist/test/unit/keyPair.js | AI (source-diff): Compiled TS test file; long lines are TypeScript boilerplate, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/test/unit/offlineTransactionBuilder.js | AI (source-diff): Compiled TS test file; readable test code with long lines from boilerplate. | ai | |
| source-diff | obfuscated-file:dist/test/resources.js | AI (source-diff): Compiled TS test resources with long hex fixture strings; not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/test/unit/transaction.js | AI (source-diff): Compiled TS test file; long lines are TypeScript boilerplate. | ai | |
| source-diff | obfuscated-file:dist/test/unit/transactionBuilder.js | AI (source-diff): Compiled TS test file; long lines are TypeScript boilerplate. | ai | |
| source-diff | obfuscated-file:dist/test/unit/transferBuilder.js | AI (source-diff): Compiled TS test file; readable test code with long lines from boilerplate. | ai | |
| source-diff | obfuscated-file:dist/test/unit/xtz.js | AI (source-diff): Compiled TS test file; long lines are TypeScript boilerplate. | ai | |
| source-diff | obfuscated-file:dist/test/unit/util.js | AI (source-diff): Compiled TS test file; long lines are TypeScript boilerplate. | ai | |
| source-diff | obfuscated-file:dist/test/fixtures.js | AI (source-diff): Compiled TS test fixture with long hex strings; not obfuscated malware. | ai | |
| phantom-deps | phantom-dep:@taquito/local-forging | AI (phantom-deps): Tezos SDK dep; monorepo config reference pattern. | ai | |
| phantom-deps | phantom-dep:libsodium-wrappers | AI (phantom-deps): Tezos crypto dep; monorepo config reference pattern. | ai | |
| phantom-deps | phantom-dep:lodash | AI (phantom-deps): Monorepo SDK package; deps declared at package level but imported via shared modules. | ai | |
| phantom-deps | phantom-dep:bs58check | AI (phantom-deps): Same monorepo pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:superagent | AI (phantom-deps): Declared dep used via config/shared modules in monorepo; not a direct import. | ai | |
| phantom-deps | phantom-dep:bignumber.js | AI (phantom-deps): Monorepo SDK; stable false positive. | ai | |
| phantom-deps | phantom-dep:@noble/curves | AI (phantom-deps): Monorepo SDK; stable false positive. | ai | |
| phantom-deps | phantom-dep:@bitgo/blake2b | AI (phantom-deps): Same org scope; monorepo pattern. | ai | |
| phantom-deps | phantom-dep:@bitgo/statics | AI (phantom-deps): Same org scope; monorepo pattern. | ai | |
| phantom-deps | phantom-dep:@bitgo/sdk-core | AI (phantom-deps): Same org scope; monorepo pattern. | ai | |
| phantom-deps | phantom-dep:@taquito/signer | AI (phantom-deps): Tezos SDK dep; monorepo config reference pattern. | ai | |
| phantom-deps | phantom-dep:@bitgo/secp256k1 | AI (phantom-deps): Same org scope; monorepo pattern. | ai | |
| provenance | no-provenance | AI (provenance): BitGo SDK packages consistently lack Sigstore provenance; stable false positive for this package family. | ai | |
| dependencies | unvetted-dep:@bitgo/sdk-core | AI (dependencies): First-party BitGo sibling package; stable dependency across all versions of this package. | ai |
Versions (showing 51 of 97)
| Version | Deps | Published |
|---|---|---|
| 3.0.4 | 13 / 2 | |
| 3.0.3 | 13 / 2 | |
| 3.0.1 | 13 / 2 | |
| 3.0.0 | 13 / 2 | |
| 2.11.11 | 13 / 2 | |
| 2.11.10 | 13 / 2 | |
| 2.11.9 | 13 / 2 | |
| 2.11.8 | 13 / 2 | |
| 2.11.7 | 13 / 2 | |
| 2.11.6 | 13 / 2 | |
| 2.11.5 | 13 / 2 | |
| 2.11.4 | 13 / 2 | |
| 2.11.3 | 13 / 2 | |
| 2.11.2 | 13 / 2 | |
| 2.11.1 | 13 / 2 | |
| 2.11.0 | 13 / 2 | |
| 2.10.9 | 13 / 2 | |
| 2.10.8 | 13 / 2 | |
| 2.10.7 | 13 / 2 | |
| 2.10.6 | 13 / 2 | |
| 2.10.5 | 13 / 2 | |
| 2.10.4 | 13 / 2 | |
| 2.10.3 | 13 / 2 | |
| 2.10.2 | 13 / 2 | |
| 2.10.1 | 13 / 2 | |
| 2.10.0 | 13 / 2 | |
| 2.9.9 | 13 / 2 | |
| 2.9.8 | 13 / 2 | |
| 2.9.7 | 13 / 2 | |
| 2.9.6 | 13 / 2 | |
| 2.9.5 | 13 / 2 | |
| 2.9.4 | 13 / 2 | |
| 2.9.3 | 13 / 2 | |
| 2.9.2 | 13 / 2 | |
| 2.9.1 | 13 / 2 | |
| 2.9.0 | 13 / 2 | |
| 2.8.24 | 13 / 2 | |
| 2.8.22 | 13 / 2 | |
| 2.8.21 | 13 / 2 | |
| 2.8.20 | 13 / 2 | |
| 2.8.19 | 13 / 2 | |
| 2.8.18 | 13 / 2 | |
| 2.8.17 | 13 / 2 | |
| 2.8.16 | 13 / 2 | |
| 2.8.15 | 13 / 2 | |
| 2.8.14 | 13 / 2 | |
| 2.8.13 | 13 / 2 | |
| 2.8.12 | 13 / 2 | |
| 2.8.11 | 13 / 2 | |
| 2.8.10 | 13 / 2 | |
| 2.8.9 | 13 / 2 |
v3.0.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.0.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.0.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.11.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.11.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.