@bitgo/sdk-coin-xtz
BitGo SDK coin library for Tezos
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | encoded-string-file:dist/test/unit/offlineTransactionBuilder.js | AI (source-diff): Long hex strings are Tezos transaction broadcast format test vectors, not obfuscated payloads. | ai | |
| source-diff | encoded-string-file:dist/test/unit/transactionBuilder.js | AI (source-diff): Long encoded strings are Tezos tx hex and base58 signatures used as test fixtures; stable false positive for this package. | ai | |
| source-diff | obfuscated-file:dist/test/unit/keyPair.js | AI (source-diff): Compiled TS test file; long lines are TypeScript boilerplate, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/test/unit/offlineTransactionBuilder.js | AI (source-diff): Compiled TS test file; readable test code with long lines from boilerplate. | ai | |
| source-diff | obfuscated-file:dist/test/resources.js | AI (source-diff): Compiled TS test resources with long hex fixture strings; not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/test/unit/transaction.js | AI (source-diff): Compiled TS test file; long lines are TypeScript boilerplate. | ai | |
| source-diff | obfuscated-file:dist/test/unit/transactionBuilder.js | AI (source-diff): Compiled TS test file; long lines are TypeScript boilerplate. | ai | |
| source-diff | obfuscated-file:dist/test/unit/transferBuilder.js | AI (source-diff): Compiled TS test file; readable test code with long lines from boilerplate. | ai | |
| source-diff | obfuscated-file:dist/test/unit/xtz.js | AI (source-diff): Compiled TS test file; long lines are TypeScript boilerplate. | ai | |
| source-diff | obfuscated-file:dist/test/unit/util.js | AI (source-diff): Compiled TS test file; long lines are TypeScript boilerplate. | ai | |
| source-diff | obfuscated-file:dist/test/fixtures.js | AI (source-diff): Compiled TS test fixture with long hex strings; not obfuscated malware. | ai | |
| phantom-deps | phantom-dep:@taquito/local-forging | AI (phantom-deps): Tezos SDK dep; monorepo config reference pattern. | ai | |
| phantom-deps | phantom-dep:libsodium-wrappers | AI (phantom-deps): Tezos crypto dep; monorepo config reference pattern. | ai | |
| phantom-deps | phantom-dep:lodash | AI (phantom-deps): Monorepo SDK package; deps declared at package level but imported via shared modules. | ai | |
| phantom-deps | phantom-dep:bs58check | AI (phantom-deps): Same monorepo pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:superagent | AI (phantom-deps): Declared dep used via config/shared modules in monorepo; not a direct import. | ai | |
| phantom-deps | phantom-dep:bignumber.js | AI (phantom-deps): Monorepo SDK; stable false positive. | ai | |
| phantom-deps | phantom-dep:@noble/curves | AI (phantom-deps): Monorepo SDK; stable false positive. | ai | |
| phantom-deps | phantom-dep:@bitgo/blake2b | AI (phantom-deps): Same org scope; monorepo pattern. | ai | |
| phantom-deps | phantom-dep:@bitgo/statics | AI (phantom-deps): Same org scope; monorepo pattern. | ai | |
| phantom-deps | phantom-dep:@bitgo/sdk-core | AI (phantom-deps): Same org scope; monorepo pattern. | ai | |
| phantom-deps | phantom-dep:@taquito/signer | AI (phantom-deps): Tezos SDK dep; monorepo config reference pattern. | ai | |
| phantom-deps | phantom-dep:@bitgo/secp256k1 | AI (phantom-deps): Same org scope; monorepo pattern. | ai | |
| provenance | no-provenance | AI (provenance): BitGo SDK packages consistently lack Sigstore provenance; stable false positive for this package family. | ai | |
| dependencies | unvetted-dep:@bitgo/sdk-core | AI (dependencies): First-party BitGo sibling package; stable dependency across all versions of this package. | ai |
Versions (showing 97 of 97)
| Version | Deps | Published |
|---|---|---|
| 3.0.4 | 13 / 2 | |
| 3.0.3 | 13 / 2 | |
| 3.0.1 | 13 / 2 | |
| 3.0.0 | 13 / 2 | |
| 2.11.11 | 13 / 2 | |
| 2.11.10 | 13 / 2 | |
| 2.11.9 | 13 / 2 | |
| 2.11.8 | 13 / 2 | |
| 2.11.7 | 13 / 2 | |
| 2.11.6 | 13 / 2 | |
| 2.11.5 | 13 / 2 | |
| 2.11.4 | 13 / 2 | |
| 2.11.3 | 13 / 2 | |
| 2.11.2 | 13 / 2 | |
| 2.11.1 | 13 / 2 | |
| 2.11.0 | 13 / 2 | |
| 2.10.9 | 13 / 2 | |
| 2.10.8 | 13 / 2 | |
| 2.10.7 | 13 / 2 | |
| 2.10.6 | 13 / 2 | |
| 2.10.5 | 13 / 2 | |
| 2.10.4 | 13 / 2 | |
| 2.10.3 | 13 / 2 | |
| 2.10.2 | 13 / 2 | |
| 2.10.1 | 13 / 2 | |
| 2.10.0 | 13 / 2 | |
| 2.9.9 | 13 / 2 | |
| 2.9.8 | 13 / 2 | |
| 2.9.7 | 13 / 2 | |
| 2.9.6 | 13 / 2 | |
| 2.9.5 | 13 / 2 | |
| 2.9.4 | 13 / 2 | |
| 2.9.3 | 13 / 2 | |
| 2.9.2 | 13 / 2 | |
| 2.9.1 | 13 / 2 | |
| 2.9.0 | 13 / 2 | |
| 2.8.24 | 13 / 2 | |
| 2.8.22 | 13 / 2 | |
| 2.8.21 | 13 / 2 | |
| 2.8.20 | 13 / 2 | |
| 2.8.19 | 13 / 2 | |
| 2.8.18 | 13 / 2 | |
| 2.8.17 | 13 / 2 | |
| 2.8.16 | 13 / 2 | |
| 2.8.15 | 13 / 2 | |
| 2.8.14 | 13 / 2 | |
| 2.8.13 | 13 / 2 | |
| 2.8.12 | 13 / 2 | |
| 2.8.11 | 13 / 2 | |
| 2.8.10 | 13 / 2 | |
| 2.8.9 | 13 / 2 | |
| 2.8.8 | 12 / 2 | |
| 2.8.7 | 12 / 2 | |
| 2.8.6 | 12 / 2 | |
| 2.8.5 | 12 / 2 | |
| 2.8.4 | 12 / 2 | |
| 2.8.3 | 12 / 2 | |
| 2.8.2 | 12 / 2 | |
| 2.8.1 | 12 / 2 | |
| 2.8.0 | 12 / 2 | |
| 2.7.4 | 12 / 2 | |
| 2.7.3 | 12 / 2 | |
| 2.7.2 | 12 / 2 | |
| 2.7.1 | 12 / 2 | |
| 2.7.0 | 12 / 2 | |
| 2.6.0 | 12 / 2 | |
| 2.5.0 | 12 / 2 | |
| 2.4.13 | 11 / 2 | |
| 2.4.12 | 11 / 2 | |
| 2.4.11 | 11 / 2 | |
| 2.4.10 | 11 / 2 | |
| 2.4.9 | 11 / 2 | |
| 2.4.8 | 11 / 2 | |
| 2.4.7 | 11 / 2 | |
| 2.4.6 | 11 / 2 | |
| 2.4.5 | 11 / 2 | |
| 2.4.4 | 11 / 2 | |
| 2.4.3 | 11 / 2 | |
| 2.4.2 | 11 / 2 | |
| 2.4.1 | 11 / 2 | |
| 2.4.0 | 11 / 2 | |
| 2.3.0 | 11 / 2 | |
| 2.2.13 | 11 / 2 | |
| 2.2.12 | 11 / 2 | |
| 2.2.11 | 11 / 2 | |
| 2.2.10 | 11 / 2 | |
| 2.2.9 | 11 / 2 | |
| 2.2.8 | 11 / 2 | |
| 2.2.7 | 11 / 2 | |
| 2.2.6 | 11 / 2 | |
| 2.2.5 | 11 / 2 | |
| 2.2.4 | 11 / 2 | |
| 2.2.3 | 11 / 2 | |
| 2.2.2 | 11 / 2 | |
| 2.2.1 | 11 / 2 | |
| 2.2.0 | 11 / 2 | |
| 2.1.66 | 11 / 2 |
v3.0.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.0.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.0.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.11.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.11.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.2.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.66
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.