@bitgo/secp256k1
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/src/bip32utils.js | AI (source-diff): TS compiler output boilerplate, not obfuscation; implements documented bip32 signing feature. | ai | |
| source-diff | obfuscated-file:./dist/src/index.js | AI (source-diff): Compiled TS output with long lines, not obfuscation; no malicious behavior in sample. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Known BitGo maintainer, manual publish matches prior approved maintainer list. | ai | |
| dependencies | unvetted-dep:bitcoinjs-message | AI (dependencies): Aliased to @bitgo-forks/bitcoinjs-message, a BitGo-controlled fork; consistent with BitGo's ecosystem pattern. | ai | |
| dependencies | unvetted-dep:@brandonblack/musig | AI (dependencies): Known MuSig2 implementation used by BitGo for secp256k1 musig2 support; stable dependency for this package. | ai |
Versions (showing 37 of 37)
| Version | Deps | Published |
|---|---|---|
| 1.11.0 | 8 / 1 | |
| 1.10.0 | 8 / 1 | |
| 1.9.0 | 8 / 1 | |
| 1.8.0 | 6 / 1 | |
| 1.7.0 | 6 / 1 | |
| 1.5.0 | 6 / 1 | |
| 1.4.0 | 6 / 1 | |
| 1.3.3 | 6 / 1 | |
| 1.3.2 | 6 / 1 | |
| 1.3.1 | 6 / 2 | |
| 1.3.0 | 6 / 2 | |
| 1.2.25 | 6 / 2 | |
| 1.2.24 | 6 / 2 | |
| 1.2.23 | 6 / 2 | |
| 1.2.22 | 6 / 2 | |
| 1.2.21 | 6 / 2 | |
| 1.2.20 | 6 / 2 | |
| 1.2.19 | 6 / 2 | |
| 1.2.18 | 6 / 2 | |
| 1.2.17 | 6 / 2 | |
| 1.2.16 | 6 / 2 | |
| 1.2.15 | 6 / 2 | |
| 1.2.14 | 6 / 2 | |
| 1.2.13 | 6 / 2 | |
| 1.2.12 | 6 / 2 | |
| 1.2.11 | 6 / 2 | |
| 1.2.10 | 6 / 2 | |
| 1.2.8 | 6 / 2 | |
| 1.2.7 | 6 / 2 | |
| 1.2.6 | 6 / 2 | |
| 1.2.5 | 6 / 2 | |
| 1.2.3 | 6 / 2 | |
| 1.2.2 | 6 / 2 | |
| 1.2.1 | 6 / 2 | |
| 1.2.0 | 6 / 2 | |
| 1.1.0 | 6 / 2 | |
| 1.0.1 | 6 / 2 |
v1.10.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (pengyuc_bitgo) than the most recent previously approved version (zahin-mohammad) on 2024-02-06. It has since remained available on npm for 896 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.25
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (pengyuc_bitgo) than the most recent previously approved version (zahin-mohammad) on 2024-01-30. It has since remained available on npm for 903 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.24
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alebusse) than the most recent previously approved version (zahin-mohammad) on 2024-01-26, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.2.23
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alebusse) than the most recent previously approved version (zahin-mohammad) on 2024-01-26, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.2.22
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alebusse) than the most recent previously approved version (zahin-mohammad) on 2024-01-25, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.2.21
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alebusse) than the most recent previously approved version (zahin-mohammad) on 2024-01-22, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.2.20
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alebusse) than the most recent previously approved version (zahin-mohammad) on 2024-01-09, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.2.19
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (pengyuc_bitgo) than the most recent previously approved version (zahin-mohammad) on 2024-01-03. It has since remained available on npm for 930 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.18
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alebusse) than the most recent previously approved version (zahin-mohammad) on 2023-12-18, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.2.17
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alebusse) than the most recent previously approved version (zahin-mohammad) on 2023-12-12, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.2.16
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alebusse) than the most recent previously approved version (zahin-mohammad) on 2023-12-09, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.2.15
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alebusse) than the most recent previously approved version (zahin-mohammad) on 2023-12-05, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.2.14
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alebusse) than the most recent previously approved version (zahin-mohammad) on 2023-11-28, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.2.13
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alebusse) than the most recent previously approved version (zahin-mohammad) on 2023-11-24, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.2.12
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alebusse) than the most recent previously approved version (zahin-mohammad) on 2023-11-17, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.2.11
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alebusse) than the most recent previously approved version (zahin-mohammad) on 2023-11-13, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.2.10
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alebusse) than the most recent previously approved version (zahin-mohammad) on 2023-11-13, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.2.8
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alebusse) than the most recent previously approved version (zahin-mohammad) on 2023-10-20, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.2.7
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alebusse) than the most recent previously approved version (zahin-mohammad) on 2023-10-18, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.2.6
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alebusse) than the most recent previously approved version (zahin-mohammad) on 2023-09-25, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.2.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (zahin-mohammad) than the most recent previously approved version (mmcshinsky-bitgo) on 2023-09-01, but zahin-mohammad is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.2.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (mmcshinsky-bitgo) than the most recent previously approved version (zahin-mohammad) on 2023-08-04, but mmcshinsky-bitgo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.