@bitgo/utxo-bin
Command-line utility for BitGo UTXO transactions
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:clipboardy-cjs | AI (dependencies): clipboardy-cjs is a standard CJS wrapper for clipboardy; appropriate for a CLI tool and stable across versions. | ai | |
| source-diff | obfuscated-file:dist/src/prevTx.js | AI (source-diff): Standard tsc output with __createBinding/__importStar helpers, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/src/commands/cmdDescriptor/fromFixedScript.js | AI (source-diff): Standard TypeScript compiled output; long lines from TS __createBinding boilerplate, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/test/cmdDescriptor/fromFixedScript.js | AI (source-diff): Standard TypeScript compiled test output; same TS boilerplate pattern, not obfuscation. | ai | |
| provenance | publisher-changed | AI (provenance): bitgobot is BitGo's CI bot with established track record (31 approved packages); consistent with org-wide automation. | ai | |
| dependencies | unvetted-dep:@bitgo/blockapis | AI (dependencies): Internal BitGo monorepo dependency; stable pattern across all @bitgo/* packages. | ai | |
| dependencies | unvetted-dep:@bitgo/utxo-core | AI (dependencies): Internal BitGo monorepo dependency added in this version; stable pattern for this package family. | ai | |
| dependencies | unvetted-dep:@bitgo/unspents | AI (dependencies): Internal BitGo monorepo dependency; stable pattern across all @bitgo/* packages. | ai |
Versions (showing 51 of 70)
| Version | Deps | Published |
|---|---|---|
| 3.25.15 | 16 / 3 | |
| 3.25.14 | 16 / 3 | |
| 3.25.12 | 16 / 3 | |
| 3.25.11 | 16 / 3 | |
| 3.25.10 | 16 / 3 | |
| 3.25.9 | 16 / 3 | |
| 3.25.8 | 16 / 3 | |
| 3.25.7 | 16 / 3 | |
| 3.25.6 | 16 / 3 | |
| 3.25.5 | 16 / 3 | |
| 3.25.4 | 16 / 3 | |
| 3.25.3 | 16 / 3 | |
| 3.25.2 | 16 / 3 | |
| 3.25.1 | 16 / 3 | |
| 3.25.0 | 16 / 3 | |
| 3.24.1 | 16 / 3 | |
| 3.24.0 | 16 / 3 | |
| 3.23.1 | 16 / 3 | |
| 3.23.0 | 16 / 3 | |
| 3.22.3 | 16 / 3 | |
| 3.22.2 | 16 / 3 | |
| 3.22.1 | 16 / 3 | |
| 3.22.0 | 16 / 3 | |
| 3.21.3 | 16 / 3 | |
| 3.21.2 | 16 / 3 | |
| 3.21.1 | 16 / 3 | |
| 3.21.0 | 16 / 3 | |
| 3.20.4 | 16 / 3 | |
| 3.20.3 | 16 / 3 | |
| 3.20.2 | 16 / 3 | |
| 3.20.1 | 16 / 3 | |
| 3.20.0 | 16 / 3 | |
| 3.19.0 | 16 / 3 | |
| 3.18.0 | 16 / 3 | |
| 3.17.1 | 16 / 3 | |
| 3.16.0 | 16 / 3 | |
| 3.15.0 | 16 / 3 | |
| 3.14.0 | 16 / 3 | |
| 3.13.3 | 16 / 3 | |
| 3.13.2 | 16 / 3 | |
| 3.13.1 | 16 / 3 | |
| 3.13.0 | 16 / 3 | |
| 3.12.2 | 16 / 3 | |
| 3.12.1 | 16 / 3 | |
| 3.12.0 | 16 / 3 | |
| 3.11.0 | 16 / 3 | |
| 3.10.11 | 16 / 3 | |
| 3.10.8 | 16 / 3 | |
| 3.10.4 | 16 / 3 | |
| 3.10.3 | 16 / 3 | |
| 3.9.3 | 16 / 3 |
v3.25.15
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.25.14
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.25.12
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.25.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.25.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.25.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.