← Home

@bitgo/wasm-utxo

WebAssembly wrapper for rust-bitcoin (beta)

85
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

louib-bitgobitgobot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
npm-metadata bundled-binaries AI (npm-metadata): WASM binary is this package's compiled build artifact, not a backdoor. ai
source-diff large-new-source-files AI (source-diff): Major version bump with WASM build artifacts; large file count expected for this package type. ai
provenance slsa-provenance AI (provenance): BitGo org publishes via GitHub Actions CI with SLSA attestation; stable pattern for this package. ai
provenance publisher-changed AI (provenance): Transition from bitgobot to GitHub Actions is a CI/CD migration pattern consistent with SLSA attestation. ai
maintainer-change maintainer-added AI (maintainer-change): louib-bitgo is a BitGo org member; addition consistent with legitimate team expansion. ai
bogus-package bogus-package AI (bogus-package): @bitgo scoped package from established BitGo publisher; stub/placeholder releases are normal for this org. ai

Versions (showing 85 of 85)

Version Deps Published
4.27.0 0 / 10
4.26.0 0 / 10
4.25.0 0 / 10
4.24.0 0 / 10
4.23.0 0 / 10
4.22.0 0 / 10
4.21.1 0 / 10
4.21.0 0 / 10
4.20.0 0 / 10
4.19.0 0 / 10
4.18.0 0 / 10
4.17.0 0 / 10
4.15.0 0 / 10
4.14.1 0 / 10
4.14.0 0 / 10
4.13.0 0 / 10
4.12.0 0 / 10
4.11.1 0 / 10
4.11.0 0 / 10
4.10.0 0 / 10
4.9.0 0 / 10
4.8.1 0 / 10
4.8.0 0 / 10
4.7.0 0 / 10
4.6.0 0 / 10
4.5.0 0 / 10
4.4.0 0 / 10
4.3.0 0 / 10
4.2.0 0 / 10
4.1.0 0 / 10
4.0.2 0 / 10
4.0.1 0 / 10
4.0.0 0 / 10
3.1.0 0 / 10
3.0.0 0 / 10
2.1.0 0 / 10
2.0.0 0 / 10
1.44.0 0 / 10
1.43.0 0 / 10
1.42.0 0 / 10
1.41.0 0 / 10
1.40.0 0 / 10
1.39.0 0 / 10
1.38.0 0 / 10
1.37.0 0 / 10
1.36.0 0 / 10
1.35.0 0 / 10
1.34.0 0 / 10
1.33.0 0 / 10
1.32.0 0 / 10
1.31.0 0 / 10
1.30.0 0 / 10
1.29.0 0 / 10
1.28.0 0 / 10
1.27.0 0 / 10
1.26.0 0 / 10
1.25.0 0 / 9
1.24.0 0 / 9
1.23.0 0 / 9
1.22.0 0 / 9
1.21.0 0 / 9
1.20.0 0 / 9
1.19.0 0 / 9
1.18.0 0 / 9
1.17.0 0 / 9
1.16.0 0 / 9
1.15.0 0 / 9
1.14.1 0 / 9
1.14.0 0 / 9
1.13.0 0 / 9
1.12.0 0 / 9
1.11.0 0 / 9
1.10.0 0 / 9
1.9.0 0 / 9
1.8.0 0 / 9
1.7.0 0 / 9
1.6.0 0 / 9
1.5.0 0 / 6
1.4.0 0 / 6
1.3.0 0 / 6
1.2.0 0 / 6
1.1.0 0 / 6
1.0.0 0 / 6
0.0.2 0 / 6
0.0.1 0 / 0

v4.27.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.26.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.25.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.24.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.23.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.22.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.21.1

2 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/js/wasm/wasm_utxo_bg.wasm • dist/esm/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.21.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.20.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.19.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.0.2

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/js/wasm/wasm_utxo_bg.wasm • dist/esm/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2026-03-26, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2026-03-26, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v4.0.1

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/js/wasm/wasm_utxo_bg.wasm • dist/esm/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2026-03-16, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2026-03-16, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v4.0.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/js/wasm/wasm_utxo_bg.wasm • dist/esm/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2026-03-16, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2026-03-16, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.1.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/js/wasm/wasm_utxo_bg.wasm • dist/esm/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2026-03-13, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2026-03-13, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.0.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/js/wasm/wasm_utxo_bg.wasm • dist/esm/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2026-03-12, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2026-03-12, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.1.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/js/wasm/wasm_utxo_bg.wasm • dist/esm/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2026-03-05, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2026-03-05, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.0.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/js/wasm/wasm_utxo_bg.wasm • dist/esm/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2026-03-04, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2026-03-04, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.44.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/js/wasm/wasm_utxo_bg.wasm • dist/esm/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2026-02-26, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2026-02-26, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.43.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/js/wasm/wasm_utxo_bg.wasm • dist/esm/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2026-02-25, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2026-02-25, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.42.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/js/wasm/wasm_utxo_bg.wasm • dist/esm/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2026-02-17, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2026-02-17, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.41.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/js/wasm/wasm_utxo_bg.wasm • dist/esm/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2026-02-14, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2026-02-14, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.40.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/js/wasm/wasm_utxo_bg.wasm • dist/esm/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2026-02-14, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2026-02-14, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.39.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/js/wasm/wasm_utxo_bg.wasm • dist/esm/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2026-02-13, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2026-02-13, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.38.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/js/wasm/wasm_utxo_bg.wasm • dist/esm/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2026-02-12, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2026-02-12, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.37.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/js/wasm/wasm_utxo_bg.wasm • dist/esm/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2026-02-11, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2026-02-11, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.36.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/js/wasm/wasm_utxo_bg.wasm • dist/esm/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2026-02-10, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2026-02-10, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.35.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/js/wasm/wasm_utxo_bg.wasm • dist/esm/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2026-02-07, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2026-02-07, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.34.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/js/wasm/wasm_utxo_bg.wasm • dist/esm/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2026-02-05, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2026-02-05, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.33.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/js/wasm/wasm_utxo_bg.wasm • dist/esm/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2026-02-04, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2026-02-04, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.32.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/js/wasm/wasm_utxo_bg.wasm • dist/esm/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2026-02-03, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2026-02-03, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.31.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/js/wasm/wasm_utxo_bg.wasm • dist/esm/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2026-01-30, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2026-01-30, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.30.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/js/wasm/wasm_utxo_bg.wasm • dist/esm/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2026-01-29, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2026-01-29, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.29.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/js/wasm/wasm_utxo_bg.wasm • dist/esm/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2026-01-28, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2026-01-28, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.28.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/js/wasm/wasm_utxo_bg.wasm • dist/esm/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2026-01-28, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2026-01-28, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.27.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/js/wasm/wasm_utxo_bg.wasm • dist/esm/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2026-01-15, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2026-01-15, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.26.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/js/wasm/wasm_utxo_bg.wasm • dist/esm/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2026-01-14, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2026-01-14, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.25.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/js/wasm/wasm_utxo_bg.wasm • dist/esm/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2026-01-14, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2026-01-14, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.24.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/js/wasm/wasm_utxo_bg.wasm • dist/esm/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2026-01-13, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2026-01-13, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.23.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/js/wasm/wasm_utxo_bg.wasm • dist/esm/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2026-01-12, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2026-01-12, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.22.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/js/wasm/wasm_utxo_bg.wasm • dist/esm/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2026-01-09, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2026-01-09, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.21.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/js/wasm/wasm_utxo_bg.wasm • dist/esm/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2026-01-09, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2026-01-09, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.20.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/js/wasm/wasm_utxo_bg.wasm • dist/esm/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2026-01-07, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2026-01-07, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.19.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/js/wasm/wasm_utxo_bg.wasm • dist/esm/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2026-01-05, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2026-01-05, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.18.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/js/wasm/wasm_utxo_bg.wasm • dist/esm/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2026-01-05, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2026-01-05, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.17.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/js/wasm/wasm_utxo_bg.wasm • dist/esm/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2025-12-22, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2025-12-22, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.16.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/js/wasm/wasm_utxo_bg.wasm • dist/esm/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2025-12-22, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2025-12-22, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.15.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/js/wasm/wasm_utxo_bg.wasm • dist/esm/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2025-12-18, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2025-12-18, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.14.1

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/js/wasm/wasm_utxo_bg.wasm • dist/esm/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2025-12-18, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2025-12-18, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.14.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/js/wasm/wasm_utxo_bg.wasm • dist/esm/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2025-12-17, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2025-12-17, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.13.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/js/wasm/wasm_utxo_bg.wasm • dist/esm/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2025-12-16, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2025-12-16, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.12.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/js/wasm/wasm_utxo_bg.wasm • dist/esm/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2025-12-10, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2025-12-10, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.11.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/js/wasm/wasm_utxo_bg.wasm • dist/esm/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2025-12-03, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2025-12-03, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.10.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/js/wasm/wasm_utxo_bg.wasm • dist/esm/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2025-12-02, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2025-12-02, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.9.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/js/wasm/wasm_utxo_bg.wasm • dist/esm/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2025-11-29, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2025-11-29, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.8.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/js/wasm/wasm_utxo_bg.wasm • dist/esm/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2025-11-27, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2025-11-27, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.7.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/js/wasm/wasm_utxo_bg.wasm • dist/esm/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2025-11-26, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2025-11-26, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.6.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/js/wasm/wasm_utxo_bg.wasm • dist/esm/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2025-11-26, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2025-11-26, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.5.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/js/wasm/wasm_utxo_bg.wasm • dist/esm/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2025-11-20, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2025-11-20, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.4.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/cjs/wasm/wasm_utxo_bg.wasm • dist/esm/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2025-11-19, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2025-11-19, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.3.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/browser/js/wasm/wasm_utxo_bg.wasm • dist/node/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2025-11-13, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2025-11-13, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.2.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/browser/js/wasm/wasm_utxo_bg.wasm • dist/node/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2025-11-12, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2025-11-12, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.1.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/browser/js/wasm/wasm_utxo_bg.wasm • dist/node/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2025-11-11, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2025-11-11, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.0.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/browser/js/wasm/wasm_utxo_bg.wasm • dist/node/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2025-11-10, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2025-11-10, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.0.2

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/browser/js/wasm/wasm_utxo_bg.wasm • dist/node/js/wasm/wasm_utxo_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bitgobot → GitHub Actions (on 2025-11-07, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bitgobot) on 2025-11-07, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.