@bulletxyz/bullet-sdk
Bullet SDK
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| npm-metadata | bundled-binaries | AI (npm-metadata): Expected wasm build artifact for this SDK's node/browser dual targets. | ai | |
| source-diff | encoded-string-file:dist/browser/index.js | AI (source-diff): wasm-bindgen base64 WASM blob in bundled output, not obfuscation. | ai | |
| source-diff | encoded-string-file:dist/node/index.js | AI (source-diff): wasm-bindgen base64 WASM blob in bundled output, not obfuscation. | ai | |
| provenance | publisher-changed | AI (provenance): CI/CD (GitHub Actions) publisher, consistent with automated release pipeline. | ai | |
| phantom-deps | phantom-dep:eventemitter3 | AI (phantom-deps): Declared dep used transitively/in config; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@sovereign-sdk/modules | AI (phantom-deps): Declared dep from same sovereign-sdk namespace; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:upgrade | AI (phantom-deps): Declared dep used transitively/in config; stable false positive for this package. | ai |
Versions (showing 60 of 60)
| Version | Deps | Published |
|---|---|---|
| 0.49.18 | 9 / 11 | |
| 0.49.17 | 9 / 11 | |
| 0.49.16 | 9 / 11 | |
| 0.49.15 | 9 / 11 | |
| 0.49.14 | 9 / 11 | |
| 0.49.13 | 9 / 11 | |
| 0.49.12 | 9 / 11 | |
| 0.49.11 | 9 / 11 | |
| 0.49.10 | 9 / 11 | |
| 0.49.9 | 9 / 11 | |
| 0.49.8 | 9 / 11 | |
| 0.49.7 | 9 / 11 | |
| 0.49.6 | 9 / 11 | |
| 0.49.5 | 9 / 11 | |
| 0.49.4 | 9 / 11 | |
| 0.49.3 | 9 / 11 | |
| 0.49.2 | 9 / 11 | |
| 0.49.1 | 9 / 11 | |
| 0.49.0 | 9 / 11 | |
| 0.48.8 | 9 / 11 | |
| 0.48.7 | 9 / 11 | |
| 0.48.6 | 9 / 11 | |
| 0.48.5 | 9 / 11 | |
| 0.48.4 | 9 / 11 | |
| 0.48.3 | 9 / 11 | |
| 0.48.2 | 9 / 11 | |
| 0.48.1 | 9 / 11 | |
| 0.48.0 | 9 / 11 | |
| 0.47.8 | 9 / 11 | |
| 0.47.7 | 9 / 11 | |
| 0.47.6 | 9 / 11 | |
| 0.47.5 | 8 / 11 | |
| 0.47.4 | 8 / 11 | |
| 0.47.3 | 8 / 11 | |
| 0.47.2 | 8 / 11 | |
| 0.47.1 | 8 / 11 | |
| 0.47.0 | 8 / 11 | |
| 0.46.2 | 8 / 11 | |
| 0.46.1 | 8 / 11 | |
| 0.46.0 | 8 / 11 | |
| 0.45.3 | 8 / 11 | |
| 0.45.2 | 8 / 11 | |
| 0.45.1 | 8 / 11 | |
| 0.42.0 | 8 / 11 | |
| 0.41.0 | 8 / 11 | |
| 0.40.0 | 8 / 11 | |
| 0.39.0 | 8 / 11 | |
| 0.36.0 | 8 / 13 | |
| 0.32.5 | 10 / 21 | |
| 0.32.4 | 10 / 21 | |
| 0.32.3 | 10 / 21 | |
| 0.32.2 | 9 / 21 | |
| 0.32.1 | 10 / 21 | |
| 0.25.4 | 11 / 19 | |
| 0.25.3 | 11 / 19 | |
| 0.25.2 | 11 / 19 | |
| 0.25.1 | 11 / 19 | |
| 0.25.0 | 11 / 19 | |
| 0.23.1 | 11 / 16 | |
| 0.17.7 | 11 / 16 |
v0.49.18
2 findingsPackage contains compiled binaries that could be backdoors: • dist/browser/bullet_wasm_bg.wasm • dist/node/bullet_wasm_bg.wasm
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.49.17
2 findingsPackage contains compiled binaries that could be backdoors: • dist/browser/bullet_wasm_bg.wasm • dist/node/bullet_wasm_bg.wasm
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.49.16
2 findingsThis version was published by a different npm account than previous versions on 2026-07-03. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.48.7
4 findingsThis version was published by a different npm account than previous versions on 2026-03-17. This could indicate a legitimate maintainer transition or an account compromise.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.48.6
4 findingsThis version was published by a different npm account than previous versions on 2026-03-16. This could indicate a legitimate maintainer transition or an account compromise.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.48.5
4 findingsThis version was published by a different npm account than previous versions on 2026-03-16. This could indicate a legitimate maintainer transition or an account compromise.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.48.4
4 findingsThis version was published by a different npm account than previous versions on 2026-03-09. This could indicate a legitimate maintainer transition or an account compromise.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.48.3
4 findingsThis version was published by a different npm account than previous versions on 2026-03-05. This could indicate a legitimate maintainer transition or an account compromise.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.48.2
4 findingsThis version was published by a different npm account than previous versions on 2026-03-05. This could indicate a legitimate maintainer transition or an account compromise.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.48.1
4 findingsThis version was published by a different npm account than previous versions on 2026-03-04. This could indicate a legitimate maintainer transition or an account compromise.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.48.0
4 findingsThis version was published by a different npm account than previous versions on 2026-03-04. This could indicate a legitimate maintainer transition or an account compromise.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.47.8
4 findingsThis version was published by a different npm account than previous versions on 2026-03-04. This could indicate a legitimate maintainer transition or an account compromise.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.47.7
4 findingsThis version was published by a different npm account than previous versions on 2026-02-27. This could indicate a legitimate maintainer transition or an account compromise.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.47.6
4 findingsThis version was published by a different npm account than previous versions on 2026-02-26. This could indicate a legitimate maintainer transition or an account compromise.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.47.5
4 findingsThis version was published by a different npm account than previous versions on 2026-02-26. This could indicate a legitimate maintainer transition or an account compromise.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.47.4
4 findingsThis version was published by a different npm account than previous versions on 2026-02-26. This could indicate a legitimate maintainer transition or an account compromise.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.47.3
4 findingsThis version was published by a different npm account than previous versions on 2026-02-26. This could indicate a legitimate maintainer transition or an account compromise.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.47.2
4 findingsThis version was published by a different npm account than previous versions on 2026-02-24. This could indicate a legitimate maintainer transition or an account compromise.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.47.1
4 findingsThis version was published by a different npm account than previous versions on 2026-02-12. This could indicate a legitimate maintainer transition or an account compromise.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.47.0
4 findingsThis version was published by a different npm account than previous versions on 2026-02-12. This could indicate a legitimate maintainer transition or an account compromise.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.46.2
4 findingsThis version was published by a different npm account than previous versions on 2026-02-04. This could indicate a legitimate maintainer transition or an account compromise.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.46.1
4 findingsThis version was published by a different npm account than previous versions on 2026-02-04. This could indicate a legitimate maintainer transition or an account compromise.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.46.0
3 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.45.3
4 findingsThis version was published by a different npm account than previous versions on 2026-01-29. This could indicate a legitimate maintainer transition or an account compromise.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.45.2
4 findingsThis version was published by a different npm account than previous versions on 2026-01-29. This could indicate a legitimate maintainer transition or an account compromise.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.23.1
3 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.17.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.