@coti-io/coti-contracts
A library for smart contract development on the COTI network.
5
Versions
—
License
No
Install Scripts
Attested
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation (unverified)
npm registry signatures
gitHead linked
Maintainers
gmesika-coti
Keywords
cotiprivacyethereumblockchainweb3garbled-circuitsl2on-chain-compute
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | large-new-source-files | AI (source-diff): 136 new files are typechain-generated factories for new PrivacyBridge contracts; consistent with feature expansion. | ai | |
| source-diff | obfuscated-file:typechain-types/factories/contracts/disperse/coinByRatio/FixedRatioCoinDisperserLeftoverS1__factory.ts | AI (source-diff): Typechain autogenerated factory file with long ABI/bytecode strings; not obfuscation. | ai | |
| source-diff | obfuscated-file:typechain-types/factories/contracts/disperse/coinByRatio/FixedRatioCoinDisperserUnlimitedWindow__factory.ts | AI (source-diff): Typechain autogenerated factory file with long ABI/bytecode strings; not obfuscation. | ai | |
| source-diff | encoded-string-file:typechain-types/factories/contracts/onboard/AccountOnboard__factory.ts | AI (source-diff): Long encoded strings are ABI/bytecode in typechain factory files; standard pattern for this package. | ai | |
| source-diff | obfuscated-file:typechain-types/factories/contracts/node/CotiNodeRewards__factory.ts | AI (source-diff): Typechain autogenerated factory file with long ABI/bytecode strings; not obfuscation. | ai | |
| source-diff | obfuscated-file:typechain-types/factories/contracts/oracle/CotiPriceConsumer__factory.ts | AI (source-diff): Typechain autogenerated factory file with long ABI/bytecode strings; not obfuscation. | ai | |
| source-diff | obfuscated-file:typechain-types/factories/@openzeppelin/contracts/token/ERC20/ERC20__factory.ts | AI (source-diff): Typechain autogenerated factory file with long ABI/bytecode strings; not obfuscation. | ai | |
| source-diff | obfuscated-file:typechain-types/factories/contracts/mocks/token/ERC20DecimalsMock__factory.ts | AI (source-diff): Typechain autogenerated factory file with long ABI/bytecode strings; not obfuscation. | ai | |
| source-diff | obfuscated-file:typechain-types/factories/contracts/mocks/token/ERC20Mock__factory.ts | AI (source-diff): Typechain autogenerated factory file with long ABI/bytecode strings; not obfuscation. | ai | |
| source-diff | obfuscated-file:typechain-types/factories/@openzeppelin/contracts/token/ERC721/ERC721__factory.ts | AI (source-diff): Typechain autogenerated factory file with long ABI/bytecode strings; not obfuscation. | ai | |
| phantom-deps | phantom-dep:@openzeppelin/contracts | AI (phantom-deps): Referenced in Solidity/config files, not JS imports. Expected pattern for a smart contract library. | ai | |
| phantom-deps | phantom-dep:@coti-io/coti-sdk-typescript | AI (phantom-deps): Same-org dep used in test/config context; not a direct JS import. Stable FP for this package. | ai | |
| phantom-deps | phantom-dep:@coti-io/coti-ethers | AI (phantom-deps): Solidity contracts library; deps used in hardhat config/tooling, not direct JS imports. Stable FP for this package. | ai |
Versions (showing 5 of 5)
| Version | Deps | Published |
|---|---|---|
| 1.3.0 | 4 / 19 | |
| 1.2.0 | 4 / 19 | |
| 1.1.0 | 3 / 2 | |
| 1.0.2 | 3 / 2 | |
| 1.0.0 | 3 / 2 |
v1.0.2
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.0
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.