← Home

@coti-io/coti-contracts

A library for smart contract development on the COTI network.

5
Versions
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures gitHead linked

Maintainers

gmesika-coti

Keywords

cotiprivacyethereumblockchainweb3garbled-circuitsl2on-chain-compute

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff large-new-source-files AI (source-diff): 136 new files are typechain-generated factories for new PrivacyBridge contracts; consistent with feature expansion. ai
source-diff obfuscated-file:typechain-types/factories/contracts/disperse/coinByRatio/FixedRatioCoinDisperserLeftoverS1__factory.ts AI (source-diff): Typechain autogenerated factory file with long ABI/bytecode strings; not obfuscation. ai
source-diff obfuscated-file:typechain-types/factories/contracts/disperse/coinByRatio/FixedRatioCoinDisperserUnlimitedWindow__factory.ts AI (source-diff): Typechain autogenerated factory file with long ABI/bytecode strings; not obfuscation. ai
source-diff encoded-string-file:typechain-types/factories/contracts/onboard/AccountOnboard__factory.ts AI (source-diff): Long encoded strings are ABI/bytecode in typechain factory files; standard pattern for this package. ai
source-diff obfuscated-file:typechain-types/factories/contracts/node/CotiNodeRewards__factory.ts AI (source-diff): Typechain autogenerated factory file with long ABI/bytecode strings; not obfuscation. ai
source-diff obfuscated-file:typechain-types/factories/contracts/oracle/CotiPriceConsumer__factory.ts AI (source-diff): Typechain autogenerated factory file with long ABI/bytecode strings; not obfuscation. ai
source-diff obfuscated-file:typechain-types/factories/@openzeppelin/contracts/token/ERC20/ERC20__factory.ts AI (source-diff): Typechain autogenerated factory file with long ABI/bytecode strings; not obfuscation. ai
source-diff obfuscated-file:typechain-types/factories/contracts/mocks/token/ERC20DecimalsMock__factory.ts AI (source-diff): Typechain autogenerated factory file with long ABI/bytecode strings; not obfuscation. ai
source-diff obfuscated-file:typechain-types/factories/contracts/mocks/token/ERC20Mock__factory.ts AI (source-diff): Typechain autogenerated factory file with long ABI/bytecode strings; not obfuscation. ai
source-diff obfuscated-file:typechain-types/factories/@openzeppelin/contracts/token/ERC721/ERC721__factory.ts AI (source-diff): Typechain autogenerated factory file with long ABI/bytecode strings; not obfuscation. ai
phantom-deps phantom-dep:@openzeppelin/contracts AI (phantom-deps): Referenced in Solidity/config files, not JS imports. Expected pattern for a smart contract library. ai
phantom-deps phantom-dep:@coti-io/coti-sdk-typescript AI (phantom-deps): Same-org dep used in test/config context; not a direct JS import. Stable FP for this package. ai
phantom-deps phantom-dep:@coti-io/coti-ethers AI (phantom-deps): Solidity contracts library; deps used in hardhat config/tooling, not direct JS imports. Stable FP for this package. ai

Versions (showing 5 of 5)

Version Deps Published
1.3.0 4 / 19
1.2.0 4 / 19
1.1.0 3 / 2
1.0.2 3 / 2
1.0.0 3 / 2

v1.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.