← Home

@credo-ts/cheqd

<p align="center"> <br /> <img alt="Credo Logo" src="https://github.com/openwallet-foundation/credo-ts/blob/c7886cb8377ceb8ee4efe8d264211e561a75072d/images/credo-logo.png" height="250px" /> </p> <h1 align="center"><b>Credo Cheqd Module</

22
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

openwalletfoundationtimoglastragenaris

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern new-deps-added AI (publish-pattern): Adds @cosmjs/stargate, same trusted cosmjs family already used elsewhere in deps. ai
provenance missing-githead AI (provenance): Metadata gap, not a behavioral change; publisher has strong track record. ai
maintainer-change maintainer-added AI (maintainer-change): genaris is a known contributor in the OpenWallet Foundation org; addition consistent with legitimate project growth. ai
provenance publisher-changed AI (provenance): Transition to GitHub Actions publisher with SLSA attestation is the documented CI/CD release pattern for openwallet-foundation/credo-ts. ai
dependencies unvetted-dep:@cheqd/ts-proto AI (dependencies): First-party cheqd protobuf types; stable dependency for this integration package. ai
dependencies unvetted-dep:@cheqd/sdk AI (dependencies): First-party cheqd SDK; expected core dependency for this cheqd integration package across all versions. ai
phantom-deps phantom-dep:rxjs AI (phantom-deps): rxjs is a runtime dep used transitively via cheqd SDK; phantom-dep heuristic fires on config references. ai
phantom-deps phantom-dep:@stablelib/ed25519 AI (phantom-deps): Crypto dep declared for type/config usage; stable false positive for this package. ai
phantom-deps phantom-dep:tsyringe AI (phantom-deps): tsyringe is a DI framework used by credo-ts; referenced in config/type files, stable false positive. ai

Versions (showing 22 of 22)

Version Deps Published
0.7.0 13 / 1
0.6.3 12 / 1
0.6.2 12 / 1
0.6.1 12 / 1
0.6.0 12 / 1
0.5.19 12 / 2
0.5.18 12 / 2
0.5.17 12 / 2
0.5.16 12 / 2
0.5.15 12 / 2
0.5.14 12 / 2
0.5.13 12 / 2
0.5.12 12 / 2
0.5.11 12 / 2
0.5.10 12 / 2
0.5.9 12 / 2
0.5.8 12 / 2
0.5.7 12 / 2
0.5.3 11 / 2
0.5.2 11 / 2
0.5.1 11 / 2
0.5.0 11 / 2

v0.5.13

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: openwalletfoundation.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.12

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: openwalletfoundation.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.11

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: openwalletfoundation.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.10

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: openwalletfoundation.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.9

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: openwalletfoundation.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.8

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: openwalletfoundation.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.7

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: openwalletfoundation.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.5.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.5.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.