@gooddollar/web3sdk-v2
ethers and react hooks based on usedapp sdk for GoodDollar protocol
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@types/react-native | AI (phantom-deps): Types-only package loaded by convention, not direct import. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New deps are established, purpose-aligned packages. | ai | |
| dependencies | unvetted-dep:@usedapp/core | AI (dependencies): Well-known usedapp core lib, matches package description. | ai | |
| source-diff | encoded-string-file:src/sdk/base/sdk.ts | AI (source-diff): Documented Divvi ABI-encoded hex data suffix, not an obfuscated payload. | ai | |
| source-diff | encoded-string-file:dist/cjs/sdk/base/sdk.js | AI (source-diff): Hex constant is an on-chain tx suffix, not an obfuscated payload. | ai | |
| source-diff | encoded-string-file:dist/esm/sdk/base/sdk.js | AI (source-diff): Same hex constant as CJS build; benign contract data. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): No material diff vs last approved version; consistent with routine maintenance release. | ai | |
| dependencies | unvetted-dep:@web3auth/core | AI (dependencies): Well-known wallet auth SDK, standard for web3 dapps. | ai | |
| phantom-deps | phantom-dep:@types/react | AI (phantom-deps): Framework-scoped type package, benign. | ai | |
| dependencies | unvetted-dep:@web3modal/react | AI (dependencies): Legitimate widely-used wallet-connect library matching package's stated web3 SDK purpose. | ai | |
| dependencies | unvetted-dep:@web3auth/base | AI (dependencies): Established web3auth SDK, standard for wallet auth. | ai | |
| phantom-deps | phantom-dep:viem | AI (phantom-deps): Config-referenced, expected for wagmi/web3modal setup. | ai | |
| provenance | no-provenance | AI (provenance): Established package with 451 versions; lack of provenance is consistent across all prior releases. | ai | |
| phantom-deps | phantom-dep:@walletconnect/qrcode-modal | AI (phantom-deps): WalletConnect UI dep; referenced in config but not directly imported, stable FP. | ai | |
| phantom-deps | phantom-dep:@ceramicnetwork/stream-tile | AI (phantom-deps): Same as above — optional Ceramic integration, stable FP. | ai | |
| phantom-deps | phantom-dep:@ceramicnetwork/http-client | AI (phantom-deps): Ceramic deps are optional integration points; phantom-dep heuristic is a stable FP for this package. | ai | |
| phantom-deps | phantom-dep:@walletconnect/client | AI (phantom-deps): Declared as peer/optional dep for wallet integration; not directly imported but legitimately referenced in config. | ai | |
| phantom-deps | phantom-dep:@web3auth/base | AI (phantom-deps): Declared for peer/config use; stable false positive for this SDK package. | ai | |
| semgrep | semgrep:shady-links-tlds | AI (semgrep): goodcollective.xyz is the project's own product domain, not a C2 endpoint. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Standard Buffer.from(base64) for S3 upload body; not obfuscation or exfiltration. | ai | |
| phantom-deps | phantom-dep:@solana/web3.js | AI (phantom-deps): Declared for peer/config use; stable false positive for this SDK package. | ai | |
| phantom-deps | phantom-dep:@web3auth/torus-wallet-connector-plugin | AI (phantom-deps): Declared for peer/config use; stable false positive for this SDK package. | ai | |
| phantom-deps | phantom-dep:@web3auth/openlogin-adapter | AI (phantom-deps): Declared for peer/config use; stable false positive for this SDK package. | ai | |
| phantom-deps | phantom-dep:@web3auth/core | AI (phantom-deps): Declared for peer/config use; stable false positive for this SDK package. | ai |
Versions (showing 51 of 110)
| Version | Deps | Published |
|---|---|---|
| 0.4.46 | 35 / 50 | |
| 0.4.45 | 35 / 50 | |
| 0.4.44 | 35 / 50 | |
| 0.4.43 | 35 / 50 | |
| 0.4.40 | 35 / 50 | |
| 0.4.37 | 35 / 50 | |
| 0.4.36 | 35 / 50 | |
| 0.4.35 | 37 / 50 | |
| 0.4.34 | 37 / 50 | |
| 0.4.33 | 37 / 50 | |
| 0.4.30 | 37 / 50 | |
| 0.4.29 | 37 / 50 | |
| 0.4.28 | 37 / 50 | |
| 0.4.27 | 37 / 50 | |
| 0.4.26 | 37 / 50 | |
| 0.4.25 | 37 / 50 | |
| 0.4.24 | 37 / 50 | |
| 0.4.23 | 37 / 50 | |
| 0.4.22 | 40 / 50 | |
| 0.4.21 | 40 / 50 | |
| 0.4.20 | 40 / 50 | |
| 0.4.19 | 40 / 50 | |
| 0.4.18 | 40 / 50 | |
| 0.4.17 | 40 / 50 | |
| 0.4.16 | 40 / 50 | |
| 0.4.15 | 40 / 50 | |
| 0.4.14 | 40 / 50 | |
| 0.4.13 | 40 / 50 | |
| 0.4.12 | 40 / 50 | |
| 0.4.11 | 40 / 50 | |
| 0.4.10 | 40 / 50 | |
| 0.4.9 | 40 / 50 | |
| 0.4.8 | 40 / 50 | |
| 0.4.7 | 40 / 50 | |
| 0.4.6 | 40 / 50 | |
| 0.4.5 | 40 / 50 | |
| 0.4.4 | 40 / 50 | |
| 0.4.3 | 40 / 50 | |
| 0.4.2 | 40 / 50 | |
| 0.4.1 | 41 / 49 | |
| 0.4.0 | 44 / 44 | |
| 0.3.3 | 37 / 49 | |
| 0.3.2 | 36 / 49 | |
| 0.2.34 | 39 / 45 | |
| 0.2.25 | 41 / 45 | |
| 0.2.22 | 41 / 45 | |
| 0.2.21 | 41 / 45 | |
| 0.2.20 | 40 / 46 | |
| 0.2.19 | 40 / 46 | |
| 0.2.18 | 40 / 46 | |
| 0.2.17 | 40 / 46 |
v0.4.46
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.45
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.44
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.36
4 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.34
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.33
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.30
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.29
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.28
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.27
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.26
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.24
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.17
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.6
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (sirpush) than the most recent previously approved version (lbwgd) on 2025-03-26, but sirpush is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.4.5
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (sirpush) than the most recent previously approved version (lbwgd) on 2025-03-25, but sirpush is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.4.4
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (lbwgd) than the most recent previously approved version (sirpush) on 2025-03-25, but lbwgd is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.4.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.0
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (lbwgd) than the most recent previously approved version (sirpush) on 2024-11-27, but lbwgd is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.3.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.34
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.25
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.22
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.21
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.20
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.19
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.18
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.17
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.