@hashgraph/sdk
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | bulk-obfuscated-files:lib | AI (source-diff): Babel-compiled lib/ output; hex blob is embedded address-book protobuf data, benign. | ai | |
| phantom-deps | phantom-dep:@types/utf8 | AI (phantom-deps): Type-only package, loaded by convention. | ai | |
| npm-metadata | url-dep:@hashgraph/cryptography | AI (npm-metadata): Lerna monorepo sibling package reference, standard for this SDK's structure. | ai | |
| phantom-deps | phantom-dep:@types/crypto-js | AI (phantom-deps): Type-only package, loaded by convention. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Minified lib/ build output shipped alongside src/; benign for this SDK. | ai | |
| source-diff | encoded-string-file:lib/address_book/AddressBooks.cjs | AI (source-diff): Hex-encoded protobuf NodeAddressBook data for mainnet/testnet/previewnet; expected for this SDK. | ai | |
| source-diff | obfuscated-file:lib/network/AddressBookQueryWeb.js | AI (source-diff): Browser-targeted minified bundle mapped in package.json browser field; standard build output for this SDK. | ai | |
| source-diff | encoded-string-file:lib/client/addressbooks/previewnet.d.ts | AI (source-diff): Type declaration includes address book constant; expected for this SDK. | ai | |
| source-diff | encoded-string-file:lib/client/addressbooks/mainnet.d.ts | AI (source-diff): Type declaration includes address book constant; expected for this SDK. | ai | |
| source-diff | encoded-string-file:dist/umd.js | AI (source-diff): UMD bundle includes the same protobuf-encoded address book data; expected bundled artifact. | ai | |
| source-diff | encoded-string-file:lib/client/addressbooks/testnet.d.ts | AI (source-diff): Type declaration includes address book constant; expected for this SDK. | ai | |
| source-diff | encoded-string-file:dist/umd.min.js | AI (source-diff): Minified UMD bundle includes the same protobuf-encoded address book data; expected bundled artifact. | ai | |
| source-diff | encoded-string-file:lib/client/addressbooks/previewnet.js | AI (source-diff): Hex-encoded protobuf address book data for Hedera previewnet nodes; stable pattern in this SDK. | ai | |
| source-diff | encoded-string-file:lib/client/addressbooks/mainnet.cjs | AI (source-diff): Hex-encoded protobuf address book data for Hedera mainnet nodes; stable pattern in this SDK. | ai | |
| source-diff | encoded-string-file:lib/client/addressbooks/previewnet.cjs | AI (source-diff): Hex-encoded protobuf address book data for Hedera previewnet nodes; stable pattern in this SDK. | ai | |
| source-diff | encoded-string-file:lib/client/addressbooks/testnet.cjs | AI (source-diff): Hex-encoded protobuf address book data for Hedera testnet nodes; stable pattern in this SDK. | ai | |
| source-diff | encoded-string-file:lib/client/addressbooks/mainnet.js | AI (source-diff): Hex-encoded protobuf address book data for Hedera mainnet nodes; stable pattern in this SDK. | ai | |
| source-diff | encoded-string-file:src/client/addressbooks/mainnet.js | AI (source-diff): Hex-encoded protobuf address book data for Hedera mainnet nodes; stable pattern in this SDK. | ai | |
| source-diff | encoded-string-file:src/client/addressbooks/previewnet.js | AI (source-diff): Hex-encoded protobuf address book data for Hedera previewnet nodes; stable pattern in this SDK. | ai | |
| source-diff | encoded-string-file:lib/client/addressbooks/testnet.js | AI (source-diff): Hex-encoded protobuf address book data for Hedera testnet nodes; stable pattern in this SDK. | ai | |
| source-diff | encoded-string-file:src/client/addressbooks/testnet.js | AI (source-diff): Hex-encoded protobuf address book data for Hedera testnet nodes; stable pattern in this SDK. | ai | |
| dependencies | unvetted-dep:@hashgraph/proto | AI (dependencies): First-party Hedera/Hiero protobuf definitions package; expected dependency for this SDK. | ai | |
| dependencies | unvetted-dep:protobufjs | AI (dependencies): protobufjs is a well-known, widely-used protobuf library; its use in a blockchain SDK is expected and legitimate. | ai | |
| dependencies | unvetted-dep:@hashgraph/cryptography | AI (dependencies): First-party Hedera/Hiero cryptography package; expected dependency for this SDK. | ai | |
| phantom-deps | phantom-dep:ansi-styles | AI (phantom-deps): ansi-styles is declared as a direct dependency; phantom detection is a false positive for this package. | ai | |
| phantom-deps | phantom-dep:strip-ansi | AI (phantom-deps): strip-ansi is declared as a direct dependency; phantom detection is a false positive for this package. | ai | |
| phantom-deps | phantom-dep:ansi-regex | AI (phantom-deps): ansi-regex is declared as a direct dependency; phantom detection is a false positive for this package. | ai | |
| phantom-deps | phantom-dep:debug | AI (phantom-deps): debug is declared as a direct dependency; phantom detection is a false positive for this package's build/import structure. | ai | |
| semgrep | semgrep:hex-decode | AI (semgrep): Buffer.from(str, 'hex') is standard Node.js hex decoding, expected and necessary in a blockchain SDK for handling keys, addresses, and transaction data. | ai | |
| phantom-deps | phantom-dep:bn.js | AI (phantom-deps): bn.js is declared as a peerDependency and in resolutions; phantom detection is a false positive for this package's build structure. | ai | |
| phantom-deps | phantom-dep:@ethersproject/bignumber | AI (phantom-deps): @ethersproject/bignumber is declared as a direct dependency; phantom detection is a false positive for this package. | ai | |
| phantom-deps | phantom-dep:pino-pretty | AI (phantom-deps): pino-pretty is declared as a direct dependency; phantom detection is a false positive for this package. | ai |
Versions (showing 51 of 71)
| Version | Deps | Published |
|---|---|---|
| 2.81.0 | 21 / 56 | |
| 2.80.0 | 21 / 54 | |
| 2.79.0 | 21 / 54 | |
| 2.78.0 | 21 / 54 | |
| 2.77.0 | 21 / 54 | |
| 2.76.0 | 21 / 54 | |
| 2.75.0 | 21 / 54 | |
| 2.74.0 | 21 / 54 | |
| 2.73.2 | 21 / 54 | |
| 2.73.1 | 21 / 54 | |
| 2.72.0 | 17 / 54 | |
| 2.71.1 | 17 / 54 | |
| 2.71.0 | 17 / 54 | |
| 2.70.0 | 17 / 54 | |
| 2.69.0 | 17 / 54 | |
| 2.68.0 | 17 / 53 | |
| 2.67.0 | 17 / 53 | |
| 2.66.0 | 17 / 53 | |
| 2.65.1 | 17 / 53 | |
| 2.65.0 | 17 / 53 | |
| 2.64.5 | 17 / 53 | |
| 2.64.3 | 17 / 53 | |
| 2.62.0 | 17 / 53 | |
| 2.61.0 | 17 / 50 | |
| 2.59.0 | 18 / 48 | |
| 2.58.0 | 18 / 48 | |
| 2.57.2 | 18 / 48 | |
| 2.56.0 | 18 / 48 | |
| 2.55.1 | 18 / 48 | |
| 2.55.0 | 18 / 48 | |
| 2.54.2 | 18 / 49 | |
| 2.53.0 | 18 / 49 | |
| 2.52.0 | 18 / 49 | |
| 2.51.0 | 18 / 49 | |
| 2.50.0 | 18 / 49 | |
| 2.49.2 | 18 / 49 | |
| 2.48.1 | 18 / 49 | |
| 2.48.0 | 18 / 49 | |
| 2.47.0 | 18 / 49 | |
| 2.46.0 | 18 / 49 | |
| 2.45.0 | 18 / 48 | |
| 2.2.0 | 9 / 39 | |
| 2.0.28 | 11 / 36 | |
| 2.0.27 | 11 / 36 | |
| 2.0.26 | 11 / 36 | |
| 2.0.25 | 11 / 36 | |
| 2.0.24 | 11 / 36 | |
| 2.0.23 | 11 / 36 | |
| 2.0.22 | 11 / 36 | |
| 2.0.21 | 11 / 36 | |
| 2.0.20 | 11 / 36 |
v2.62.0
20 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.61.0
20 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.59.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.58.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.57.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.56.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.55.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.55.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.54.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.53.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.52.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.51.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.50.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.49.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.48.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.48.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.47.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.46.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.45.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: danielakhterov.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.28
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: danielakhterov.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.27
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.26
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.25
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.24
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.23
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.22
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.21
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.20
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.