← Home

@hashgraph/sdk

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

steven.sheehyswirldslabs-adminrbair23nathan-swirldslabshedera-eng-automationnana-ec

Keywords

hierohederahashgraphsdktransactions

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff bulk-obfuscated-files:lib AI (source-diff): Babel-compiled lib/ output; hex blob is embedded address-book protobuf data, benign. ai
phantom-deps phantom-dep:@types/utf8 AI (phantom-deps): Type-only package, loaded by convention. ai
npm-metadata url-dep:@hashgraph/cryptography AI (npm-metadata): Lerna monorepo sibling package reference, standard for this SDK's structure. ai
phantom-deps phantom-dep:@types/crypto-js AI (phantom-deps): Type-only package, loaded by convention. ai
source-diff large-new-source-files AI (source-diff): Minified lib/ build output shipped alongside src/; benign for this SDK. ai
source-diff encoded-string-file:lib/address_book/AddressBooks.cjs AI (source-diff): Hex-encoded protobuf NodeAddressBook data for mainnet/testnet/previewnet; expected for this SDK. ai
source-diff obfuscated-file:lib/network/AddressBookQueryWeb.js AI (source-diff): Browser-targeted minified bundle mapped in package.json browser field; standard build output for this SDK. ai
source-diff encoded-string-file:lib/client/addressbooks/previewnet.d.ts AI (source-diff): Type declaration includes address book constant; expected for this SDK. ai
source-diff encoded-string-file:lib/client/addressbooks/mainnet.d.ts AI (source-diff): Type declaration includes address book constant; expected for this SDK. ai
source-diff encoded-string-file:dist/umd.js AI (source-diff): UMD bundle includes the same protobuf-encoded address book data; expected bundled artifact. ai
source-diff encoded-string-file:lib/client/addressbooks/testnet.d.ts AI (source-diff): Type declaration includes address book constant; expected for this SDK. ai
source-diff encoded-string-file:dist/umd.min.js AI (source-diff): Minified UMD bundle includes the same protobuf-encoded address book data; expected bundled artifact. ai
source-diff encoded-string-file:lib/client/addressbooks/previewnet.js AI (source-diff): Hex-encoded protobuf address book data for Hedera previewnet nodes; stable pattern in this SDK. ai
source-diff encoded-string-file:lib/client/addressbooks/mainnet.cjs AI (source-diff): Hex-encoded protobuf address book data for Hedera mainnet nodes; stable pattern in this SDK. ai
source-diff encoded-string-file:lib/client/addressbooks/previewnet.cjs AI (source-diff): Hex-encoded protobuf address book data for Hedera previewnet nodes; stable pattern in this SDK. ai
source-diff encoded-string-file:lib/client/addressbooks/testnet.cjs AI (source-diff): Hex-encoded protobuf address book data for Hedera testnet nodes; stable pattern in this SDK. ai
source-diff encoded-string-file:lib/client/addressbooks/mainnet.js AI (source-diff): Hex-encoded protobuf address book data for Hedera mainnet nodes; stable pattern in this SDK. ai
source-diff encoded-string-file:src/client/addressbooks/mainnet.js AI (source-diff): Hex-encoded protobuf address book data for Hedera mainnet nodes; stable pattern in this SDK. ai
source-diff encoded-string-file:src/client/addressbooks/previewnet.js AI (source-diff): Hex-encoded protobuf address book data for Hedera previewnet nodes; stable pattern in this SDK. ai
source-diff encoded-string-file:lib/client/addressbooks/testnet.js AI (source-diff): Hex-encoded protobuf address book data for Hedera testnet nodes; stable pattern in this SDK. ai
source-diff encoded-string-file:src/client/addressbooks/testnet.js AI (source-diff): Hex-encoded protobuf address book data for Hedera testnet nodes; stable pattern in this SDK. ai
dependencies unvetted-dep:@hashgraph/proto AI (dependencies): First-party Hedera/Hiero protobuf definitions package; expected dependency for this SDK. ai
dependencies unvetted-dep:protobufjs AI (dependencies): protobufjs is a well-known, widely-used protobuf library; its use in a blockchain SDK is expected and legitimate. ai
dependencies unvetted-dep:@hashgraph/cryptography AI (dependencies): First-party Hedera/Hiero cryptography package; expected dependency for this SDK. ai
phantom-deps phantom-dep:ansi-styles AI (phantom-deps): ansi-styles is declared as a direct dependency; phantom detection is a false positive for this package. ai
phantom-deps phantom-dep:strip-ansi AI (phantom-deps): strip-ansi is declared as a direct dependency; phantom detection is a false positive for this package. ai
phantom-deps phantom-dep:ansi-regex AI (phantom-deps): ansi-regex is declared as a direct dependency; phantom detection is a false positive for this package. ai
phantom-deps phantom-dep:debug AI (phantom-deps): debug is declared as a direct dependency; phantom detection is a false positive for this package's build/import structure. ai
semgrep semgrep:hex-decode AI (semgrep): Buffer.from(str, 'hex') is standard Node.js hex decoding, expected and necessary in a blockchain SDK for handling keys, addresses, and transaction data. ai
phantom-deps phantom-dep:bn.js AI (phantom-deps): bn.js is declared as a peerDependency and in resolutions; phantom detection is a false positive for this package's build structure. ai
phantom-deps phantom-dep:@ethersproject/bignumber AI (phantom-deps): @ethersproject/bignumber is declared as a direct dependency; phantom detection is a false positive for this package. ai
phantom-deps phantom-dep:pino-pretty AI (phantom-deps): pino-pretty is declared as a direct dependency; phantom detection is a false positive for this package. ai

Versions (showing 51 of 71)

View all versions
Version Deps Published
2.81.0 21 / 56
2.80.0 21 / 54
2.79.0 21 / 54
2.78.0 21 / 54
2.77.0 21 / 54
2.76.0 21 / 54
2.75.0 21 / 54
2.74.0 21 / 54
2.73.2 21 / 54
2.73.1 21 / 54
2.72.0 17 / 54
2.71.1 17 / 54
2.71.0 17 / 54
2.70.0 17 / 54
2.69.0 17 / 54
2.68.0 17 / 53
2.67.0 17 / 53
2.66.0 17 / 53
2.65.1 17 / 53
2.65.0 17 / 53
2.64.5 17 / 53
2.64.3 17 / 53
2.62.0 17 / 53
2.61.0 17 / 50
2.59.0 18 / 48
2.58.0 18 / 48
2.57.2 18 / 48
2.56.0 18 / 48
2.55.1 18 / 48
2.55.0 18 / 48
2.54.2 18 / 49
2.53.0 18 / 49
2.52.0 18 / 49
2.51.0 18 / 49
2.50.0 18 / 49
2.49.2 18 / 49
2.48.1 18 / 49
2.48.0 18 / 49
2.47.0 18 / 49
2.46.0 18 / 49
2.45.0 18 / 48
2.2.0 9 / 39
2.0.28 11 / 36
2.0.27 11 / 36
2.0.26 11 / 36
2.0.25 11 / 36
2.0.24 11 / 36
2.0.23 11 / 36
2.0.22 11 / 36
2.0.21 11 / 36
2.0.20 11 / 36

v2.62.0

20 findings
HIGH New obfuscated file: lib/token/AbstractTokenTransferTransaction.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/account/AccountAllowanceAdjustTransaction.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/account/AccountAllowanceApproveTransaction.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/account/AccountCreateTransaction.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/account/AccountId.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/account/AccountInfo.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/account/AccountUpdateTransaction.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/address_book/AddressBooks.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/browser.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/Cache.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/client/Client.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/constants/ClientConstants.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/contract/ContractCallQuery.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/contract/ContractCreateFlow.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/contract/ContractCreateTransaction.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/contract/ContractFunctionParameters.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/contract/ContractFunctionResult.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/contract/ContractFunctionSelector.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/contract/ContractUpdateTransaction.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.61.0

20 findings
HIGH New obfuscated file: lib/token/AbstractTokenTransferTransaction.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/account/AccountAllowanceAdjustTransaction.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/account/AccountAllowanceApproveTransaction.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/account/AccountCreateTransaction.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/account/AccountId.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/account/AccountInfo.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/account/AccountUpdateTransaction.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/address_book/AddressBooks.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/browser.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/Cache.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/client/Client.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/constants/ClientConstants.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/contract/ContractCallQuery.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/contract/ContractCreateFlow.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/contract/ContractCreateTransaction.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/contract/ContractFunctionParameters.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/contract/ContractFunctionResult.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/contract/ContractFunctionSelector.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/contract/ContractUpdateTransaction.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.59.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.58.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.57.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.56.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.55.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.55.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.54.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.53.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.52.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.51.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.50.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.49.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.48.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.48.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.47.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.46.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.45.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.2.0

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: danielakhterov.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.28

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: danielakhterov.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.27

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.26

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.25

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.24

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.23

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.22

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.21

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.20

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.