← Home

@hiero-ledger/sdk

1
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

lfdt-npmrbarkernathan-swirldslabsandrewb1269hg

Keywords

hierohederahashgraphsdktransactions

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:hex-decode AI (semgrep): Buffer.from(str, 'hex') is standard Node.js hex decoding in an encoding utility; not malicious. ai
phantom-deps phantom-dep:bn.js AI (phantom-deps): bn.js is a declared peer dependency; phantom-dep heuristic fires incorrectly here. ai
phantom-deps phantom-dep:debug AI (phantom-deps): debug is a direct runtime dependency; phantom-dep heuristic is a false positive. ai
phantom-deps phantom-dep:ansi-regex AI (phantom-deps): ansi-regex is a direct runtime dependency; phantom-dep heuristic is a false positive. ai
phantom-deps phantom-dep:strip-ansi AI (phantom-deps): strip-ansi is a direct runtime dependency; phantom-dep heuristic is a false positive. ai
phantom-deps phantom-dep:ansi-styles AI (phantom-deps): ansi-styles is a direct runtime dependency; phantom-dep heuristic is a false positive. ai
phantom-deps phantom-dep:pino-pretty AI (phantom-deps): pino-pretty is a direct runtime dependency; phantom-dep heuristic is a false positive. ai

Versions (showing 1 of 1)

Version Deps Published
2.83.0 18 / 55