@icgio/icg-exchanges
icgio exchanges package
16
Versions
ISC
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
npmlq
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:child-process-import | AI (semgrep): Exchange integration package; execFile in blofin.js is a pre-existing pattern for this exchange connector. | ai | |
| source-diff | net-exec-file:lib/utils/mexc/PublicSpotKlineV3Api_pb.js | AI (source-diff): Standard google-protobuf JsPbCodeGenerator output. | ai | |
| source-diff | net-exec-file:lib/utils/mexc/PushDataV3ApiWrapper_pb.js | AI (source-diff): Standard google-protobuf JsPbCodeGenerator output. | ai | |
| source-diff | net-exec-file:lib/utils/mexc/PrivateAccountV3Api_pb.js | AI (source-diff): Standard google-protobuf JsPbCodeGenerator output; Function('return this') is the canonical global detection pattern, not malware. | ai | |
| source-diff | net-exec-file:lib/utils/mexc/PrivateDealsV3Api_pb.js | AI (source-diff): Standard google-protobuf JsPbCodeGenerator output. | ai | |
| source-diff | net-exec-file:lib/utils/mexc/PrivateOrdersV3Api_pb.js | AI (source-diff): Standard google-protobuf JsPbCodeGenerator output. | ai | |
| source-diff | net-exec-file:lib/utils/mexc/PublicAggreBookTickerV3Api_pb.js | AI (source-diff): Standard google-protobuf JsPbCodeGenerator output. | ai | |
| source-diff | net-exec-file:lib/utils/mexc/PublicAggreDealsV3Api_pb.js | AI (source-diff): Standard google-protobuf JsPbCodeGenerator output. | ai | |
| source-diff | net-exec-file:lib/utils/mexc/PublicAggreDepthsV3Api_pb.js | AI (source-diff): Standard google-protobuf JsPbCodeGenerator output. | ai | |
| source-diff | net-exec-file:lib/utils/mexc/PublicBookTickerBatchV3Api_pb.js | AI (source-diff): Standard google-protobuf JsPbCodeGenerator output. | ai | |
| source-diff | net-exec-file:lib/utils/mexc/PublicBookTickerV3Api_pb.js | AI (source-diff): Standard google-protobuf JsPbCodeGenerator output. | ai | |
| source-diff | net-exec-file:lib/utils/mexc/PublicDealsV3Api_pb.js | AI (source-diff): Standard google-protobuf JsPbCodeGenerator output. | ai | |
| source-diff | net-exec-file:lib/utils/mexc/PublicIncreaseDepthsBatchV3Api_pb.js | AI (source-diff): Standard google-protobuf JsPbCodeGenerator output. | ai | |
| source-diff | net-exec-file:lib/utils/mexc/PublicIncreaseDepthsV3Api_pb.js | AI (source-diff): Standard google-protobuf JsPbCodeGenerator output. | ai | |
| source-diff | net-exec-file:lib/utils/mexc/PublicLimitDepthsV3Api_pb.js | AI (source-diff): Standard google-protobuf JsPbCodeGenerator output. | ai | |
| source-diff | net-exec-file:lib/utils/mexc/PublicMiniTickersV3Api_pb.js | AI (source-diff): Standard google-protobuf JsPbCodeGenerator output. | ai | |
| source-diff | net-exec-file:lib/utils/mexc/PublicMiniTickerV3Api_pb.js | AI (source-diff): Standard google-protobuf JsPbCodeGenerator output. | ai | |
| semgrep | semgrep:shady-links-tlds | AI (semgrep): gateio.ws is the legitimate Gate.io exchange API domain; .ws TLD is part of their official branding. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Base64 used for HMAC signature construction per Coinbase FIX API spec — standard crypto pattern, not obfuscation. | ai |