@injectivelabs/wallet-turnkey
Turnkey wallet strategy for use with @injectivelabs/wallet-core.
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@injectivelabs/wallet-base | AI (phantom-deps): Direct dep; re-exported by this package's public API. | ai | |
| phantom-deps | phantom-dep:@injectivelabs/utils | AI (phantom-deps): Same-org dep; re-exported by upstream packages in monorepo. | ai | |
| phantom-deps | phantom-dep:@turnkey/sdk-browser | AI (phantom-deps): Direct dep; re-exported by upstream wallet-base package. | ai | |
| phantom-deps | phantom-dep:@injectivelabs/sdk-ts | AI (phantom-deps): Same-org dep; re-exported by upstream wallet-base package. | ai | |
| phantom-deps | phantom-dep:@injectivelabs/ts-types | AI (phantom-deps): Same-org dep; re-exported by upstream packages in monorepo. | ai | |
| phantom-deps | phantom-dep:@injectivelabs/exceptions | AI (phantom-deps): Same-org dep; re-exported by upstream packages in monorepo. | ai | |
| phantom-deps | phantom-dep:viem | AI (phantom-deps): Transitive dep of @turnkey/viem; re-exported by upstream packages. | ai | |
| phantom-deps | phantom-dep:@turnkey/viem | AI (phantom-deps): Direct dep; re-exported by upstream wallet-base package. | ai | |
| provenance | slsa-provenance | AI (provenance): Package consistently published via CI/CD with Sigstore attestation; stable signal for this package. | ai | |
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions CI publisher is consistent with org-level CI/CD migration for InjectiveLabs monorepo. | ai | |
| provenance | missing-githead | AI (provenance): Missing gitHead is a side effect of the CI/CD publish environment change; SLSA attestation compensates. | ai | |
| dependencies | unvetted-dep:@turnkey/sdk-browser | AI (dependencies): Legitimate Turnkey SDK dependency matching the package's documented wallet integration purpose. | ai | |
| dependencies | unvetted-dep:@turnkey/viem | AI (dependencies): Legitimate Turnkey SDK dependency matching the package's documented wallet integration purpose. | ai |
Versions (showing 33 of 146)
| Version | Deps | Published |
|---|---|---|
| 1.16.2 | 8 / 7 | |
| 1.16.1 | 8 / 7 | |
| 1.15.43 | 8 / 7 | |
| 1.15.42 | 8 / 7 | |
| 1.15.41 | 8 / 7 | |
| 1.15.40 | 8 / 7 | |
| 1.15.39 | 8 / 7 | |
| 1.15.38 | 8 / 7 | |
| 1.15.37 | 8 / 7 | |
| 1.15.36 | 8 / 7 | |
| 1.15.35 | 8 / 7 | |
| 1.15.34 | 8 / 7 | |
| 1.15.33 | 8 / 7 | |
| 1.15.32 | 8 / 7 | |
| 1.15.31 | 8 / 7 | |
| 1.15.30 | 8 / 7 | |
| 1.15.29 | 8 / 7 | |
| 1.15.28 | 8 / 7 | |
| 1.15.27 | 8 / 7 | |
| 1.15.26 | 8 / 7 | |
| 1.15.25 | 8 / 7 | |
| 1.15.24 | 8 / 7 | |
| 1.15.23 | 8 / 7 | |
| 1.15.22 | 8 / 7 | |
| 1.15.21 | 8 / 7 | |
| 1.15.20 | 8 / 7 | |
| 1.15.19 | 8 / 7 | |
| 1.15.18 | 8 / 7 | |
| 1.15.17 | 8 / 7 | |
| 1.15.16 | 8 / 7 | |
| 1.15.15 | 8 / 7 | |
| 1.15.13 | 8 / 7 | |
| 1.15.10 | 8 / 7 |
v1.16.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.16.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.15.43
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.15.42
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.15.41
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.15.40
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.15.39
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.15.38
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.15.37
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.15.36
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.15.35
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.15.34
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.15.33
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.15.32
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.15.31
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.15.30
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.15.29
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.15.28
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.15.27
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.15.26
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.15.25
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.15.24
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.15.23
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.15.22
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.15.21
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.15.20
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.15.19
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.15.18
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.15.17
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.15.16
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.15.15
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.15.13
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.15.10
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.