@interchainjs/crypto
Cryptography resources for blockchain projects
16
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
pyramationzetazz
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:libsodium-wrappers-sumo | AI (phantom-deps): libsodium-wrappers-sumo is a legitimate cryptographic library; phantom-dep reflects indirect usage. | ai | |
| phantom-deps | phantom-dep:bn.js | AI (phantom-deps): bn.js is a legitimate cryptographic dependency; phantom-dep pattern is common in crypto libraries with indirect imports. | ai | |
| phantom-deps | phantom-dep:elliptic | AI (phantom-deps): elliptic is a standard ECC library; phantom-dep pattern reflects indirect usage through re-exports. | ai | |
| phantom-deps | phantom-dep:@noble/hashes | AI (phantom-deps): @noble/hashes is a legitimate cryptographic dependency; phantom-dep is stable for this package. | ai | |
| phantom-deps | phantom-dep:@interchainjs/math | AI (phantom-deps): Internal monorepo dependency; phantom-dep pattern is expected for same-org scoped packages. | ai | |
| phantom-deps | phantom-dep:@interchainjs/utils | AI (phantom-deps): Internal monorepo dependency; phantom-dep pattern is expected for same-org scoped packages. | ai | |
| phantom-deps | phantom-dep:@interchainjs/encoding | AI (phantom-deps): Internal monorepo dependency; phantom-dep pattern is expected for same-org scoped packages. | ai | |
| dependencies | unvetted-dep:libsodium-wrappers-sumo | AI (dependencies): libsodium-wrappers-sumo is a well-known, widely-used cryptographic library. Its use in a blockchain crypto package is expected and appropriate; stable false positive for this package. | ai | |
| provenance | publisher-changed | AI (provenance): pyramation is a highly trusted publisher (2694 approved/0 rejected, 2767 days history) taking over from zetazz within the same hyperweb-io/interchainjs ecosystem — consistent with a legitimate org-level maintainer transition. | ai | |
| provenance | no-provenance | AI (provenance): Established package with 57 versions and strong publisher track record; lack of Sigstore provenance is a minor hygiene issue, not a security risk for this package. | ai | |
| dependencies | unvetted-dep:@interchainjs/math | AI (dependencies): First-party sibling package in the interchainjs monorepo; always published in lockstep with this package. Not an independent risk. | ai | |
| dependencies | unvetted-dep:@interchainjs/utils | AI (dependencies): First-party sibling package in the interchainjs monorepo; always published in lockstep with this package. Not an independent risk. | ai | |
| dependencies | unvetted-dep:@interchainjs/encoding | AI (dependencies): First-party sibling package in the interchainjs monorepo; always published in lockstep with this package. Not an independent risk. | ai | |
| dependencies | unvetted-dep:elliptic | AI (dependencies): elliptic is a well-established cryptographic library widely used in blockchain ecosystems; its use here is expected and stable across versions of this package. | ai | |
| typosquat | typosquat.levenshtein:bcrypt | AI (typosquat): @interchainjs/crypto is a scoped blockchain crypto utility with no resemblance to bcrypt in purpose or branding; the levenshtein match is a false positive stable across all versions. | ai |