@keplr-wallet/crypto
51
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
chainapsis
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | no-provenance | AI (provenance): Provenance attestation is not yet standard practice; absence is not a security signal for established publishers. | ai | |
| dependencies | unvetted-dep:elliptic | AI (dependencies): elliptic is a standard, widely-used ECC library; its use is expected and appropriate for a crypto wallet utility package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Established scoped package under @keplr-wallet with 1882 days history and 25k weekly downloads. Missing metadata fields are a hygiene issue, not a malice indicator. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Monorepo sub-package; missing description is a cosmetic issue with no security relevance for this established package. | ai | |
| provenance | publisher-changed | AI (provenance): Chainapsis migrated publishing to GitHub Actions CI/CD with SLSA provenance attestation. This is a legitimate and recommended practice for the official keplr-wallet monorepo. | ai | |
| typosquat | typosquat.levenshtein:bcrypt | AI (typosquat): @keplr-wallet/crypto is a scoped crypto utility for the Keplr wallet SDK, not a typosquat of bcrypt. The name similarity is coincidental and the package has a long legitimate history. | ai | |
| semgrep | semgrep:hex-decode | AI (semgrep): Hex decode usage in this package is exclusively in test vectors for cryptographic hash functions (hash.spec.ts). This is standard practice for crypto libraries and not a malicious payload indicator. | ai |
Versions (showing 51 of 370)
| Version | Deps | Published |
|---|---|---|
| 0.13.41 | 7 / 0 | |
| 0.13.40 | 7 / 0 | |
| 0.13.39 | 7 / 0 | |
| 0.13.38 | 7 / 0 | |
| 0.13.37 | 7 / 0 | |
| 0.13.36 | 7 / 0 | |
| 0.13.35 | 7 / 0 | |
| 0.13.34 | 7 / 0 | |
| 0.13.33 | 7 / 0 | |
| 0.13.32 | 7 / 0 | |
| 0.13.31 | 7 / 0 | |
| 0.13.30 | 7 / 0 | |
| 0.13.29 | 7 / 0 | |
| 0.13.28 | 7 / 0 | |
| 0.13.27 | 7 / 0 | |
| 0.13.26 | 7 / 0 | |
| 0.13.24 | 7 / 0 | |
| 0.13.23 | 7 / 0 | |
| 0.13.22 | 7 / 0 | |
| 0.13.21 | 7 / 0 | |
| 0.13.20 | 7 / 0 | |
| 0.13.19 | 7 / 0 | |
| 0.13.18 | 7 / 0 | |
| 0.13.17 | 7 / 0 | |
| 0.13.16 | 7 / 0 | |
| 0.13.15 | 7 / 0 | |
| 0.13.14 | 7 / 0 | |
| 0.13.13 | 7 / 0 | |
| 0.13.12 | 7 / 0 | |
| 0.13.11 | 7 / 0 | |
| 0.13.10 | 7 / 0 | |
| 0.13.9 | 7 / 0 | |
| 0.13.8 | 7 / 0 | |
| 0.13.7 | 7 / 0 | |
| 0.13.6 | 7 / 0 | |
| 0.13.5 | 7 / 0 | |
| 0.13.4 | 7 / 0 | |
| 0.13.3 | 7 / 0 | |
| 0.13.2 | 7 / 0 | |
| 0.13.1 | 7 / 0 | |
| 0.13.0 | 7 / 0 | |
| 0.12.313 | 7 / 0 | |
| 0.12.312 | 7 / 0 | |
| 0.12.311 | 7 / 0 | |
| 0.12.310 | 7 / 0 | |
| 0.12.309 | 7 / 0 | |
| 0.12.308 | 7 / 0 | |
| 0.12.307 | 7 / 0 | |
| 0.12.306 | 7 / 0 | |
| 0.12.305 | 7 / 0 | |
| 0.12.304 | 7 / 0 |
v0.13.41
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.40
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.