@ledgerhq/coin-celo
celo coin integration
31
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
No source commit
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
phenry-ledgersergii-shkolingbrahm-ledgerthomas.coudrayldg-github-civbouzonledger-releaser
Keywords
LedgerLedgerWalletCeloHardware Wallet
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@ledgerhq/coin-framework | AI (dependencies): @ledgerhq/coin-framework is LedgerHQ's own coin framework package from the same organization, expected dependency. | ai | |
| dependencies | unvetted-dep:@celo/utils | AI (dependencies): @celo/utils is the official Celo blockchain SDK utility package, expected dependency for a Celo coin integration module. | ai | |
| dependencies | unvetted-dep:@celo/connect | AI (dependencies): @celo/connect is the official Celo blockchain connection package, expected dependency for a Celo coin integration module. | ai | |
| dependencies | unvetted-dep:@celo/contractkit | AI (dependencies): @celo/contractkit is the official Celo smart contract toolkit, expected dependency for a Celo coin integration module. | ai | |
| dependencies | unvetted-dep:@celo/wallet-base | AI (dependencies): @celo/wallet-base is the official Celo wallet base package, expected dependency for a Celo coin integration module. | ai | |
| dependencies | unvetted-dep:@celo/wallet-ledger | AI (dependencies): @celo/wallet-ledger is the official Celo Ledger wallet integration package, expected dependency for this module. | ai | |
| provenance | no-provenance | AI (provenance): LedgerHQ publishes via CI bot; lack of Sigstore provenance is common and not a security risk given the established package history and official GitHub repo. | ai | |
| semgrep | semgrep:hex-decode | AI (semgrep): Hex decoding of ECDSA signature r/s components from hardware wallet responses is standard cryptographic practice for a coin integration library; not a malicious payload indicator. | ai | |
| phantom-deps | phantom-dep:lodash | AI (phantom-deps): lodash is a declared runtime dependency used via config/build tooling; phantom-dep finding is a false positive for this package. | ai | |
| phantom-deps | phantom-dep:invariant | AI (phantom-deps): invariant is a declared runtime dependency; phantom-dep finding reflects config-only reference pattern, not a security issue. | ai | |
| phantom-deps | phantom-dep:@ledgerhq/devices | AI (phantom-deps): Same-org package used as a type/peer dependency; phantom-dep finding is expected for this monorepo package structure. | ai | |
| phantom-deps | phantom-dep:@celo/wallet-ledger | AI (phantom-deps): Celo wallet-ledger is a declared runtime dependency; phantom-dep finding reflects config-only reference, not a security issue. | ai |
Versions (showing 31 of 31)
| Version | Deps | Published |
|---|---|---|
| 2.9.0 | 21 / 16 | |
| 2.8.0 | 21 / 16 | |
| 2.7.0 | 20 / 15 | |
| 2.6.0 | 20 / 15 | |
| 2.5.0 | 19 / 15 | |
| 2.4.1 | 19 / 15 | |
| 2.4.0 | 19 / 15 | |
| 2.3.0 | 19 / 15 | |
| 2.2.0 | 22 / 16 | |
| 2.1.1 | 22 / 16 | |
| 2.1.0 | 22 / 16 | |
| 2.0.0 | 22 / 15 | |
| 1.17.0 | 22 / 15 | |
| 1.16.0 | 22 / 13 | |
| 1.15.0 | 22 / 13 | |
| 1.14.0 | 21 / 13 | |
| 1.13.0 | 21 / 13 | |
| 1.12.0 | 21 / 12 | |
| 1.11.0 | 21 / 12 | |
| 1.10.0 | 21 / 12 | |
| 1.9.3 | 21 / 12 | |
| 1.9.2 | 21 / 12 | |
| 1.9.1 | 21 / 12 | |
| 1.9.0 | 21 / 12 | |
| 1.8.2 | 21 / 11 | |
| 1.8.1 | 21 / 11 | |
| 1.8.0 | 21 / 11 | |
| 1.7.3 | 21 / 11 | |
| 1.7.2 | 21 / 11 | |
| 1.7.1 | 21 / 11 | |
| 1.7.0 | 21 / 11 |
v2.9.0
1 finding
INFO
No provenance attestation
provenance
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.8.0
1 finding
INFO
No provenance attestation
provenance
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.7.0
1 finding
INFO
No provenance attestation
provenance
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.