← Home

@ledgerhq/coin-polkadot

Ledger Polkadot Coin integration

47
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

phenry-ledgersergii-shkolingbrahm-ledgerthomas.coudrayldg-github-civbouzonledger-releaser

Keywords

LedgerLedgerWalletdotPolkadotHardware Wallet

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@ledgerhq/coin-framework AI (dependencies): Sibling LedgerHQ package from the same monorepo; unvetted status is a pipeline artifact, not a security concern for this well-established org. ai
dependencies unvetted-dep:@ledgerhq/devices AI (dependencies): Internal @ledgerhq sibling package from the same monorepo; expected dependency for this coin integration module. ai
dependencies unvetted-dep:@ledgerhq/cryptoassets AI (dependencies): Internal @ledgerhq sibling package from the same monorepo; expected dependency for this coin integration module. ai
dependencies unvetted-dep:@ledgerhq/live-network AI (dependencies): Internal @ledgerhq sibling package from the same monorepo; expected dependency for this coin integration module. ai
dependencies unvetted-dep:@ledgerhq/types-cryptoassets AI (dependencies): Internal @ledgerhq sibling package from the same monorepo; expected dependency for this coin integration module. ai
dependencies unvetted-dep:@ledgerhq/coin-module-framework AI (dependencies): Internal @ledgerhq sibling package from the same monorepo; expected dependency for this coin integration module. ai
dependencies unvetted-dep:@ledgerhq/ledger-wallet-framework AI (dependencies): Internal @ledgerhq sibling package from the same monorepo; expected dependency for this coin integration module. ai
dependencies unvetted-dep:@ledgerhq/logs AI (dependencies): Internal @ledgerhq sibling package from the same monorepo; expected dependency for this coin integration module. ai
dependencies unvetted-dep:@ledgerhq/errors AI (dependencies): Internal @ledgerhq sibling package from the same monorepo; expected dependency for this coin integration module. ai
dependencies unvetted-dep:@ledgerhq/types-live AI (dependencies): Internal @ledgerhq sibling package from the same monorepo; expected dependency for this coin integration module. ai
phantom-deps phantom-dep:lodash AI (phantom-deps): lodash is referenced in config files only, not directly imported at runtime. Safe for this package. ai
phantom-deps phantom-dep:@ledgerhq/devices AI (phantom-deps): Same org scope package; phantom dep finding is expected in a monorepo context where transitive usage may occur. ai
phantom-deps phantom-dep:@polkadot/api-derive AI (phantom-deps): Referenced in config files only; @polkadot/api-derive is a known Polkadot ecosystem package used transitively. ai
semgrep semgrep:hex-decode AI (semgrep): Hex decoding in signTransaction.js is standard cryptographic practice for converting hardware wallet signatures to bytes for Polkadot extrinsics. Not a malicious payload indicator. ai
phantom-deps phantom-dep:expect AI (phantom-deps): expect is a test dependency referenced in jest config files, not a runtime import. Safe for this package. ai

Versions (showing 47 of 47)

Version Deps Published
6.27.2 21 / 17
6.27.1 21 / 17
6.27.0 21 / 17
6.26.0 21 / 17
6.25.0 21 / 18
6.24.1 21 / 18
6.24.0 21 / 18
6.23.0 21 / 18
6.22.0 21 / 18
6.21.1 21 / 17
6.21.0 21 / 17
6.20.0 20 / 17
6.19.0 20 / 17
6.18.0 20 / 16
6.17.1 20 / 15
6.17.0 20 / 15
6.16.3 20 / 15
6.16.2 20 / 15
6.16.1 20 / 15
6.16.0 20 / 15
6.15.0 20 / 14
6.14.1 20 / 14
6.14.0 20 / 14
6.13.2 20 / 14
6.13.1 20 / 14
6.13.0 20 / 14
6.12.0 20 / 14
6.11.0 20 / 14
6.10.2 21 / 14
6.10.1 21 / 14
6.10.0 21 / 14
6.9.0 21 / 14
6.8.0 21 / 14
6.7.0 21 / 14
6.6.0 21 / 14
6.5.0 21 / 14
6.4.0 21 / 14
6.3.1 21 / 16
6.3.0 21 / 16
6.2.2 21 / 16
6.2.1 21 / 16
6.2.0 21 / 16
6.1.2 21 / 17
6.1.1 21 / 17
6.1.0 21 / 17
6.0.1 21 / 17
6.0.0 21 / 16

v6.27.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.27.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.27.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.26.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.25.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.24.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.24.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.23.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v6.22.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v6.21.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v6.21.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v6.11.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.10.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.10.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.10.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.9.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.8.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.3.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.2.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.2.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v6.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v6.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v6.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v6.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v6.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.