@ledgerhq/coin-xrp
40
Versions
—
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
No source commit
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
phenry-ledgersergii-shkolingbrahm-ledgerthomas.coudrayldg-github-civbouzonledger-releaser
Keywords
LedgerLedgerWalletxrpRippleHardware Wallet
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): ledger-releaser is Ledger's established release account with 192 approved packages; transition from ldg-github-ci is a known CI account migration. | ai | |
| source-diff | encoded-string-file:lib-es/api/index.integ.test.js | AI (source-diff): XRP transaction hex in test assertions; stable false positive for this package. | ai | |
| source-diff | encoded-string-file:lib/api/index.integ.test.js | AI (source-diff): XRP transaction hex in test assertions; stable false positive for this package. | ai | |
| source-diff | encoded-string-file:src/api/index.integ.test.ts | AI (source-diff): Long hex strings in this file are XRP transaction bytes used as expected values in integration tests — a standard pattern for blockchain library testing, not obfuscation. | ai | |
| phantom-deps | phantom-dep:@ledgerhq/devices | AI (phantom-deps): @ledgerhq/devices is a same-org dependency declared in package.json; phantom-dep false positive for this package. | ai | |
| provenance | no-provenance | AI (provenance): Established @ledgerhq scoped package with 495 versions; lack of Sigstore provenance is consistent with their release pipeline and not a meaningful risk signal. | ai |
Versions (showing 40 of 40)
| Version | Deps | Published |
|---|---|---|
| 7.25.2 | 5 / 10 | |
| 7.25.0 | 5 / 11 | |
| 7.24.0 | 5 / 11 | |
| 7.23.5 | 5 / 11 | |
| 7.23.4 | 5 / 11 | |
| 7.23.3 | 5 / 11 | |
| 7.22.0 | 9 / 14 | |
| 7.21.7 | 5 / 11 | |
| 7.21.6 | 5 / 11 | |
| 7.21.5 | 5 / 12 | |
| 7.21.4 | 5 / 12 | |
| 7.21.3 | 5 / 12 | |
| 7.21.2 | 5 / 12 | |
| 7.21.1 | 5 / 12 | |
| 7.21.0 | 9 / 12 | |
| 7.20.0 | 9 / 12 | |
| 7.19.0 | 11 / 12 | |
| 7.18.0 | 11 / 13 | |
| 7.17.0 | 11 / 12 | |
| 7.16.0 | 11 / 12 | |
| 7.15.0 | 11 / 12 | |
| 7.14.0 | 11 / 12 | |
| 7.13.1 | 11 / 12 | |
| 7.13.0 | 11 / 12 | |
| 7.12.0 | 11 / 12 | |
| 7.11.0 | 11 / 11 | |
| 7.10.1 | 11 / 11 | |
| 7.10.0 | 11 / 11 | |
| 7.9.1 | 11 / 11 | |
| 7.9.0 | 11 / 11 | |
| 7.8.0 | 11 / 11 | |
| 7.7.0 | 11 / 11 | |
| 7.6.0 | 11 / 11 | |
| 7.5.1 | 11 / 11 | |
| 7.5.0 | 11 / 11 | |
| 7.4.0 | 11 / 11 | |
| 7.3.0 | 11 / 11 | |
| 7.2.0 | 11 / 11 | |
| 7.1.0 | 11 / 11 | |
| 7.0.0 | 11 / 11 |
v7.25.2
1 finding
INFO
No provenance attestation
provenance
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.25.0
1 finding
INFO
No provenance attestation
provenance
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.24.0
1 finding
INFO
No provenance attestation
provenance
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.