← Home

@ledgerhq/hw-app-exchange

55
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

phenry-ledgersergii-shkolingbrahm-ledgerthomas.coudrayldg-github-civbouzonledger-releaser

Keywords

LedgerLedgerWalletNanoSBlueHardware Wallet

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff encoded-string-file:lib/SwapUtils.test.js AI (source-diff): Same test fixture data, compiled output. ai
source-diff encoded-string-file:lib-es/SwapUtils.test.js AI (source-diff): Test fixture hex/base64 payloads for protobuf decode tests, not hidden malware. ai
maintainer-change maintainer-added AI (maintainer-change): Org-wide CI publisher migration across LedgerHQ packages, trusted publisher track record. ai
provenance publisher-changed-stale AI (provenance): Stale for 924d with no unpublish; consistent with legitimate CI switch, not takeover. ai
maintainer-change maintainer-removed AI (maintainer-change): Same CI migration; removed maintainers replaced by automated publishing account. ai
source-diff encoded-string-file:src/SellUtils.test.ts AI (source-diff): Source TypeScript test file with protobuf hex payload; benign. ai
source-diff encoded-string-file:lib-es/SellUtils.test.js AI (source-diff): Hex-encoded protobuf payload used in unit tests for decodeSellPayload; benign. ai
source-diff encoded-string-file:lib/SellUtils.test.js AI (source-diff): Same protobuf test payload as lib-es counterpart; benign for this package. ai
source-diff encoded-string-file:lib-es/Exchange.integ.test.js AI (source-diff): Hex-encoded test vectors for SELL payload signature verification; not a malicious payload. ai
source-diff encoded-string-file:lib/Exchange.integ.test.js AI (source-diff): Hex-encoded test vectors for SELL payload signature verification; not a malicious payload. ai
source-diff encoded-string-file:src/Exchange.integ.test.ts AI (source-diff): Hex-encoded test vectors for SELL payload signature verification; not a malicious payload. ai
publish-pattern dormant-publish AI (publish-pattern): Established LedgerHQ org package; dormancy likely reflects release cadence, not takeover. No suspicious changes in diff. ai
dependencies unvetted-dep:protobufjs AI (dependencies): protobufjs is a legitimate, widely-used protobuf library. Its use is clearly justified by the package's protocol buffer compilation and deserialization needs for Ledger exchange protocol. ai
dependencies unvetted-dep:protobufjs-cli AI (dependencies): protobufjs-cli is used in the prebuild script to compile .proto files; legitimate build tooling for this Ledger hardware wallet library. ai
semgrep semgrep:base64-decode AI (semgrep): Base64 decoding is used to parse protobuf-encoded transaction payloads from Ledger's exchange protocol. Legitimate and expected for this package. ai
phantom-deps phantom-dep:protobufjs-cli AI (phantom-deps): protobufjs-cli is a build-time CLI tool used in the prebuild script (pnpm pbjs). Not imported at runtime; phantom-dep finding is expected and benign. ai
semgrep semgrep:hex-decode AI (semgrep): Hex decoding is used for legitimate APDU command construction in a hardware wallet library. Not obfuscation or malicious payload hiding. ai

Versions (showing 55 of 55)

Version Deps Published
0.23.1 7 / 11
0.23.0 7 / 11
0.22.4 7 / 11
0.22.3 7 / 11
0.22.2 7 / 11
0.22.1 7 / 11
0.22.0 7 / 11
0.21.1 7 / 11
0.21.0 7 / 11
0.20.0 7 / 11
0.19.0 7 / 11
0.18.3 7 / 10
0.18.2 7 / 10
0.18.1 7 / 10
0.18.0 7 / 10
0.17.0 7 / 10
0.16.0 7 / 10
0.15.0 7 / 10
0.14.0 7 / 10
0.13.2 7 / 10
0.13.1 7 / 10
0.13.0 7 / 10
0.12.0 7 / 10
0.11.0 7 / 10
0.10.4 7 / 10
0.10.3 7 / 10
0.10.2 7 / 11
0.10.1 6 / 11
0.10.0 6 / 11
0.9.0 6 / 11
0.8.0 6 / 10
0.7.0 6 / 10
0.6.2 6 / 10
0.6.1 6 / 9
0.6.0 6 / 9
0.5.2 6 / 9
0.5.1 6 / 9
0.5.0 6 / 9
0.4.7 6 / 9
0.4.6 4 / 10
0.4.5 4 / 10
0.4.4 4 / 10
0.4.3 4 / 10
0.4.2 4 / 10
0.4.1 4 / 10
0.4.0 4 / 10
0.3.0 4 / 10
0.2.3 4 / 7
0.2.2 4 / 7
0.2.1 4 / 7
0.2.0 4 / 7
0.1.3 4 / 7
0.1.2 4 / 7
0.1.1 4 / 7
0.1.0 4 / 8

v0.23.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.23.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.0

3 findings
HIGH Long encoded string in modified file: lib-es/SwapUtils.test.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: lib/SwapUtils.test.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.0

3 findings
HIGH Long encoded string in modified file: lib-es/SwapUtils.test.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: lib/SwapUtils.test.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.8.0

3 findings
HIGH Long encoded string in modified file: lib-es/SwapUtils.test.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: lib/SwapUtils.test.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.4.7

2 findings
MEDIUM Publisher changed: sergii-shkolin → ldg-github-ci (on 2024-04-18, unremoved on npm for 824d) provenance

This version was published by a different npm account (ldg-github-ci) than the most recent previously approved version (sergii-shkolin) on 2024-04-18. It has since remained available on npm for 824 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.6

2 findings
MEDIUM Publisher changed: sergii-shkolin → ldg-github-ci (on 2024-03-19, unremoved on npm for 854d) provenance

This version was published by a different npm account (ldg-github-ci) than the most recent previously approved version (sergii-shkolin) on 2024-03-19. It has since remained available on npm for 854 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.5

2 findings
MEDIUM Publisher changed: sergii-shkolin → ldg-github-ci (on 2024-02-19, unremoved on npm for 882d) provenance

This version was published by a different npm account (ldg-github-ci) than the most recent previously approved version (sergii-shkolin) on 2024-02-19. It has since remained available on npm for 882 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.4

2 findings
MEDIUM Publisher changed: sergii-shkolin → ldg-github-ci (on 2024-01-31, unremoved on npm for 902d) provenance

This version was published by a different npm account (ldg-github-ci) than the most recent previously approved version (sergii-shkolin) on 2024-01-31. It has since remained available on npm for 902 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.3

2 findings
MEDIUM Publisher changed: sergii-shkolin → ldg-github-ci (on 2024-01-23, unremoved on npm for 910d) provenance

This version was published by a different npm account (ldg-github-ci) than the most recent previously approved version (sergii-shkolin) on 2024-01-23. It has since remained available on npm for 910 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.2

2 findings
MEDIUM Publisher changed: sergii-shkolin → ldg-github-ci (on 2024-01-09, unremoved on npm for 924d) provenance

This version was published by a different npm account (ldg-github-ci) than the most recent previously approved version (sergii-shkolin) on 2024-01-09. It has since remained available on npm for 924 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.