@ledgerhq/hw-app-polkadot
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | dormant-publish | AI (publish-pattern): LedgerHQ monorepo package; long dormancy between Polkadot-specific releases is expected. Published by the same trusted CI account with no other risk signals. | ai | |
| semgrep | semgrep:hex-decode | AI (semgrep): Buffer.from() calls in a hardware wallet signing API are standard binary data handling, not payload obfuscation. This is a stable false positive for this package. | ai | |
| dependencies | unvetted-dep:@zondax/ledger-substrate | AI (dependencies): Zondax is the official maintainer of Ledger apps for Substrate/Polkadot chains; this dependency is expected and legitimate for this hardware wallet library. | ai |
Versions (showing 21 of 21)
| Version | Deps | Published |
|---|---|---|
| 6.38.4 | 4 / 10 | |
| 6.38.3 | 4 / 10 | |
| 6.38.2 | 4 / 10 | |
| 6.38.1 | 4 / 10 | |
| 6.38.0 | 4 / 10 | |
| 6.37.1 | 4 / 10 | |
| 6.37.0 | 4 / 10 | |
| 6.36.0 | 4 / 10 | |
| 6.35.0 | 4 / 10 | |
| 6.34.12 | 4 / 9 | |
| 6.34.11 | 4 / 9 | |
| 6.34.10 | 4 / 9 | |
| 6.34.9 | 4 / 9 | |
| 6.34.8 | 4 / 9 | |
| 6.34.7 | 4 / 9 | |
| 6.34.6 | 4 / 9 | |
| 6.34.5 | 4 / 9 | |
| 6.34.4 | 4 / 9 | |
| 6.34.3 | 4 / 9 | |
| 6.34.2 | 4 / 10 | |
| 6.34.1 | 4 / 10 |
v6.38.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.38.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.38.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.38.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.38.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.37.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.37.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.36.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.34.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.34.11
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.34.10
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.34.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.34.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.34.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.34.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.34.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.34.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.34.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.34.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.34.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.