@lightsparkdev/crypto-wasm
A shared library for crypto operations in Lightspark's SDKs.
13
Versions
—
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
jeremyatlightsparkcoreymartinmgorven.ls
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions publisher is intentional CI/CD automation, backed by SLSA provenance attestation. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): wasm-bindgen generated glue code; new Function() reconstructs wasm-exported JS functions, not user-controlled input. | ai | |
| bogus-package | bogus-package | AI (bogus-package): SDK sub-package from established Lightspark org; sparse README and no keywords are typical for auto-generated wasm packages. | ai | |
| phantom-deps | phantom-dep:@lightsparkdev/core | AI (phantom-deps): Same-org peer dependency; phantom-dep heuristic fires because it's not directly imported in wasm glue files. | ai |