@lit-protocol/ecdsa-sdk
Read more about it here:
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-added | AI (maintainer-change): Known org maintainer roster churn, no behavioral change in diff. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Removal alone with unchanged code/publisher trust is benign. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Monorepo package with synced version bumps; no behavioral change accompanies it. | ai | |
| phantom-deps | phantom-dep:util | AI (phantom-deps): util is a legit polyfill dep referenced via config, stable false positive. | ai |
Versions (showing 44 of 44)
| Version | Deps | Published |
|---|---|---|
| 6.11.5 | 2 / 0 | |
| 6.11.4 | 2 / 0 | |
| 6.11.3 | 2 / 0 | |
| 6.11.2 | 2 / 0 | |
| 6.11.1 | 2 / 0 | |
| 6.11.0 | 2 / 0 | |
| 6.10.0 | 2 / 0 | |
| 6.9.0 | 2 / 0 | |
| 6.8.1 | 2 / 0 | |
| 6.8.0 | 2 / 0 | |
| 6.7.1 | 2 / 0 | |
| 6.7.0 | 2 / 0 | |
| 6.6.1 | 2 / 0 | |
| 6.6.0 | 2 / 0 | |
| 6.5.3 | 2 / 0 | |
| 6.5.2 | 2 / 0 | |
| 6.5.1 | 2 / 0 | |
| 6.5.0 | 2 / 0 | |
| 6.4.10 | 2 / 0 | |
| 6.4.9 | 2 / 0 | |
| 6.4.8 | 2 / 0 | |
| 6.4.7 | 2 / 0 | |
| 6.4.6 | 2 / 0 | |
| 6.4.5 | 2 / 0 | |
| 6.4.4 | 2 / 0 | |
| 6.4.3 | 2 / 0 | |
| 6.4.2 | 2 / 0 | |
| 6.4.1 | 2 / 0 | |
| 6.4.0 | 2 / 0 | |
| 6.3.0 | 2 / 0 | |
| 6.2.4 | 2 / 0 | |
| 6.2.3 | 2 / 0 | |
| 6.2.2 | 2 / 0 | |
| 6.2.1 | 2 / 0 | |
| 6.2.0 | 2 / 0 | |
| 6.1.1 | 2 / 0 | |
| 6.1.0 | 2 / 0 | |
| 6.0.5 | 2 / 0 | |
| 6.0.4 | 2 / 0 | |
| 6.0.3 | 2 / 0 | |
| 6.0.2 | 2 / 0 | |
| 6.0.1 | 2 / 0 | |
| 6.0.0 | 2 / 0 | |
| 5.1.0 | 2 / 0 |
v6.11.4
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (famura) than the most recent previously approved version (websaam) on 2024-12-23, but famura is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.11.3
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (famura) than the most recent previously approved version (websaam) on 2024-12-09, but famura is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.11.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.11.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (glitch003) than the most recent previously approved version (websaam) on 2024-11-15, but glitch003 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.11.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (websaam) than the most recent previously approved version (maximushaximus) on 2024-10-18, but websaam is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.10.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.9.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (maximushaximus) than the most recent previously approved version (websaam) on 2024-10-10, but maximushaximus is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.8.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.8.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.7.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.7.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.6.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.6.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (websaam) than the most recent previously approved version (josh-long) on 2024-09-23, but websaam is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.5.3
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (websaam) than the most recent previously approved version (josh-long) on 2024-09-19, but websaam is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.5.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (josh-long) than the most recent previously approved version (websaam) on 2024-09-19, but josh-long is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.5.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.5.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.4.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.4.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.4.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.4.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.4.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.4.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.4.4
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (glitch003) than the most recent previously approved version (websaam) on 2024-08-14, but glitch003 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.4.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.4.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.4.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.4.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.3.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.2.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.2.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.2.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (adarsh-kumar28) than the most recent previously approved version (websaam) on 2024-07-22, but adarsh-kumar28 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.2.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.2.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.1.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (websaam) than the most recent previously approved version (glitch003) on 2024-07-12, but websaam is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.1.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (maximushaximus) than the most recent previously approved version (glitch003) on 2024-07-08, but maximushaximus is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.0.5
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (glitch003) than the most recent previously approved version (josh-long) on 2024-07-02, but glitch003 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.0.4
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (glitch003) than the most recent previously approved version (josh-long) on 2024-07-02, but glitch003 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.0.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.0.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.0.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.0.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (josh-long) than the most recent previously approved version (websaam) on 2024-06-03, but josh-long is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.