← Home

@railgun-community/wallet

6
Versions
License
Yes
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

mesqukaconcertina_dev

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
maintainer-change maintainer-removed AI (maintainer-change): Part of same legitimate CI/CD migration. ai
maintainer-change maintainer-added AI (maintainer-change): Publisher has established 8-package approved track record; org-level transition. ai
source-diff encoded-string-file:dist/tests/mocks.test.js AI (source-diff): Crypto test fixtures/mock ciphertext, not a hidden payload. ai
npm-metadata url-dep:ethers AI (npm-metadata): Railgun-Community/ethers.js is the project's own pinned fork at a specific tag; intentional and stable for this package. ai
install-scripts install-script:postinstall AI (install-scripts): Runs a local postinstall.js bundled with the package; consistent with cross-platform SDK setup across all versions. ai
phantom-deps phantom-dep:stream-browserify AI (phantom-deps): Browser polyfill declared as dep for bundler config; stable false positive for this cross-platform SDK. ai
phantom-deps phantom-dep:events AI (phantom-deps): Browser polyfill declared as dep for bundler config; stable false positive for this cross-platform SDK. ai
phantom-deps phantom-dep:assert AI (phantom-deps): Browser polyfill declared as dep for bundler config; stable false positive for this cross-platform SDK. ai

Versions (showing 6 of 6)

Version Deps Published
10.8.6 24 / 25
10.8.5 24 / 25
10.8.4 24 / 25
10.8.3 24 / 25
10.8.1 24 / 25
8.1.0 24 / 25

v10.8.4

3 findings
HIGH Long encoded string in modified file: dist/tests/mocks.test.js source-diff

Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: ptsimpso → GitHub Actions (on 2026-03-04, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ptsimpso) on 2026-03-04, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v10.8.3

3 findings
HIGH Long encoded string in modified file: dist/tests/mocks.test.js source-diff

Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: ptsimpso → GitHub Actions (on 2026-02-09, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ptsimpso) on 2026-02-09, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v10.8.1

3 findings
HIGH Publisher changed: ptsimpso → concertina_dev (on 2025-12-02) provenance

This version was published by a different npm account than previous versions on 2025-12-02. This could indicate a legitimate maintainer transition or an account compromise.

HIGH Long encoded string in modified file: dist/tests/mocks.test.js source-diff

Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.