@solana/keychain
Unified Solana transaction signing across multiple backends
10
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
solana-devs
Keywords
solanasigningwalletprivyvaultturnkeyawskmsfireblockscdpcoinbaseparadfnscrossmintopenfortutila
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): SLSA provenance attestation present; missing gitHead is a minor metadata gap, not a supply chain risk for this package. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size increase reflects addition of 6 new first-party @solana/keychain-* sub-package dependencies in a major version bump. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): All new deps are first-party @solana/keychain-* packages matching the package's documented aggregator purpose. | ai |