@solana/keychain-vault
HashiCorp Vault signer for Solana transactions
12
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
solana-devs
Keywords
solanasigningwalletvaulthashicorp
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| npm-metadata | suspicious-initial-version | AI (npm-metadata): Solana-devs publishes 0.0.0 stubs to reserve namespaces; pattern is consistent across their approved packages. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Placeholder stub under official @solana scope; empty payload and missing metadata are intentional for namespace reservation. | ai | |
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): Localhost Vault address in test file; standard HashiCorp Vault integration test pattern, not a real network exfiltration risk. | ai |