@swapkit/wallet-keystore
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:hex-decode | AI (semgrep): Hex decode is used to prepare input for blake2b hashing — standard crypto pattern in a keystore wallet, not obfuscation. | ai | |
| provenance | no-provenance | AI (provenance): GitHub Actions CI publisher; consistent across all SwapKit monorepo releases. | ai |
Versions (showing 51 of 104)
| Version | Deps | Published |
|---|---|---|
| 4.5.5 | 3 / 0 | |
| 4.5.4 | 3 / 0 | |
| 4.5.3 | 3 / 0 | |
| 4.5.2 | 3 / 0 | |
| 4.5.1 | 3 / 0 | |
| 4.5.0 | 3 / 0 | |
| 4.4.17 | 3 / 0 | |
| 4.4.15 | 3 / 0 | |
| 4.4.14 | 3 / 0 | |
| 4.4.13 | 3 / 0 | |
| 4.4.12 | 3 / 0 | |
| 4.4.11 | 3 / 0 | |
| 4.4.10 | 3 / 0 | |
| 4.4.9 | 3 / 0 | |
| 4.4.8 | 3 / 0 | |
| 4.4.7 | 3 / 0 | |
| 4.4.6 | 3 / 0 | |
| 4.4.5 | 3 / 0 | |
| 4.4.4 | 3 / 0 | |
| 4.4.3 | 3 / 0 | |
| 4.4.2 | 3 / 0 | |
| 4.4.1 | 3 / 0 | |
| 4.4.0 | 3 / 0 | |
| 4.3.37 | 3 / 0 | |
| 4.3.36 | 3 / 0 | |
| 4.3.35 | 3 / 0 | |
| 4.3.34 | 3 / 0 | |
| 4.3.33 | 3 / 0 | |
| 4.3.32 | 3 / 0 | |
| 4.3.31 | 3 / 0 | |
| 4.3.30 | 3 / 0 | |
| 4.3.29 | 5 / 0 | |
| 4.3.28 | 5 / 0 | |
| 4.3.27 | 5 / 0 | |
| 4.3.26 | 5 / 0 | |
| 4.3.25 | 5 / 0 | |
| 4.3.24 | 5 / 0 | |
| 4.3.23 | 5 / 0 | |
| 4.3.22 | 5 / 0 | |
| 4.3.21 | 5 / 0 | |
| 4.3.20 | 5 / 0 | |
| 4.3.19 | 5 / 0 | |
| 4.3.18 | 5 / 0 | |
| 4.3.17 | 5 / 0 | |
| 4.3.16 | 5 / 0 | |
| 4.3.15 | 5 / 0 | |
| 4.3.14 | 5 / 0 | |
| 4.3.13 | 5 / 0 | |
| 4.3.12 | 5 / 0 | |
| 4.3.11 | 5 / 0 | |
| 4.3.10 | 5 / 0 |
v4.5.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.5.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.5.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.5.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.5.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.5.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.4.17
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.4.15
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.4.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.4.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.4.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.4.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.4.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.4.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.