@trezor/blockchain-link
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): Trusted trezor-ci publisher; publish-env metadata change, not malicious. | ai | |
| dependencies | unvetted-dep:@everstake/wallet-sdk | AI (dependencies): Staking SDK addition consistent with package's blockchain-integration purpose; from trusted publisher. | ai | |
| source-diff | encoded-string-file:lib/workers/electrum/devrun.js | AI (source-diff): Test-fixture xpubs/tx hex in dev-run script; benign and recurring for this package. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Active Trezor monorepo package; publish gaps are normal for individual sub-packages. | ai | |
| semgrep | semgrep:hex-decode | AI (semgrep): Hex decode used to display OP_RETURN data as ASCII string — no code execution, stable pattern for this blockchain library. | ai | |
| phantom-deps | phantom-dep:@solana/rpc-types | AI (phantom-deps): Referenced in config files as part of Solana ecosystem; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:crypto-browserify | AI (phantom-deps): Browser polyfill referenced in webpack config; not directly imported but legitimately used as a build-time alias. | ai | |
| phantom-deps | phantom-dep:stream-browserify | AI (phantom-deps): Browser polyfill referenced in webpack config; same pattern as crypto-browserify. | ai | |
| phantom-deps | phantom-dep:@types/web | AI (phantom-deps): Type-only package loaded by convention; no runtime import needed. | ai |
Versions (showing 53 of 53)
| Version | Deps | Published |
|---|---|---|
| 2.6.2 | 18 / 9 | |
| 2.6.1 | 18 / 9 | |
| 2.6.0 | 18 / 9 | |
| 2.5.4 | 18 / 9 | |
| 2.5.3 | 17 / 10 | |
| 2.5.2 | 16 / 10 | |
| 2.5.1 | 16 / 10 | |
| 2.5.0 | 16 / 11 | |
| 2.4.5 | 14 / 11 | |
| 2.4.4 | 14 / 11 | |
| 2.4.3 | 14 / 11 | |
| 2.4.2 | 14 / 11 | |
| 2.4.1 | 14 / 11 | |
| 2.4.0 | 14 / 11 | |
| 2.3.6 | 12 / 11 | |
| 2.3.5 | 12 / 11 | |
| 2.3.4 | 12 / 11 | |
| 2.3.3 | 12 / 11 | |
| 2.3.2 | 12 / 10 | |
| 2.3.1 | 11 / 10 | |
| 2.3.0 | 11 / 10 | |
| 2.2.0 | 11 / 10 | |
| 2.1.30 | 11 / 10 | |
| 2.1.29 | 12 / 10 | |
| 2.1.28 | 12 / 10 | |
| 2.1.27 | 12 / 10 | |
| 2.1.26 | 12 / 10 | |
| 2.1.25 | 12 / 13 | |
| 2.1.23 | 12 / 13 | |
| 2.1.22 | 12 / 13 | |
| 2.1.21 | 12 / 13 | |
| 2.1.20 | 12 / 13 | |
| 2.1.19 | 12 / 13 | |
| 2.1.18 | 10 / 13 | |
| 2.1.17 | 10 / 13 | |
| 2.1.16 | 10 / 13 | |
| 2.1.15 | 10 / 13 | |
| 2.1.14 | 10 / 13 | |
| 2.1.13 | 10 / 11 | |
| 2.1.12 | 10 / 11 | |
| 2.1.11 | 10 / 10 | |
| 2.1.10 | 10 / 10 | |
| 2.1.9 | 10 / 10 | |
| 2.1.8 | 8 / 10 | |
| 2.1.7 | 8 / 11 | |
| 2.1.6 | 8 / 11 | |
| 2.1.5 | 8 / 11 | |
| 2.1.4 | 8 / 11 | |
| 2.1.3 | 8 / 7 | |
| 2.1.2 | 8 / 7 | |
| 2.1.1 | 7 / 7 | |
| 2.1.0 | 7 / 7 | |
| 2.0.0 | 4 / 7 |
v2.4.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.4.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.4.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.4.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.4.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.2
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.30
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.29
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.28
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.27
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.26
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.25
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.23
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.22
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.21
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.20
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.19
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.18
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: trezor-ci.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.17
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: trezor-ci.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.16
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: trezor-ci.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.15
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: trezor-ci.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.14
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: trezor-ci.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.13
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: trezor-ci.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.12
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: trezor-ci.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.11
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: trezor-ci.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.10
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: trezor-ci.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.9
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: trezor-ci.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.8
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: trezor-ci.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.7
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: trezor-ci.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.6
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: trezor-ci.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.4
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (trezor-ci) than the most recent previously approved version (martin_varmuza) on 2022-09-12, but trezor-ci is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.1.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (martin_varmuza) than the most recent previously approved version (trezor-ci) on 2022-03-29, but martin_varmuza is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.1.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.