@wireio/sdk-core
Library for working with Wire powered blockchains.
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:lib/esm/common/ZlibCompression.js | AI (source-diff): Same file, ESM build; readable pako wrapper, not obfuscated. | ai | |
| source-diff | obfuscated-file:lib/cjs/common/ZlibCompression.js | AI (source-diff): Readable code, long lines only; no true obfuscation signature. | ai | |
| source-diff | obfuscated-file:lib/cjs/chain/PackedTransactionCompression.js | AI (source-diff): Readable compiled zlib-decompression utility, not obfuscated code. | ai | |
| source-diff | obfuscated-file:lib/esm/chain/PackedTransactionCompression.js | AI (source-diff): Same source as ESM build output, clean and readable. | ai | |
| source-diff | obfuscated-file:lib/esm/SlugName.js | AI (source-diff): Same file as CJS counterpart; documented, non-obfuscated. | ai | |
| source-diff | obfuscated-file:lib/esm/types/SysioContractTypes.js | AI (source-diff): Auto-generated contract type enums, large but not obfuscated. | ai | |
| source-diff | obfuscated-file:lib/cjs/types/SysioContractTypes.js | AI (source-diff): Auto-generated contract type enums, large but not obfuscated. | ai | |
| source-diff | obfuscated-file:lib/cjs/SlugName.js | AI (source-diff): Long lines are documented codec logic, not obfuscation; no malicious behavior. | ai | |
| source-diff | obfuscated-file:lib/cjs/contracts/sysio/msig/Actions.js | AI (source-diff): Compiled TS output with long export lines, not true obfuscation; matches package's contract SDK purpose. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Generated contract type/client code for new sysio.msig support, consistent with stated function. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): Well-known ethersproject packages replacing single ethers dep, not unvetted. | ai | |
| dependencies | unvetted-dep:elliptic | AI (dependencies): elliptic is a standard crypto dependency for blockchain SDKs; expected and not known-vulnerable at ^6.5.4. | ai | |
| phantom-deps | phantom-dep:pako | AI (phantom-deps): Standard compression lib; consistent with blockchain SDK use; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:tweetnacl | AI (phantom-deps): Standard crypto lib; consistent with blockchain SDK purpose. | ai | |
| phantom-deps | phantom-dep:elliptic | AI (phantom-deps): Standard elliptic curve crypto lib; expected in blockchain SDK. | ai | |
| phantom-deps | phantom-dep:hash.js | AI (phantom-deps): Crypto hashing lib; consistent with blockchain SDK; phantom-dep false positive. | ai | |
| phantom-deps | phantom-dep:bn.js | AI (phantom-deps): Standard big-number lib for crypto; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:js-big-decimal | AI (phantom-deps): Decimal arithmetic lib; consistent with blockchain SDK use. | ai | |
| phantom-deps | phantom-dep:brorand | AI (phantom-deps): Crypto RNG lib; expected transitive dep for elliptic; phantom-dep false positive. | ai | |
| phantom-deps | phantom-dep:ethers | AI (phantom-deps): Core blockchain lib; consistent with Wire blockchain SDK purpose. | ai | |
| phantom-deps | phantom-dep:tslib | AI (phantom-deps): tslib is a known implicit TypeScript runtime dep; stable false positive for compiled TS packages. | ai | |
| phantom-deps | phantom-dep:ts-pattern | AI (phantom-deps): Referenced in config files per finding; stable false positive for this package. | ai |
Versions (showing 25 of 25)
| Version | Deps | Published |
|---|---|---|
| 1.0.57 | 23 / 5 | |
| 1.0.52 | 23 / 5 | |
| 1.0.43 | 23 / 5 | |
| 1.0.42 | 23 / 5 | |
| 1.0.40 | 23 / 5 | |
| 1.0.36 | 15 / 5 | |
| 1.0.35 | 15 / 5 | |
| 1.0.34 | 15 / 5 | |
| 1.0.33 | 15 / 5 | |
| 1.0.32 | 15 / 5 | |
| 1.0.27 | 15 / 5 | |
| 1.0.26 | 15 / 5 | |
| 1.0.25 | 15 / 5 | |
| 1.0.24 | 15 / 5 | |
| 1.0.23 | 15 / 5 | |
| 1.0.22 | 15 / 5 | |
| 1.0.21 | 10 / 5 | |
| 1.0.20 | 10 / 5 | |
| 1.0.18 | 9 / 4 | |
| 1.0.16 | 9 / 4 | |
| 1.0.14 | 9 / 4 | |
| 1.0.13 | 9 / 4 | |
| 1.0.12 | 9 / 4 | |
| 1.0.8 | 9 / 4 | |
| 0.3.3 | 9 / 4 |
v1.0.57
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.52
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.43
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.42
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.40
30 findingsThis version was published by a different npm account than previous versions on 2026-07-08. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.36
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.35
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.34
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.33
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.32
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.