@wireio/sdk-core
Library for working with Wire powered blockchains.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:elliptic | AI (dependencies): elliptic is a standard crypto dependency for blockchain SDKs; expected and not known-vulnerable at ^6.5.4. | ai | |
| phantom-deps | phantom-dep:pako | AI (phantom-deps): Standard compression lib; consistent with blockchain SDK use; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:bn.js | AI (phantom-deps): Standard big-number lib for crypto; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:ethers | AI (phantom-deps): Core blockchain lib; consistent with Wire blockchain SDK purpose. | ai | |
| phantom-deps | phantom-dep:brorand | AI (phantom-deps): Crypto RNG lib; expected transitive dep for elliptic; phantom-dep false positive. | ai | |
| phantom-deps | phantom-dep:tweetnacl | AI (phantom-deps): Standard crypto lib; consistent with blockchain SDK purpose. | ai | |
| phantom-deps | phantom-dep:js-big-decimal | AI (phantom-deps): Decimal arithmetic lib; consistent with blockchain SDK use. | ai | |
| phantom-deps | phantom-dep:hash.js | AI (phantom-deps): Crypto hashing lib; consistent with blockchain SDK; phantom-dep false positive. | ai | |
| phantom-deps | phantom-dep:elliptic | AI (phantom-deps): Standard elliptic curve crypto lib; expected in blockchain SDK. | ai | |
| phantom-deps | phantom-dep:tslib | AI (phantom-deps): tslib is a known implicit TypeScript runtime dep; stable false positive for compiled TS packages. | ai | |
| phantom-deps | phantom-dep:ts-pattern | AI (phantom-deps): Referenced in config files per finding; stable false positive for this package. | ai |
Versions (showing 6 of 6)
| Version | Deps | Published |
|---|---|---|
| 1.0.27 | 15 / 5 | |
| 1.0.25 | 15 / 5 | |
| 1.0.24 | 15 / 5 | |
| 1.0.23 | 15 / 5 | |
| 1.0.16 | 9 / 4 | |
| 0.3.3 | 9 / 4 |
v1.0.27
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.25
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.24
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.23
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.16
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.