@xyo-network/sdk-protocol
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | encoded-string-file:dist/browser/worker/wasmHash-bundle.mjs | AI (source-diff): Base64 WASM binary in hash-wasm bundle, standard pattern for WASM hash libs, not a payload. | ai | |
| dependencies | unvetted-dep:@xyo-network/pqc | AI (dependencies): Internal XYO monorepo sibling package, same version pinning as all other deps. | ai | |
| source-diff | obfuscated-file:dist/neutral/worker/wasmHash-bundle.mjs | AI (source-diff): esbuild bundle output of hash-wasm worker, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/node/worker/wasmHash-bundle.mjs | AI (source-diff): esbuild bundle output of hash-wasm worker, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/neutral/hash/worker/wasmHash-bundle.mjs | AI (source-diff): Bundled build output (esbuild-style wasm worker), not obfuscation; no malicious behavior present. | ai | |
| dependencies | unvetted-dep:@xyo-network/sdk-protocol-core | AI (dependencies): First-party same-org split-out package, part of documented facade refactor. | ai | |
| source-diff | obfuscated-file:dist/browser/worker/wasmHash-bundle.mjs | AI (source-diff): File is bundled build output (zod/wasm worker bundle); readable source visible in sample, not true obfuscation. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): All new deps are first-party @xyo-network/* packages at matching version; monorepo barrel consolidation pattern. | ai |
Versions (showing 14 of 14)
| Version | Deps | Published |
|---|---|---|
| 7.1.0 | 1 / 9 | |
| 7.0.16 | 1 / 13 | |
| 7.0.15 | 0 / 31 | |
| 7.0.14 | 51 / 23 | |
| 7.0.13 | 51 / 25 | |
| 7.0.12 | 0 / 76 | |
| 7.0.11 | 0 / 76 | |
| 7.0.10 | 0 / 76 | |
| 7.0.9 | 0 / 76 | |
| 7.0.8 | 0 / 76 | |
| 7.0.7 | 0 / 76 | |
| 7.0.6 | 0 / 76 | |
| 7.0.5 | 0 / 29 | |
| 7.0.4 | 0 / 29 |
v7.1.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.0.16
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.0.15
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.0.14
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.0.13
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.0.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.0.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.0.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.0.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.0.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.0.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.0.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.0.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.0.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.