← Home

casper-js-sdk

8
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

burlachenkomichaelsteuerdavidatwhiletrueyevhenbilovalex_myshchyshyncasper-sretvasile

Keywords

CasperBlockChainsdk

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:elliptic AI (dependencies): Package explicitly pins [email protected] via overrides; intentional and controlled dependency management. ai
provenance slsa-provenance AI (provenance): SLSA provenance attestation confirms CI/CD publishing from the official repository. ai
provenance publisher-changed AI (provenance): Publisher changed to GitHub Actions with SLSA provenance — this is a CI/CD migration, not a compromise. ai
phantom-deps phantom-dep:@scure/bip32 AI (phantom-deps): BIP32 key derivation is a core feature of a blockchain SDK; phantom-dep heuristic is a false positive. ai
phantom-deps phantom-dep:glob AI (phantom-deps): glob is a legitimate declared dependency in this blockchain SDK; phantom-dep heuristic fires because it's referenced in config/build files rather than direct imports. ai
phantom-deps phantom-dep:node-fetch AI (phantom-deps): node-fetch is a legitimate runtime dependency for HTTP calls in this SDK; phantom-dep heuristic is a false positive here. ai
phantom-deps phantom-dep:@scure/bip39 AI (phantom-deps): BIP39 mnemonic support is a core feature of a blockchain SDK; phantom-dep heuristic is a false positive. ai
phantom-deps phantom-dep:@noble/curves AI (phantom-deps): Elliptic curve cryptography is essential for a blockchain SDK; phantom-dep heuristic is a false positive. ai
phantom-deps phantom-dep:@open-rpc/client-js AI (phantom-deps): OpenRPC client is used for blockchain node communication; phantom-dep heuristic is a false positive for this SDK. ai
dependencies unvetted-dep:vocs AI (dependencies): vocs is a documentation site framework used for docs:build/dev/preview scripts; not a runtime dependency for SDK consumers. Low risk. ai
license uncommon-license:Apache 2.0 AI (license): Apache 2.0 is a well-known permissive open source license; the 'uncommon' flag is a false positive from the license checker's allowlist. ai
phantom-deps phantom-dep:@types/ws AI (phantom-deps): @types/ws is a TypeScript type definition package; its presence as a runtime dep is unusual but benign for a bundled SDK. ai
phantom-deps phantom-dep:reflect-metadata AI (phantom-deps): reflect-metadata is a known implicit runtime dependency for TypeScript decorator metadata; expected in TypeScript SDKs using decorators. ai

Versions (showing 8 of 8)

Version Deps Published
5.0.12 19 / 58
5.0.11 21 / 56
5.0.10 22 / 57
5.0.9 22 / 57
5.0.8 23 / 58
5.0.7 23 / 58
5.0.6 23 / 58
5.0.5 23 / 58

v5.0.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.0.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.0.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.0.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.0.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.