← Home

eth-crypto

Cryptographic functions for ethereum and how to use them with web3 and solidity

2
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

pubkey

Keywords

ethereumethweb3solidityencryptionsecp256k1dappblockchaineciessmart-contractidentitysignature

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:hex-decode AI (semgrep): Hex decoding is core to this Ethereum crypto library's cipher/key handling; not a malicious payload pattern. ai
semgrep semgrep:base64-decode AI (semgrep): Base64 decode used for hex conversion utility; legitimate crypto library operation. ai
phantom-deps phantom-dep:@types/bn.js AI (phantom-deps): Explicitly whitelisted in package's own dependency-check script with --ignore-module @types/bn.js. ai

Versions (showing 2 of 2)

Version Deps Published
4.1.0 7 / 49
4.0.0 8 / 49

v4.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.