tiny-secp256k1
A tiny secp256k1 JS
22
Versions
MIT
License
Yes
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
No source commit
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
jprichardsonjunderw
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| install-scripts | install-script:install | AI (install-scripts): Native C addon (gypfile:true) using node-gyp rebuild with graceful JS fallback. Standard pattern for native crypto bindings. | ai | |
| semgrep | semgrep:hex-decode | AI (semgrep): Hex values are secp256k1 curve constants (group order and field prime) — well-known cryptographic parameters, not obfuscated payloads. | ai | |
| provenance | missing-githead | AI (provenance): Established publisher with strong track record; missing gitHead is a minor metadata change, not a security concern. | ai | |
| source-diff | large-new-source-files | AI (source-diff): v2.x rewrote from native C++ bindings to WASM; new files are expected for this architectural change. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size increase is from the WASM binary replacing native C++ bindings; expected for v2.x architecture. | ai |
Versions (showing 22 of 22)
| Version | Deps | Published |
|---|---|---|
| 2.2.4 | 1 / 21 | |
| 2.2.3 | 1 / 21 | |
| 2.2.2 | 1 / 19 | |
| 2.2.1 | 1 / 19 | |
| 2.2.0 | 1 / 19 | |
| 2.1.2 | 1 / 19 | |
| 2.1.1 | 1 / 19 | |
| 2.1.0 | 1 / 19 | |
| 2.0.1 | 0 / 19 | |
| 2.0.0 | 0 / 19 | |
| 1.1.7 | 5 / 3 | |
| 0.2.2 | 5 / 1 | |
| 0.2.1 | 5 / 1 | |
| 0.2.0 | 5 / 1 | |
| 0.1.0 | 5 / 1 | |
| 0.0.7 | 5 / 1 | |
| 0.0.6 | 5 / 1 | |
| 0.0.5 | 5 / 1 | |
| 0.0.4 | 5 / 1 | |
| 0.0.3 | 5 / 1 | |
| 0.0.2 | 5 / 1 | |
| 0.0.1 | 5 / 1 |