← Home

@keplr-wallet/hooks-bitcoin

15
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

chainapsis

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI publishing is confirmed by SLSA provenance attestation; stable for this package going forward. ai
bogus-package bogus-package AI (bogus-package): Monorepo sub-package from established keplr-wallet org; missing metadata is a known pattern across their packages. ai
npm-metadata no-description AI (npm-metadata): Consistent with other @keplr-wallet/* sub-packages; not a spam indicator here. ai
provenance no-provenance AI (provenance): No provenance across all keplr-wallet packages; stable false positive for this publisher. ai
phantom-deps phantom-dep:@keplr-wallet/background AI (phantom-deps): Same-org monorepo dep; stable false positive for this package. ai
phantom-deps phantom-dep:long AI (phantom-deps): Monorepo package; transitive/polyfill dep declared for bundler config, not a direct import. ai
phantom-deps phantom-dep:@keplr-wallet/proto-types AI (phantom-deps): Same-org monorepo dep; stable false positive for this package. ai
phantom-deps phantom-dep:buffer AI (phantom-deps): Browser polyfill declared for bundler config; stable pattern for this package. ai
phantom-deps phantom-dep:utility-types AI (phantom-deps): TypeScript utility types used at type-level only; not a runtime import. ai
phantom-deps phantom-dep:@keplr-wallet/crypto AI (phantom-deps): Same-org monorepo dep; may be used transitively or at type level. ai

Versions (showing 15 of 115)

Version Deps Published
0.12.245 14 / 0
0.12.244 14 / 0
0.12.243 14 / 0
0.12.242 14 / 0
0.12.241 14 / 0
0.12.240 14 / 0
0.12.239 14 / 0
0.12.238 14 / 0
0.12.237 14 / 0
0.12.236 14 / 0
0.12.235 14 / 0
0.12.234 14 / 0
0.12.233 14 / 0
0.12.232 14 / 0
0.12.231 14 / 0

v0.12.245

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.244

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.243

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.242

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.241

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.240

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.239

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.238

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.237

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.236

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.12.235

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.12.234

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.12.233

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.12.232

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.12.231

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.