@actions/http-client
Actions Http Client
16
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
bryanmacfarlanethboopericsciplebdehamer
Keywords
githubactionshttp
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:undici | AI (dependencies): Undici is a legitimate, widely-used HTTP client library; appropriate for this package's purpose. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New dependency is undici, an established HTTP library; semantically appropriate and from trusted maintainer. | ai | |
| provenance | publisher-changed | AI (provenance): Publisher changed to the official 'GitHub Actions' org account — a legitimate centralization of publishing for the actions/toolkit monorepo. SLSA attestation confirms CI/CD provenance. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Added maintainers (cschleiden, bdehamer, joshmgross) are known GitHub Actions team members; consistent with org-level team management. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Removal of hross is consistent with normal team roster changes within the GitHub Actions org; no takeover indicators given SLSA attestation. | ai | |
| provenance | no-provenance | AI (provenance): Published in 2022 before Sigstore/npm provenance was standard; @actions scope is GitHub-controlled. | ai |