← Home

@activepieces/piece-http

34
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

abuaboudactivepieces-botabdul_activepiecer

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:dayjs AI (phantom-deps): Config-driven dependency usage pattern; stable for this package type. ai
phantom-deps phantom-dep:@anthropic-ai/sdk AI (phantom-deps): Config-driven dependency usage pattern; stable for this package type. ai
phantom-deps phantom-dep:replicate AI (phantom-deps): Config-driven dependency usage pattern; stable for this package type. ai
phantom-deps phantom-dep:deepmerge AI (phantom-deps): Config-driven dependency usage pattern; stable for this package type. ai
phantom-deps phantom-dep:openai AI (phantom-deps): Config-driven dependency usage pattern; stable for this package type. ai
phantom-deps phantom-dep:ai AI (phantom-deps): Transitive imports in plugin framework; stable pattern for this package. ai
phantom-deps phantom-dep:@ai-sdk/google AI (phantom-deps): Transitive imports in plugin framework; stable pattern for this package. ai
phantom-deps phantom-dep:@ai-sdk/openai AI (phantom-deps): Transitive imports in plugin framework; stable pattern for this package. ai
phantom-deps phantom-dep:@ai-sdk/anthropic AI (phantom-deps): Transitive imports in plugin framework; stable pattern for this package. ai
phantom-deps phantom-dep:@ai-sdk/replicate AI (phantom-deps): Transitive imports in plugin framework; stable pattern for this package. ai
phantom-deps phantom-dep:@sinclair/typebox AI (phantom-deps): Declared in package.json; used by framework pieces. Stable false positive. ai
phantom-deps phantom-dep:semver AI (phantom-deps): Declared in package.json; used by framework pieces. Stable false positive. ai
phantom-deps phantom-dep:nanoid AI (phantom-deps): Declared in package.json; used by framework pieces. Stable false positive. ai
phantom-deps phantom-dep:zod AI (phantom-deps): Declared in package.json; used by framework pieces. Stable false positive. ai
phantom-deps phantom-dep:axios-retry AI (phantom-deps): Declared in package.json; used by framework pieces. Stable false positive. ai
phantom-deps phantom-dep:deepmerge-ts AI (phantom-deps): Declared in package.json; used by framework pieces. Stable false positive. ai
phantom-deps phantom-dep:fast-glob AI (phantom-deps): Declared in package.json; used by framework pieces. Stable false positive. ai
phantom-deps phantom-dep:mime-types AI (phantom-deps): Declared in package.json; used by framework pieces. Stable false positive. ai
source-diff source-size-tripled AI (source-diff): Size growth from bundling deps into single dist file; expected for this build. ai
source-diff encoded-string-file:src/index.js AI (source-diff): Bundled esbuild output inlining deps; long strings are regex/library tables, not payloads. ai

Versions (showing 34 of 34)

Version Deps Published
0.11.12 0 / 0
0.11.11 0 / 0
0.11.10 7 / 1
0.11.9 7 / 1
0.11.8 7 / 1
0.11.7 16 / 0
0.11.6 17 / 0
0.11.5 17 / 0
0.11.4 17 / 0
0.11.2 19 / 0
0.11.1 19 / 0
0.11.0 16 / 0
0.10.0 15 / 0
0.9.5 14 / 0
0.9.4 14 / 0
0.9.3 14 / 0
0.9.2 14 / 0
0.9.1 14 / 0
0.9.0 14 / 0
0.8.7 14 / 0
0.8.6 15 / 0
0.8.5 15 / 0
0.8.4 20 / 0
0.8.3 20 / 0
0.8.2 20 / 0
0.8.1 20 / 0
0.8.0 20 / 0
0.7.0 18 / 0
0.6.2 17 / 0
0.6.1 17 / 0
0.6.0 17 / 0
0.5.1 13 / 0
0.5.0 13 / 0
0.4.5 13 / 0

v0.11.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.11.11

2 findings
HIGH Long encoded string in modified file: src/index.js source-diff

Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.6.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.6.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.5.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.4.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.