@archildata/client
Deprecated — install `disk` (pure-JS API+CLI) and/or `@archildata/native` (low-level protocol client) instead.
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): Expected side effect of moving publish to CI/CD attested pipeline. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Coincides with legitimate trusted-publisher transition, not compromise. | ai | |
| npm-metadata | bundled-binaries | AI (npm-metadata): NAPI-RS native addon package; .node binaries are the expected distribution mechanism for platform-specific native bindings. Pattern matches canonical NAPI-RS structure. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): child_process used only to run 'which ldd' for musl detection in NAPI-RS boilerplate index.js; benign and stable for this package. | ai | |
| semgrep | semgrep:child-process-execsync | AI (semgrep): execSync('which ldd') is NAPI-RS boilerplate for detecting musl libc to select the correct native binary; not a security risk for this package. | ai | |
| provenance | no-provenance | AI (provenance): Lack of provenance is common (~88% of packages) and not a meaningful risk signal for this straightforward deprecation shim with no install scripts or suspicious code. | ai |
Versions (showing 34 of 34)
| Version | Deps | Published |
|---|---|---|
| 0.8.22 | 1 / 3 | |
| 0.8.21 | 1 / 3 | |
| 0.8.20 | 1 / 3 | |
| 0.8.19 | 1 / 3 | |
| 0.8.18 | 1 / 3 | |
| 0.8.17 | 1 / 3 | |
| 0.8.16 | 1 / 3 | |
| 0.8.15 | 1 / 3 | |
| 0.8.14 | 1 / 3 | |
| 0.8.13 | 1 / 3 | |
| 0.8.12 | 1 / 3 | |
| 0.8.11 | 1 / 3 | |
| 0.8.10 | 1 / 3 | |
| 0.8.9 | 1 / 3 | |
| 0.8.8 | 1 / 5 | |
| 0.8.7 | 1 / 5 | |
| 0.8.6 | 1 / 5 | |
| 0.8.4 | 1 / 5 | |
| 0.8.3 | 1 / 5 | |
| 0.8.2 | 1 / 5 | |
| 0.8.1 | 1 / 5 | |
| 0.1.13 | 0 / 1 | |
| 0.1.12 | 0 / 1 | |
| 0.1.11 | 0 / 1 | |
| 0.1.10 | 0 / 1 | |
| 0.1.9 | 0 / 1 | |
| 0.1.8 | 0 / 1 | |
| 0.1.7 | 0 / 1 | |
| 0.1.6 | 0 / 1 | |
| 0.1.5 | 0 / 1 | |
| 0.1.4 | 0 / 1 | |
| 0.1.3 | 0 / 1 | |
| 0.1.2 | 0 / 1 | |
| 0.1.0 | 0 / 1 |
v0.8.22
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (jhleath) on 2026-07-21, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.8.21
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: jhleath.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.20
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: jhleath.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.19
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: jhleath.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.