← Home

@atproto-labs/fetch-node

SSRF protection for fetch() in Node.js

17
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

devinivyestrattonbaileydholms

Keywords

atprotofetchnode

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:shady-links-raw-ip AI (semgrep): Raw IP appears in a test asserting SSRF rejection of private addresses — this is the package's core security feature, not a real outbound call. ai
dependencies unvetted-dep:undici_v6 AI (dependencies): npm alias for undici@^6.x — canonical Node.js HTTP client, multi-version alias pattern for compatibility. ai
dependencies unvetted-dep:undici_v7 AI (dependencies): npm alias for undici@^7.x — same rationale as undici_v6. ai
dependencies unvetted-dep:undici_v8 AI (dependencies): npm alias for undici@^8.x — same rationale as undici_v6. ai
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI publishing with SLSA attestation from the official bluesky-social/atproto monorepo; legitimate workflow change. ai
maintainer-change maintainer-removed AI (maintainer-change): Maintainer removal consistent with org-level CI publishing transition; no takeover indicators. ai

Versions (showing 17 of 17)

Version Deps Published
0.3.3 6 / 1
0.3.2 4 / 0
0.3.1 4 / 0
0.3.0 4 / 1
0.2.0 4 / 1
0.1.10 4 / 1
0.1.9 4 / 1
0.1.8 5 / 2
0.1.7 5 / 2
0.1.6 5 / 2
0.1.5 5 / 2
0.1.4 5 / 2
0.1.3 5 / 2
0.1.2 5 / 2
0.1.1 5 / 2
0.1.0 5 / 2
0.0.1 4 / 1

v0.1.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.