@axsdk/core
axsdk core
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | encoded-string-file:dist/lib.cjs | AI (source-diff): Long strings are tslib/TypeScript compiler helpers (setPrototypeOf, assign, awaiter patterns), not obfuscated payloads. | ai | |
| source-diff | encoded-string-file:dist/lib.js | AI (source-diff): Same tslib helper pattern in ESM build; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:qs | AI (phantom-deps): qs is a declared runtime dep used via config/bundled; phantom-dep heuristic fires on bundled packages. | ai | |
| typosquat | typosquat.levenshtein:cors | AI (typosquat): Scoped SDK package @axsdk/core; name similarity to 'cors' is coincidental, not impersonation. | ai | |
| phantom-deps | phantom-dep:nanoid | AI (phantom-deps): Phantom-dep heuristic; nanoid is a declared runtime dep, likely used in bundled output. | ai | |
| phantom-deps | phantom-dep:html2canvas | AI (phantom-deps): Phantom-dep heuristic; html2canvas is a declared runtime dep, likely used in bundled output. | ai |
Versions (showing 77 of 77)
| Version | Deps | Published |
|---|---|---|
| 0.4.32 | 6 / 2 | |
| 0.4.31 | 6 / 2 | |
| 0.4.30 | 6 / 2 | |
| 0.4.29 | 6 / 2 | |
| 0.4.28 | 6 / 2 | |
| 0.4.27 | 6 / 2 | |
| 0.4.25 | 6 / 2 | |
| 0.4.23 | 6 / 2 | |
| 0.4.22 | 6 / 2 | |
| 0.4.21 | 6 / 2 | |
| 0.4.20 | 6 / 2 | |
| 0.4.19 | 6 / 2 | |
| 0.4.18 | 6 / 2 | |
| 0.4.17 | 6 / 2 | |
| 0.4.15 | 6 / 2 | |
| 0.4.14 | 6 / 2 | |
| 0.4.13 | 6 / 2 | |
| 0.4.12 | 6 / 2 | |
| 0.4.11 | 6 / 2 | |
| 0.4.10 | 6 / 2 | |
| 0.4.8 | 6 / 2 | |
| 0.4.7 | 6 / 2 | |
| 0.4.6 | 6 / 2 | |
| 0.4.5 | 6 / 2 | |
| 0.4.3 | 6 / 2 | |
| 0.3.34 | 6 / 2 | |
| 0.3.33 | 6 / 2 | |
| 0.3.31 | 6 / 2 | |
| 0.3.30 | 6 / 2 | |
| 0.3.29 | 6 / 2 | |
| 0.3.28 | 6 / 2 | |
| 0.3.27 | 6 / 2 | |
| 0.3.26 | 6 / 2 | |
| 0.3.25 | 6 / 2 | |
| 0.3.24 | 6 / 2 | |
| 0.3.23 | 6 / 2 | |
| 0.3.22 | 6 / 2 | |
| 0.3.21 | 5 / 1 | |
| 0.3.20 | 5 / 1 | |
| 0.3.19 | 5 / 1 | |
| 0.3.18 | 5 / 1 | |
| 0.3.16 | 5 / 1 | |
| 0.3.15 | 5 / 1 | |
| 0.3.14 | 5 / 1 | |
| 0.3.13 | 5 / 1 | |
| 0.3.12 | 5 / 1 | |
| 0.3.11 | 5 / 1 | |
| 0.3.10 | 5 / 1 | |
| 0.3.8 | 5 / 1 | |
| 0.3.7 | 5 / 1 | |
| 0.3.6 | 5 / 1 | |
| 0.3.4 | 5 / 1 | |
| 0.3.3 | 5 / 1 | |
| 0.3.2 | 5 / 1 | |
| 0.3.1 | 5 / 1 | |
| 0.3.0 | 5 / 1 | |
| 0.2.13 | 5 / 1 | |
| 0.2.12 | 5 / 1 | |
| 0.2.11 | 5 / 1 | |
| 0.2.10 | 5 / 1 | |
| 0.2.9 | 5 / 1 | |
| 0.2.8 | 5 / 1 | |
| 0.2.7 | 5 / 1 | |
| 0.2.6 | 5 / 1 | |
| 0.2.5 | 5 / 1 | |
| 0.2.4 | 5 / 1 | |
| 0.2.3 | 5 / 1 | |
| 0.2.2 | 5 / 1 | |
| 0.2.1 | 5 / 1 | |
| 0.2.0 | 5 / 1 | |
| 0.1.8 | 5 / 1 | |
| 0.1.6 | 5 / 1 | |
| 0.1.5 | 5 / 1 | |
| 0.1.4 | 5 / 1 | |
| 0.1.3 | 5 / 1 | |
| 0.1.2 | 5 / 1 | |
| 0.1.1 | 5 / 1 |
v0.4.32
3 findingsModified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.31
3 findingsModified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.30
3 findingsModified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.29
3 findingsModified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.28
3 findingsModified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.27
3 findingsModified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.23
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.21
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.20
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.19
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.18
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.17
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.15
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.14
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.13
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.12
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.11
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.10
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.8
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.7
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.6
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.5
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.3
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.34
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.33
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.31
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.30
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.29
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.28
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.27
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.26
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.25
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.24
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.23
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.22
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.21
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.20
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.19
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.18
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.16
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.15
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.14
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.13
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.11
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.10
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.8
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.7
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.6
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.4
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.3
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.2
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.1
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.0
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.13
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.12
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.11
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.10
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.9
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.8
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.7
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.6
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.5
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.4
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.3
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.2
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.1
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.0
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.8
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.6
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.5
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.4
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.2
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.1
2 findingsPackage name '@axsdk/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.