@bbc/consumer-contracts
Consumer driven contracts for Node.js
1
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
bbc-voice-pipelineglorhie99rtholmes96simon_taylordrrobharperjodiw_bbchowelr03peteslomanbhartn01johnsn27olivierhuinbbcparticipation-jenkinsbillt-bbcayu-idjajasgospodinovcharliertonymcbethmagdalena.glancrichardfeltonjezbur-bbcchalfordrobfarrsilver-jenkinsliam.jenkinsonrisheet_thanki_bbcmartmarmatimasplinmdtbuildcps-supportbelloro_bbcpererr03smugpiedoladbbcdjwillcottstephegn_bbcbbc-web-corefrankj05jamesscarboroughdaniel.ochieng.extmknishlcheffernanbbc-adminiplayer-web-jenkinssbasonjezhodgesbbclewersteven-bbcbbc-news-jenkinsbenjaa14craigjabdu01tarqwynlaura01cattranfieldpjlangleysadia-taznimchrisn-bbcalexshelleykieranjoycekasunmadushankaabz.memichaelmccoyjpark0224dannymeloyrichag04carlaslatterynjh-bbcsimongregorynicholasgriffin_bbcmarkturnerpetra-atiplayerradio-awsmonsaisubsidelbbcrddanmrbryerjamesreedwyellbozziejim-johnson-rollingsstephenrobertsbbchafsa-abdulsalimfahad-75bridga03smiths124skillc01dan.thomsonbbcallybeebpcs-amp-jenkinsmark.irelandmedia-playout-jenkinschrisowenbbc-cd-jenkinslangtonmpartner-platform-jenkinsapi-management-jenkinsweather-jenkinsbbc-isiteadamxawormab01urbanm13matt-rhys-jones-bbcmichaelmrnscottjarvismarcburrowsedembbcchrismarsdenneilcraigeagerterrier_bbcawalsh90eloisecmacgll01anthonygreengel-jenkinssamgjwchalikovluke01455darrenlucas.bbcrozgonyiovaibljana345tomhobbsbbcjlsorakabigaelvidhya09tom-wrmatthewcardraulfuentesdaramaguiremark.howitteamonnsullivansamirichardsonhenrywarneshumphreyhannahdaddbeckytravkerrynscrivensport-web-jenkinskirbyc02kcoyle-bbcadama03daniel.ellisiain-bbcj-e-borehamwilsoh58abd.el-aziz.exttimhewittbrittvarnomashcleavelydiamooyoudyben_newcombeoliviadrurybbc-gnl-ciseancarrolldavidbuckhurstitv-ci-machineaudienceplatformdevbbc-archivesearch-development-teamjonathanballssounds-web-jenkinsmaxwec01obriet04mikeybykercisnkydustin-bbcalexa_srmsdevalasdairstalkerjackrmdwaleestomfranciswinningtonthomam67locator-deployrolandosorbellijordanholtmartysaintymassimurarachael-waddingtongarthcoandrewscfcchatbnchriskaymckayj07nickshankshextenevebullochlaura94dudarcoderkindgw8karen_camnpmleobsnerosivalanaceriseandywfmsupp03fostukleedriscollabigailgnicolabuckhurstacarlson0000education-jenkinsallishulteskeithcrooksbbclawrencep_bbcrdleedoughtyandyrobinson01blundj02sgrobisonlukedeightonbinhbuiinsyn-jenkinskite-jenkinsdaniel_brown_bbcwaindc01hanleg03bjorn_twachtmannemupatroljonpollardbbchellap01angelinalblythcardl01abrarkaydecygsalmah95kamara.bennettkevin.mackaypmaudsleyinti0bbcrd-artifactoryparwiz_sharifigarethjdaviescheunm01norrid02priyapolinenithomaspreecebbcjason.leemingcaporp01nanbobswatitabibianarundaleshaziabeethechangeridwan_devsteve_culverwellwillsidlebbcy.millionmattowenuksbeck1craigjwrightanderb08szpytfire-bbcguptaa01aaronmoore56yardssimontannermilkywaynianrussellbroughtonalexjn15assizpereirashrey-glageorge-brookeiplayer-pc-downloads-pipeline-botchrispnicholsonamelialloydbbcbbc-search-and-navigationjfsbbcarchibaldersonusmanbuildsstuart_jennings_bbcjacobprycemattgreenhamcv-bbcrobcattnewslabs-jenkinsjoshcoventrybbc-sounds-offproductdave.at.bbcsarahrainbowfarahjabridavid.verbenyiresist01ryanmckennabbcchris-s-thompsonshoba15matthewtaylorworkroberp05andysteadbbcclarkb12feglese_bbccarrejoe3johnnewmans-zaid-samritbbcgarydavieslexedwardsbbckmurphy3377bennuttallsimonpittthomsonpjonpbbcbradleyphippsmadamotsheilab6bbc-delivery-engineeringalistair.gempfmattbbcalexchestersbbcstevensamsyavor-atanasovbenjwheelerneha0508rthompson1991jamiebower185claydelaschibbccjewell47mcmanj04bbc-cloudengsamcauserjack_mcpolandonlyonehasgavinwright292zaintahirbbcbbcbsddaniel-baileygingertonicstdio-pmathkeehanwilldahlgreendaniel.helennenehbsevisariisikwoodp11andywebb2-bbcdo0g.bbccobair01tomchamberlainuklazzaa01ovsichtidataforce-jenkinsandycharrisjoshuacaddykavbis066iuketaylorpallavisharmabbcaward2022tamsingreensimm90tmocodeepaakhilktalagasan-rairyanwaudbybbc_ivanalvarezandyj-bbcsubhathirarengarajjsheriffbbcndbbcmangrjuiyusuf963mgavyn_bbcmesenbad-horse-bbcyonglexuizzy-pickeringgraham-armstrong-bbcshez-bbcolivia-p-moorevaughr03jackhoggbbcm-al-maarykatie.frostuk-ummeajitsanto09teju_jakkiallbuttergnpmbsfergusreidbbcodonnellbbcsuzanna_kwongfoxk13fullerlee-bbcsframptonghazif03river-bbcmnharrisonaaronkenyonbrotherkaifnotten13jakub.ggrace_alagaratnamtalal-adnanjkordekbbcjpeutherer1j616s-bbcken0310sekhar01ashtuckbbclukeparker02chrisorrickbbctampie85akumac01padmavathi.tatavartycaeseribrahimjrew-bbcramkup01karim-sprnaivinh.ta.bbccatherine_hprmichael_mulgrewaggari01laitangbbcshaquillaevelynlantana-alimilkywaynian-bbcglediatorridwanchocodedbypaulhine24arnvshukla89ryanmcbbcpriyal2024liamcannnronanmocketthangbbcmarktaylorbbcallena61marta.martidavid-boydelldavidayoolam-mafenitariqatiasilidbiguzc01shanthichaitanyakelvininukbbcnendhruvinkenhennehconway24rodger-threlfallanatdeanbeebtom-cowardjamese00garwod01bbcparfaittomnuttallbbcajrobzpatelj03bbc-cicdguild-machineuserigorisolomoncathawkercolinr2hannah-slaterrichhildyardrlfbbcvlee.bbcmessage-keeperdarkoa01jonyardleylauramihai-bbcabicoelbird96clairelittler-bbcfalko189reeda06ed.guccionesinghn08dale-waterworthyoshihirokasaharaamitch07fglover84welshl02albertlobbcgloandcopaulybwssystems-integrationlokih_james.bungayrobbmcquistonmint-dewitrlam0fuzzyjesscharlie-cowan-bbctomwieck2chris.andrews05tdoukinitsasrichard_gilpinfahad-s75bbcjlkatharinaschulzcraigatsunnybbcdas-partnerllouisetaylorbbcfelicityrcdavidsolsonapuertasjakepointingphillbbclokh01norrib01bbc-tv-open-sourcenirerr01anthonygoodchildarunbhari11ken.barnetttzaman76mathieuloutrechaitanyajjchrisjmuddmomahboobianshawnhardernhippoglenndavidsonbbcpshaw03chriss901olssod02david.toluhibensegnibbcduncan-corps-bbcpeterrichmondbbcsofiadionisioamitsavantjmegmanosada.paranaliyanagesgoudhamjadhav02orforn01holladnathjoyceashwinrdnazineh2023jonathan-gillespieimran.haidryhelen_morrisbrianbayesmichellebbcespirn01stephenlovellgiacomobgtiposupportmerhayishaaqiqbalelliottnewtonbbcmianhassanijcablesmithd24rbtweobrglennalcockcdorrian871rosie.inmandannydaviesbbcjamesdesqbrooklyn-bbcaliciagrandjeanteyahbdmattwright-bbccameronsabudabbcvinodraneshahp07jibberjimbbcjemmaproopashree-ramachandraiahdwalker487tcsquaredwhitew02chris.darlastoncallap03katyasaaabbabartsadlerbbcpeterc89matt-harris-bbcfelixmercermosshjerlingiulia.bukhvalovarosemcnallygozcue01-bbckierankellyspyrosoftandrewc0617lokesh_srinivasaashrau01zahidz01goswat01emma-moodielores-bbcangel_mariaagurenciks-bbcyellowbendyflomptytaggaj01amathmmstephensonbbcats-delivery-jenkins-userdaviskkarlamayebbcjameswilsonbbcdanielhoughbbcntbbcmarinos-papamichaellewisbellwoodyasins02keithwhittamdanielcampbellbbcmurraymcalpineharshapatankarbbcg-duffgauravmadandarior01sykecharles_alexissarveshpatilsudeep.kondikoppajq45marcw-bbcgiefortuna-bbcdecaet01faizal.ntambiyephildawsonbbcmatthewtinnbbcirina.barros.bbccoopeg05ben.bagley.bbccallumjfortunebenjijgoliviadmic342nzzaidi29ahmada16battel01quilaj01lopezl_bbcabdallah_alsalmiematharyasminasgharkevin-castillo-bbcjmonaghanemily_scottbbcwhitingbrdavidbloodamckinlaybbcadam-ali-bbcbaxterkyleidamfeedsandnpebbcdevzakarusharorarajvadlamudimikekryworukbbc-images-machine-userantoinerabanesbbcbbc-andyharmonmarykate.macphee
Keywords
consumercontracts
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:dynamic-require | AI (semgrep): Intentional contract-file loader pattern; stable design across versions of this package. | ai |
Versions (showing 1 of 1)
| Version | Deps | Published |
|---|---|---|
| 4.5.1 | 8 / 19 |