← Home

@bunchtogether/boost-client

## API

100
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

bunchtogether

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@callstack/async-storage AI (phantom-deps): @callstack/async-storage is explicitly declared in dependencies and referenced in build config; phantom-dep false positive for this package. ai
source-diff large-new-source-files AI (source-diff): Package has 111 versions and a long history; new source files reflect legitimate package growth/refactoring, not injected code. Publisher has clean track record. ai
dependencies unvetted-dep:superagent AI (dependencies): superagent is a well-established HTTP client library; its use is consistent with this package's client-side data-fetching purpose. ai
dependencies unvetted-dep:query-string AI (dependencies): query-string is a popular, well-maintained URL query string utility; no risk concerns. ai
dependencies unvetted-dep:superagent-use AI (dependencies): superagent-use is a standard superagent plugin mechanism; expected alongside superagent dependency. ai
dependencies unvetted-dep:superagent-prefix AI (dependencies): superagent-prefix is a standard superagent plugin for URL prefixing; expected alongside superagent dependency. ai
dependencies unvetted-dep:@callstack/async-storage AI (dependencies): @callstack/async-storage is a well-known React Native async storage library from a reputable org; no risk concerns. ai
provenance no-provenance AI (provenance): Package predates Sigstore provenance adoption; lack of attestation is expected for packages of this age and is not a risk signal. ai
dependencies unvetted-dep:redux-saga AI (dependencies): redux-saga is a well-known, widely-used Redux middleware library; its presence is expected and benign for this package. ai

Versions (showing 100 of 111)

Version Deps Published
1.3.20 9 / 26
1.3.19 9 / 26
1.3.18 9 / 26
1.3.17 9 / 26
1.3.16 9 / 26
1.3.15 9 / 26
1.3.14 9 / 26
1.3.13 9 / 26
1.3.12 9 / 26
1.3.11 9 / 26
1.3.10 9 / 26
1.3.9 9 / 26
1.3.8 9 / 26
1.3.7 9 / 26
1.3.6 9 / 26
1.3.5 9 / 26
1.3.4 9 / 26
1.3.3 9 / 26
1.3.2 9 / 26
1.3.1 9 / 26
1.3.0 9 / 26
1.2.4 10 / 26
1.2.3 10 / 26
1.2.2 10 / 26
1.2.1 10 / 26
1.2.0 10 / 26
1.1.33 10 / 26
1.1.32 10 / 26
1.1.31 10 / 26
1.1.30 10 / 26
1.1.29 10 / 26
1.1.28 10 / 26
1.1.27 10 / 26
1.1.26 10 / 26
1.1.25 10 / 24
1.1.24 10 / 24
1.1.23 10 / 24
1.1.22 10 / 24
1.1.21 10 / 24
1.1.20 10 / 24
1.1.19 10 / 24
1.1.18 10 / 24
1.1.17 10 / 24
1.1.16 10 / 24
1.1.15 10 / 24
1.1.14 10 / 24
1.1.13 10 / 24
1.1.12 10 / 24
1.1.11 10 / 24
1.1.10 10 / 24
1.1.9 10 / 24
1.1.8 10 / 24
1.1.7 10 / 24
1.1.6 10 / 24
1.1.5 10 / 24
1.1.4 10 / 24
1.1.3 10 / 24
1.1.2 10 / 24
1.1.1 10 / 24
1.1.0 10 / 24
1.0.52 10 / 24
1.0.51 10 / 24
1.0.50 10 / 24
1.0.49 10 / 24
1.0.48 10 / 24
1.0.47 10 / 24
1.0.46 10 / 24
1.0.45 10 / 24
1.0.44 10 / 24
1.0.43 10 / 24
1.0.42 10 / 24
1.0.41 10 / 22
1.0.40 10 / 22
1.0.39 10 / 23
1.0.38 10 / 23
1.0.37 10 / 23
1.0.35 10 / 22
1.0.34 10 / 22
1.0.33 10 / 22
1.0.32 10 / 22
1.0.31 10 / 22
1.0.30 10 / 22
1.0.29 10 / 22
1.0.28 10 / 22
1.0.27 10 / 22
1.0.26 10 / 22
1.0.25 10 / 22
1.0.23 10 / 22
1.0.22 10 / 22
1.0.21 10 / 22
1.0.20 10 / 22
1.0.19 10 / 22
1.0.18 10 / 22
1.0.17 10 / 22
1.0.16 10 / 22
1.0.15 10 / 22
1.0.14 10 / 22
1.0.13 10 / 22
1.0.12 10 / 22
1.0.11 10 / 22
Showing 100 of 111 Next page →

v1.3.20

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.19

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.17

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.15

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.14

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.12

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.8

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.33

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.30

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.28

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.21

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.16

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.15

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.12

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.11

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.10

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.9

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.8

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.51

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.50

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.49

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.48

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.46

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.44

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.42

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.39

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.37

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.35

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.34

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.32

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.30

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.28

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.26

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.22

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.19

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.18

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.15

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.14

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.13

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.