@c8y/client
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | no-provenance | AI (provenance): Long-established package published via GitHub Actions CI; lack of Sigstore attestation is common and not a risk signal here. | ai | |
| dependencies | unvetted-dep:b2a | AI (dependencies): b2a is a simple base64 encoding utility; stable use in this IoT client package across versions. | ai | |
| phantom-deps | phantom-dep:@types/node | AI (phantom-deps): TypeScript type package; loaded by convention, not directly imported. Stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@types/cometd | AI (phantom-deps): TypeScript type package; loaded by convention, not directly imported. Stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:cometd-nodejs-client | AI (phantom-deps): Referenced in config files for Node.js CometD transport; stable false positive for this IoT client package. | ai |
Versions (showing 51 of 189)
| Version | Deps | Published |
|---|---|---|
| 1023.83.4 | 9 / 9 | |
| 1023.83.3 | 9 / 8 | |
| 1023.83.2 | 9 / 8 | |
| 1023.82.8 | 9 / 8 | |
| 1023.82.4 | 9 / 8 | |
| 1023.82.3 | 9 / 8 | |
| 1023.82.2 | 9 / 8 | |
| 1023.82.1 | 9 / 8 | |
| 1023.82.0 | 9 / 8 | |
| 1023.81.3 | 9 / 8 | |
| 1023.81.2 | 9 / 8 | |
| 1023.80.2 | 9 / 8 | |
| 1023.80.0 | 9 / 8 | |
| 1023.79.1 | 9 / 8 | |
| 1023.78.7 | 9 / 8 | |
| 1023.78.5 | 9 / 8 | |
| 1023.78.4 | 9 / 8 | |
| 1023.78.1 | 9 / 8 | |
| 1023.77.1 | 9 / 8 | |
| 1023.76.0 | 9 / 8 | |
| 1023.75.1 | 9 / 8 | |
| 1023.71.1 | 9 / 8 | |
| 1023.70.0 | 9 / 8 | |
| 1023.68.7 | 9 / 8 | |
| 1023.68.6 | 9 / 8 | |
| 1023.68.3 | 9 / 8 | |
| 1023.68.0 | 9 / 8 | |
| 1023.67.0 | 9 / 8 | |
| 1023.66.4 | 9 / 8 | |
| 1023.66.3 | 9 / 8 | |
| 1023.65.2 | 9 / 8 | |
| 1023.65.1 | 9 / 8 | |
| 1023.65.0 | 9 / 8 | |
| 1023.64.2 | 9 / 8 | |
| 1023.64.1 | 9 / 8 | |
| 1023.63.1 | 9 / 8 | |
| 1023.63.0 | 9 / 8 | |
| 1023.62.2 | 9 / 8 | |
| 1023.61.12 | 9 / 8 | |
| 1023.61.2 | 9 / 8 | |
| 1023.61.0 | 9 / 8 | |
| 1023.59.1 | 9 / 8 | |
| 1023.58.3 | 9 / 8 | |
| 1023.57.0 | 9 / 8 | |
| 1023.55.5 | 9 / 8 | |
| 1023.53.0 | 9 / 8 | |
| 1023.52.0 | 9 / 8 | |
| 1023.50.2 | 9 / 8 | |
| 1023.48.3 | 9 / 8 | |
| 1023.48.2 | 9 / 8 | |
| 1023.48.0 | 9 / 8 |
v1023.83.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.83.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.83.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.82.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.82.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.82.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.82.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.82.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.82.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.81.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.81.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.80.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.80.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.79.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.78.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.78.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.78.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.78.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.77.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.75.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.71.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.70.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.68.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.68.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.68.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.68.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.67.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.66.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.66.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.65.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.65.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.65.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.64.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1023.64.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.63.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.63.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.62.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.61.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.61.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.61.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.59.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.58.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.57.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.55.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.53.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.52.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.50.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.48.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.48.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.48.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.