@c8y/client
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | no-provenance | AI (provenance): Long-established package published via GitHub Actions CI; lack of Sigstore attestation is common and not a risk signal here. | ai | |
| dependencies | unvetted-dep:b2a | AI (dependencies): b2a is a simple base64 encoding utility; stable use in this IoT client package across versions. | ai | |
| phantom-deps | phantom-dep:@types/node | AI (phantom-deps): TypeScript type package; loaded by convention, not directly imported. Stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@types/cometd | AI (phantom-deps): TypeScript type package; loaded by convention, not directly imported. Stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:cometd-nodejs-client | AI (phantom-deps): Referenced in config files for Node.js CometD transport; stable false positive for this IoT client package. | ai |
Versions (showing 100 of 224)
v1023.14.195
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.14.193
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.14.192
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.14.191
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.14.186
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.14.185
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.14.181
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.14.180
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.14.178
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.14.177
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1021.22.165
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.