← Home

@certd/plugin-lib

51
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

greper

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern new-deps-added AI (publish-pattern): New dep is an official Alibaba Cloud SDK utility, consistent with existing alicloud deps in this package. ai
provenance no-provenance AI (provenance): Only ~12% of npm packages have provenance; not a disqualifier for established packages. ai
npm-metadata no-description AI (npm-metadata): Established package with long history; missing description is metadata gap, not malware signal. ai
bogus-package bogus-package AI (bogus-package): Established @certd org package; missing metadata is a style issue, not a malice indicator. ai
dependencies unvetted-dep:@alicloud/openapi-client AI (dependencies): Official Alibaba Cloud SDK client; expected for cloud provider integration. ai
dependencies unvetted-dep:qiniu AI (dependencies): Qiniu is a legitimate Chinese cloud storage SDK; expected dependency for a cert deployment plugin. ai
dependencies unvetted-dep:@alicloud/openapi-util AI (dependencies): Official Alibaba Cloud SDK utility; expected for cloud provider integration. ai
phantom-deps phantom-dep:strip-ansi AI (phantom-deps): Cloud SDK re-export pattern; stable for this package. ai
phantom-deps phantom-dep:@certd/plus-core AI (phantom-deps): Same-org package; phantom-dep is a false positive for monorepo structures. ai
phantom-deps phantom-dep:cos-nodejs-sdk-v5 AI (phantom-deps): Cloud SDK re-export pattern; stable for this package. ai
phantom-deps phantom-dep:socks-proxy-agent AI (phantom-deps): Cloud SDK re-export pattern; stable for this package. ai
phantom-deps phantom-dep:@alicloud/pop-core AI (phantom-deps): Cloud SDK re-export pattern; stable for this package. ai
phantom-deps phantom-dep:ssh2 AI (phantom-deps): Plugin-lib re-exports cloud/infra SDKs; phantom-dep pattern is structural, not a risk. ai
phantom-deps phantom-dep:@aws-sdk/client-s3 AI (phantom-deps): Cloud SDK re-export pattern; stable for this package. ai
phantom-deps phantom-dep:@alicloud/openapi-util AI (phantom-deps): Cloud SDK re-export pattern; stable for this package. ai
phantom-deps phantom-dep:@kubernetes/client-node AI (phantom-deps): Cloud SDK re-export pattern; stable for this package. ai
phantom-deps phantom-dep:tencentcloud-sdk-nodejs AI (phantom-deps): Cloud SDK re-export pattern; stable for this package. ai
phantom-deps phantom-dep:@alicloud/openapi-client AI (phantom-deps): Cloud SDK re-export pattern; stable for this package. ai
phantom-deps phantom-dep:@alicloud/tea-util AI (phantom-deps): Cloud SDK re-export pattern; stable for this package. ai
phantom-deps phantom-dep:qiniu AI (phantom-deps): Cloud SDK re-export pattern; stable for this package. ai
phantom-deps phantom-dep:socks AI (phantom-deps): Cloud SDK re-export pattern; stable for this package. ai
phantom-deps phantom-dep:rimraf AI (phantom-deps): Cloud SDK re-export pattern; stable for this package. ai
phantom-deps phantom-dep:ali-oss AI (phantom-deps): Cloud SDK re-export pattern; stable for this package. ai
phantom-deps phantom-dep:basic-ftp AI (phantom-deps): Cloud SDK re-export pattern; stable for this package. ai
phantom-deps phantom-dep:iconv-lite AI (phantom-deps): Cloud SDK re-export pattern; stable for this package. ai

Versions (showing 51 of 98)

View all versions
Version Deps Published
1.41.1 25 / 15
1.41.0 25 / 15
1.40.5 25 / 15
1.40.4 25 / 15
1.40.3 25 / 15
1.40.2 25 / 15
1.40.1 25 / 15
1.40.0 25 / 15
1.39.16 25 / 15
1.39.14 25 / 15
1.39.13 25 / 15
1.39.12 25 / 12
1.39.11 25 / 12
1.39.10 25 / 12
1.39.9 25 / 12
1.39.8 25 / 12
1.39.7 25 / 12
1.39.6 25 / 12
1.39.5 25 / 12
1.39.4 25 / 12
1.39.3 25 / 12
1.39.2 25 / 12
1.39.1 25 / 12
1.39.0 25 / 12
1.38.12 25 / 12
1.38.11 25 / 12
1.38.10 25 / 12
1.38.9 25 / 12
1.38.8 25 / 12
1.38.7 25 / 12
1.38.6 25 / 12
1.38.5 25 / 12
1.38.4 25 / 12
1.38.3 25 / 12
1.38.2 25 / 12
1.38.1 25 / 12
1.38.0 25 / 12
1.37.17 21 / 12
1.37.16 21 / 12
1.37.15 21 / 12
1.37.14 21 / 12
1.37.13 21 / 12
1.37.12 21 / 12
1.37.11 21 / 12
1.37.10 21 / 12
1.37.9 21 / 12
1.37.8 21 / 12
1.37.7 21 / 12
1.37.6 21 / 12
1.37.5 21 / 12
1.37.4 21 / 12

v1.41.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.41.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.40.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.40.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.40.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.40.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.40.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.40.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.39.16

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.39.14

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.39.13

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.39.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.39.11

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.39.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.39.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.39.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.39.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.39.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.39.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.39.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.39.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.39.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.39.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.39.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.38.12

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.38.11

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.38.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.38.9

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.38.8

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.38.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.38.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.38.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.38.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.38.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.38.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.38.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.38.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.37.17

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.37.16

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.37.15

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.37.14

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.37.13

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.37.12

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.37.11

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.37.10

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.37.9

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.37.8

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.37.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.37.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.37.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.37.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.