← Home

@jupyterlab/services

Client APIs for the Jupyter services REST APIs

51
Versions
BSD-3-Clause
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

darianblink1073jasongroutfcollonvaljtpiombektaskrassowskijupyterlab-release-bot

Keywords

jupyternotebookservices

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:ws AI (phantom-deps): ws is a legitimate runtime dependency used for WebSocket support; phantom-dep fires due to dynamic/conditional import patterns in this isomorphic library. ai
phantom-deps phantom-dep:node-fetch AI (phantom-deps): node-fetch is loaded via eval('require')('node-fetch') to avoid bundler inclusion; static analysis cannot detect this dynamic import. Legitimate runtime dependency. ai
semgrep semgrep:eval-usage AI (semgrep): eval('require') is a hardcoded static string used to conditionally load node-fetch in Node.js environments without bundler interference — a well-known legitimate isomorphic pattern with no dynamic input. ai
phantom-deps phantom-dep:@types/text-encoding AI (phantom-deps): Type-only package used for TypeScript compilation; not directly imported at runtime is expected behavior for @types packages. ai
provenance no-provenance AI (provenance): This is a legacy version predating npm provenance attestation; absence is expected and not a risk signal for this well-established package. ai
dependencies unvetted-dep:@types/text-encoding AI (dependencies): @types/text-encoding is a TypeScript type definition package with no runtime code; it poses no security risk for this package. ai
phantom-deps phantom-dep:@types/minimist AI (phantom-deps): @types/minimist as a runtime dep is a harmless quirk of older TypeScript project conventions; no security implication. ai
dependencies unvetted-dep:phosphor AI (dependencies): phosphor was the official predecessor UI framework for JupyterLab; its use in early @jupyterlab/services versions is expected and legitimate. ai
provenance publisher-changed AI (provenance): Migration from jupyterlab-release-bot to GitHub Actions OIDC publishing with SLSA provenance; legitimate CI/CD infrastructure change for the JupyterLab project. ai
dependencies unvetted-dep:@jupyterlab/coreutils AI (dependencies): Known JupyterLab sibling package; expected dependency for @jupyterlab/services. ai
bogus-package bogus-package AI (bogus-package): Inflated semver is expected for JupyterLab monorepo packages published at their monorepo version. README signal is a false positive for this legitimate Project Jupyter package. ai
dependencies unvetted-dep:@jupyterlab/settingregistry AI (dependencies): Known JupyterLab sibling package; expected dependency for @jupyterlab/services. ai
dependencies unvetted-dep:@jupyter/ydoc AI (dependencies): Known JupyterLab ecosystem dependency; expected transitive dep for this package. ai
dependencies unvetted-dep:@lumino/polling AI (dependencies): Known Lumino ecosystem dependency; expected for @jupyterlab/services. ai
dependencies unvetted-dep:@lumino/coreutils AI (dependencies): Known Lumino ecosystem dependency; expected for @jupyterlab/services. ai
dependencies unvetted-dep:@lumino/signaling AI (dependencies): Known Lumino ecosystem dependency; expected for @jupyterlab/services. ai
dependencies unvetted-dep:@lumino/disposable AI (dependencies): Known Lumino ecosystem dependency; expected for @jupyterlab/services. ai
dependencies unvetted-dep:@lumino/properties AI (dependencies): Known Lumino ecosystem dependency; expected for @jupyterlab/services. ai
dependencies unvetted-dep:@jupyterlab/statedb AI (dependencies): Known JupyterLab sibling package; expected dependency for @jupyterlab/services. ai
dependencies unvetted-dep:@jupyterlab/nbformat AI (dependencies): Known JupyterLab sibling package; expected dependency for @jupyterlab/services. ai

Versions (showing 51 of 216)

View all versions
Version Deps Published
7.5.7 11 / 8
7.5.6 11 / 8
7.5.5 11 / 8
7.5.4 11 / 8
7.5.3 11 / 8
7.5.2 11 / 8
7.5.1 11 / 8
7.5.0 11 / 8
7.4.10 11 / 8
7.4.9 11 / 8
7.4.8 11 / 8
7.4.7 11 / 8
7.4.6 11 / 8
7.4.5 11 / 8
7.4.4 11 / 8
7.4.3 11 / 8
7.4.2 11 / 8
7.4.1 11 / 8
7.4.0 11 / 8
7.3.8 11 / 8
7.3.7 11 / 8
7.3.6 11 / 8
7.3.5 11 / 8
7.3.4 11 / 8
7.3.3 11 / 8
7.3.2 11 / 8
7.3.1 11 / 8
7.3.0 11 / 8
7.2.7 11 / 8
7.2.6 11 / 8
7.2.5 11 / 8
7.2.4 11 / 8
7.2.3 11 / 8
7.2.2 11 / 8
7.2.1 11 / 8
7.2.0 11 / 8
7.1.8 11 / 9
7.1.7 11 / 9
7.1.6 11 / 9
7.1.5 11 / 9
7.1.4 11 / 9
7.1.3 11 / 9
7.1.2 11 / 9
7.1.1 11 / 9
7.1.0 11 / 9
7.0.13 11 / 9
7.0.12 11 / 9
7.0.11 11 / 9
7.0.10 11 / 9
7.0.9 11 / 9
7.0.8 11 / 9

v7.5.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.5.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.5.5

2 findings
HIGH Publisher changed: jupyterlab-release-bot → GitHub Actions (on 2026-02-23) provenance

This version was published by a different npm account than previous versions on 2026-02-23. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.5.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.5.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.5.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.5.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.5.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.4.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.4.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.4.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.4.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.4.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.4.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.4.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.4.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.4.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.4.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.4.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.3.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.3.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.3.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.3.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.3.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.3.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.3.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.3.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.2.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.2.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.2.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.2.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.2.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.2.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.2.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.1.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.1.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.1.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.1.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.1.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.1.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.1.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.0.13

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.0.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.0.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.0.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.0.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.