← Home

@libp2p/http-utils

3
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

daviddiasalanshawachingbrainvascosantosnpm-service-account-libp2pjacobheun

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): libp2p org migrated from npm-service-account to GitHub Actions CI publishing; SLSA provenance attestation confirms CI origin. ai
publish-pattern dormant-publish AI (publish-pattern): Dormancy followed by CI-published release with SLSA provenance; consistent with org-level tooling migration. ai
phantom-deps phantom-dep:readable-stream AI (phantom-deps): readable-stream is intentionally used as a browser polyfill for node:stream via the 'browser' field in package.json; dep-check explicitly ignores it. This is a stable, documented pattern for this package. ai

Versions (showing 3 of 3)

Version Deps Published
2.0.2 13 / 1
2.0.1 13 / 1
2.0.0 13 / 1

v2.0.2

2 findings
HIGH Publisher changed: npm-service-account-libp2p → GitHub Actions (on 2026-04-28) provenance

This version was published by a different npm account than previous versions on 2026-04-28. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.