← Home

@lokalise/backend-http-client

Opinionated HTTP client for the Node.js backend

12
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

bodrovismarcocardosolokbotlokalisekibertoadcarlos_gameroaplokalisefilippos.mikropoulosandrew_lokalisedariacmbezlydmitrycasamitjanabartoszdrozd-lokalisejhfedzerikapalillontrpilot-lokalise

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): GitHub Actions publish flow with SLSA provenance replaces gitHead; expected after CI migration. ai
provenance publisher-changed AI (provenance): Org migrated publishing to GitHub Actions CI/CD with SLSA attestation; not a takeover signal. ai
maintainer-change maintainer-removed AI (maintainer-change): Removal of human maintainer consistent with org-level shift to automated CI publishing. ai
dependencies unvetted-dep:undici-retry AI (dependencies): undici-retry is a known retry wrapper for undici; expected dep for this HTTP client package. ai

Versions (showing 12 of 12)

Version Deps Published
12.0.0 2 / 11
11.2.0 2 / 11
11.1.0 2 / 11
11.0.0 2 / 11
10.3.1 3 / 11
10.3.0 3 / 11
10.2.0 3 / 11
10.1.0 2 / 11
10.0.3 2 / 11
10.0.2 2 / 11
10.0.1 2 / 11
10.0.0 2 / 10

v12.0.0

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.