@npmcli/agent
the http/https agent used by the npm cli
14
Versions
ISC
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
saquibkhannpm-cli-opsreggiowlstronaut
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:env-bulk-read | AI (semgrep): Code reads process.env only to extract a hardcoded set of 4 proxy env vars (https_proxy, http_proxy, proxy, no_proxy). This is the expected behavior for an HTTP agent respecting system proxy settings — stable false positive for this package. | ai |