@ocap/client
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | encoded-string-file:dist/bundle.js | AI (source-diff): Standard webpack bundle output; long strings are minified polyfill/library code, not obfuscated payloads. | ai | |
| phantom-deps | phantom-dep:@ocap/tx-util | AI (phantom-deps): Same org scope (@ocap); declared as runtime dep, likely used transitively or in bundled output. | ai | |
| phantom-deps | phantom-dep:@ocap/tx-protocols | AI (phantom-deps): Same org scope (@ocap); declared as runtime dep, likely used transitively or in bundled output. | ai | |
| phantom-deps | phantom-dep:blueimp-md5 | AI (phantom-deps): Stable false positive for this package; used in browser bundle. | ai | |
| phantom-deps | phantom-dep:@arcblock/jwt | AI (phantom-deps): First-party dep declared in package.json; phantom-dep heuristic false positive. | ai | |
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): Raw IP (127.0.0.1) is a localhost fallback in examples/asset.js, not production network code. | ai | |
| phantom-deps | phantom-dep:react-app-polyfill | AI (phantom-deps): Browser polyfill dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:readable-stream | AI (phantom-deps): Node.js stream polyfill; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:buffer | AI (phantom-deps): Declared as runtime dep for browser polyfill; phantom-dep heuristic false positive for this package. | ai | |
| phantom-deps | phantom-dep:lodash | AI (phantom-deps): Stable false positive; lodash is a legitimate runtime dependency used transitively. | ai |
Versions (showing 51 of 189)
| Version | Deps | Published |
|---|---|---|
| 1.30.24 | 20 / 15 | |
| 1.30.23 | 20 / 15 | |
| 1.30.22 | 20 / 15 | |
| 1.30.21 | 20 / 15 | |
| 1.30.20 | 20 / 15 | |
| 1.30.19 | 20 / 15 | |
| 1.30.18 | 20 / 15 | |
| 1.30.17 | 20 / 15 | |
| 1.30.16 | 20 / 15 | |
| 1.30.15 | 20 / 15 | |
| 1.30.14 | 20 / 15 | |
| 1.30.13 | 20 / 15 | |
| 1.30.12 | 20 / 15 | |
| 1.30.11 | 20 / 15 | |
| 1.30.10 | 20 / 15 | |
| 1.30.9 | 20 / 15 | |
| 1.30.8 | 20 / 15 | |
| 1.30.7 | 20 / 15 | |
| 1.30.6 | 20 / 15 | |
| 1.30.5 | 20 / 15 | |
| 1.30.4 | 20 / 15 | |
| 1.30.3 | 20 / 15 | |
| 1.30.2 | 20 / 15 | |
| 1.30.1 | 20 / 15 | |
| 1.30.0 | 20 / 15 | |
| 1.29.27 | 20 / 18 | |
| 1.29.26 | 20 / 18 | |
| 1.29.25 | 20 / 18 | |
| 1.29.24 | 20 / 18 | |
| 1.29.23 | 20 / 18 | |
| 1.29.22 | 20 / 18 | |
| 1.29.21 | 20 / 18 | |
| 1.29.20 | 20 / 18 | |
| 1.29.19 | 20 / 18 | |
| 1.29.18 | 20 / 18 | |
| 1.29.17 | 20 / 18 | |
| 1.29.16 | 20 / 18 | |
| 1.29.15 | 20 / 18 | |
| 1.29.14 | 20 / 18 | |
| 1.29.13 | 20 / 18 | |
| 1.29.12 | 20 / 18 | |
| 1.29.11 | 20 / 18 | |
| 1.29.10 | 20 / 18 | |
| 1.29.9 | 20 / 18 | |
| 1.29.8 | 20 / 18 | |
| 1.29.7 | 20 / 18 | |
| 1.29.6 | 20 / 18 | |
| 1.29.5 | 21 / 17 | |
| 1.29.4 | 21 / 17 | |
| 1.29.3 | 21 / 17 | |
| 1.29.2 | 21 / 17 |
v1.29.24
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.29.23
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.29.22
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.29.21
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.29.20
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.29.19
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.29.18
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.29.17
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.29.16
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.29.15
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.29.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.29.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.29.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.29.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.29.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.29.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.29.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.29.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.29.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.29.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.29.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.29.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.29.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.