@ocap/client
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | encoded-string-file:dist/bundle.js | AI (source-diff): Standard webpack bundle output; long strings are minified polyfill/library code, not obfuscated payloads. | ai | |
| phantom-deps | phantom-dep:@ocap/tx-util | AI (phantom-deps): Same org scope (@ocap); declared as runtime dep, likely used transitively or in bundled output. | ai | |
| phantom-deps | phantom-dep:@ocap/tx-protocols | AI (phantom-deps): Same org scope (@ocap); declared as runtime dep, likely used transitively or in bundled output. | ai | |
| phantom-deps | phantom-dep:blueimp-md5 | AI (phantom-deps): Stable false positive for this package; used in browser bundle. | ai | |
| phantom-deps | phantom-dep:@arcblock/jwt | AI (phantom-deps): First-party dep declared in package.json; phantom-dep heuristic false positive. | ai | |
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): Raw IP (127.0.0.1) is a localhost fallback in examples/asset.js, not production network code. | ai | |
| phantom-deps | phantom-dep:react-app-polyfill | AI (phantom-deps): Browser polyfill dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:readable-stream | AI (phantom-deps): Node.js stream polyfill; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:buffer | AI (phantom-deps): Declared as runtime dep for browser polyfill; phantom-dep heuristic false positive for this package. | ai | |
| phantom-deps | phantom-dep:lodash | AI (phantom-deps): Stable false positive; lodash is a legitimate runtime dependency used transitively. | ai |
Versions (showing 51 of 65)
| Version | Deps | Published |
|---|---|---|
| 1.30.24 | 20 / 15 | |
| 1.30.23 | 20 / 15 | |
| 1.30.22 | 20 / 15 | |
| 1.30.21 | 20 / 15 | |
| 1.30.20 | 20 / 15 | |
| 1.30.19 | 20 / 15 | |
| 1.30.18 | 20 / 15 | |
| 1.30.17 | 20 / 15 | |
| 1.30.16 | 20 / 15 | |
| 1.30.15 | 20 / 15 | |
| 1.30.14 | 20 / 15 | |
| 1.30.13 | 20 / 15 | |
| 1.30.12 | 20 / 15 | |
| 1.30.11 | 20 / 15 | |
| 1.30.10 | 20 / 15 | |
| 1.30.9 | 20 / 15 | |
| 1.30.8 | 20 / 15 | |
| 1.30.7 | 20 / 15 | |
| 1.30.6 | 20 / 15 | |
| 1.30.5 | 20 / 15 | |
| 1.30.4 | 20 / 15 | |
| 1.30.3 | 20 / 15 | |
| 1.30.2 | 20 / 15 | |
| 1.30.1 | 20 / 15 | |
| 1.30.0 | 20 / 15 | |
| 1.29.27 | 20 / 18 | |
| 1.29.26 | 20 / 18 | |
| 1.29.25 | 20 / 18 | |
| 1.25.4 | 21 / 20 | |
| 1.25.3 | 21 / 20 | |
| 1.25.2 | 21 / 20 | |
| 1.25.1 | 21 / 20 | |
| 1.25.0 | 21 / 20 | |
| 1.24.9 | 21 / 20 | |
| 1.24.8 | 21 / 20 | |
| 1.24.7 | 21 / 20 | |
| 1.24.6 | 21 / 20 | |
| 1.24.5 | 21 / 20 | |
| 1.24.4 | 21 / 20 | |
| 1.24.3 | 21 / 20 | |
| 1.24.2 | 21 / 20 | |
| 1.24.1 | 21 / 20 | |
| 1.24.0 | 21 / 20 | |
| 1.23.1 | 21 / 20 | |
| 1.23.0 | 21 / 20 | |
| 1.22.3 | 21 / 20 | |
| 1.22.2 | 21 / 20 | |
| 1.22.1 | 21 / 20 | |
| 1.22.0 | 21 / 20 | |
| 1.21.3 | 21 / 20 | |
| 1.21.2 | 21 / 20 |
v1.30.24
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.30.23
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.30.22
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.30.21
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.30.20
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.30.19
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.30.18
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.30.17
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.30.16
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.30.15
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.30.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.30.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.30.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.30.11
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.30.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.30.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.30.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.30.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.30.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.30.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.30.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.30.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.30.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.30.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.30.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.29.27
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.29.26
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.29.25
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.25.4
2 findingsModified file contains 7 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.25.3
2 findingsModified file contains 7 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.25.2
2 findingsModified file contains 7 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.25.1
2 findingsModified file contains 7 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.25.0
2 findingsModified file contains 7 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.24.9
2 findingsModified file contains 7 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.24.8
2 findingsModified file contains 7 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.24.7
2 findingsModified file contains 7 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.24.6
2 findingsModified file contains 7 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.24.5
2 findingsModified file contains 7 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.24.4
2 findingsModified file contains 7 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.24.3
2 findingsModified file contains 7 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.24.2
2 findingsModified file contains 7 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.24.1
2 findingsModified file contains 7 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.24.0
2 findingsModified file contains 7 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.23.1
2 findingsModified file contains 7 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.23.0
2 findingsModified file contains 7 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.22.3
2 findingsModified file contains 7 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.22.2
2 findingsModified file contains 7 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.22.1
2 findingsModified file contains 7 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.22.0
2 findingsModified file contains 7 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.21.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.21.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.