← Home

@osdk/client

51
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

sauravsanjpalantirericandersonericjeney-palantir

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@osdk/foundry.functions AI (dependencies): Same-org Palantir OSDK sibling package, consistent with existing @osdk/foundry.* deps pattern. ai
provenance publisher-changed AI (provenance): Palantir org uses GitHub Actions for automated publishing; CI publisher is expected for this package. ai
maintainer-change maintainer-added AI (maintainer-change): Palantir org maintainer addition consistent with team growth; SLSA provenance confirms CI-controlled release. ai
source-diff large-new-source-files AI (source-diff): New internal-node entry point added; large file count is expected for a bundled CJS build. ai
source-diff obfuscated-file:build/cjs/public/internal-node.cjs AI (source-diff): Standard CJS bundle output from Palantir monorepo transpile step; long lines are minified but not obfuscated. ai
source-diff source-size-tripled AI (source-diff): Size increase explained by new internal-node bundle; consistent with monorepo release pattern. ai
publish-pattern new-deps-added AI (publish-pattern): @osdk/foundry.mediasets is a sibling Palantir package at matching version 2.44.0; expected coordinated release. ai
phantom-deps phantom-dep:fast-deep-equal AI (phantom-deps): Same monorepo pattern; stable false positive for this package. ai
phantom-deps phantom-dep:fetch-retry AI (phantom-deps): Palantir OSDK monorepo pattern; declared in package.json but resolved transitively — stable false positive. ai
npm-metadata no-description AI (npm-metadata): Palantir monorepo package; empty description is a consistent pattern across all @osdk/* packages. ai
phantom-deps phantom-dep:@types/geojson AI (phantom-deps): Type-only dep used for GeoJSON typings; not directly imported at runtime by design. ai
phantom-deps phantom-dep:ws AI (phantom-deps): ws is a declared runtime dep used via isomorphic-ws; phantom-dep heuristic fires incorrectly here. ai

Versions (showing 51 of 94)

View all versions
Version Deps Published
2.51.0 23 / 23
2.50.0 23 / 23
2.49.0 23 / 23
2.48.0 23 / 23
2.47.0 23 / 23
2.46.0 23 / 23
2.45.0 23 / 23
2.44.0 23 / 23
2.43.0 23 / 23
2.42.0 23 / 23
2.41.0 23 / 23
2.40.0 23 / 23
2.39.0 23 / 23
2.38.0 23 / 23
2.37.0 23 / 23
2.36.0 22 / 22
2.35.0 22 / 22
2.34.0 22 / 22
2.33.0 22 / 22
2.32.0 22 / 22
2.31.0 22 / 22
2.30.0 22 / 21
2.29.0 22 / 21
2.28.0 22 / 21
2.27.0 22 / 21
2.26.0 22 / 21
2.25.0 22 / 21
2.24.0 22 / 21
2.23.0 22 / 21
2.22.0 22 / 21
2.21.0 22 / 21
2.20.0 22 / 21
2.19.0 21 / 21
2.17.0 21 / 21
2.16.0 21 / 21
2.15.0 21 / 21
2.14.0 21 / 21
2.13.0 21 / 21
2.12.0 21 / 21
2.11.0 21 / 21
2.10.0 21 / 20
2.9.0 21 / 22
2.8.0 21 / 22
2.7.8 25 / 21
2.7.7 25 / 21
2.7.6 25 / 21
2.7.5 25 / 21
2.7.4 25 / 21
2.7.3 25 / 21
2.7.2 25 / 21
2.7.1 25 / 21

v2.51.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.50.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.49.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.48.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.47.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.46.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.45.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.44.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.43.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.42.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.41.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.7.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.7.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.7.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.7.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.7.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.7.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.7.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.