@rpcbase/client
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): CI/CD publisher for monorepo package, consistent with wireit release pipeline. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): Well-known libs (pouchdb, sonner) added for legitimate feature growth across many skipped versions. | ai |
Versions (showing 51 of 145)
| Version | Deps | Published |
|---|---|---|
| 0.471.0 | 6 / 2 | |
| 0.470.0 | 6 / 2 | |
| 0.469.0 | 6 / 2 | |
| 0.468.0 | 6 / 2 | |
| 0.467.0 | 6 / 2 | |
| 0.466.0 | 6 / 2 | |
| 0.465.0 | 6 / 2 | |
| 0.464.0 | 6 / 2 | |
| 0.463.0 | 6 / 2 | |
| 0.462.0 | 6 / 2 | |
| 0.461.0 | 6 / 2 | |
| 0.460.0 | 6 / 2 | |
| 0.459.0 | 6 / 2 | |
| 0.458.0 | 6 / 2 | |
| 0.457.0 | 6 / 2 | |
| 0.440.0 | 6 / 2 | |
| 0.401.0 | 6 / 2 | |
| 0.400.0 | 6 / 2 | |
| 0.399.0 | 6 / 2 | |
| 0.398.0 | 6 / 2 | |
| 0.397.0 | 6 / 2 | |
| 0.396.0 | 6 / 2 | |
| 0.395.0 | 6 / 2 | |
| 0.394.0 | 6 / 2 | |
| 0.393.0 | 6 / 2 | |
| 0.392.0 | 6 / 2 | |
| 0.391.0 | 6 / 2 | |
| 0.390.0 | 6 / 2 | |
| 0.389.0 | 6 / 2 | |
| 0.388.0 | 6 / 2 | |
| 0.387.0 | 6 / 2 | |
| 0.386.0 | 6 / 2 | |
| 0.385.0 | 6 / 2 | |
| 0.384.0 | 6 / 2 | |
| 0.383.0 | 6 / 2 | |
| 0.382.0 | 6 / 2 | |
| 0.381.0 | 6 / 2 | |
| 0.380.0 | 6 / 2 | |
| 0.379.0 | 6 / 2 | |
| 0.378.0 | 6 / 2 | |
| 0.377.0 | 6 / 2 | |
| 0.376.0 | 6 / 2 | |
| 0.375.0 | 6 / 2 | |
| 0.374.0 | 6 / 2 | |
| 0.373.0 | 6 / 2 | |
| 0.372.0 | 6 / 2 | |
| 0.371.0 | 6 / 2 | |
| 0.370.0 | 6 / 2 | |
| 0.369.0 | 6 / 2 | |
| 0.368.0 | 6 / 2 | |
| 0.367.0 | 6 / 2 |
v0.471.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.470.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.469.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.468.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.467.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.466.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.465.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.464.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.463.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.462.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.461.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.460.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.459.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.458.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.457.0
2 findingsThis version was published by a different npm account than previous versions on 2026-07-10. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.440.0
2 findingsThis version was published by a different npm account than previous versions on 2026-06-29. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.