← Home

@subnoto/api-client

TypeScript SDK for Subnoto Public API

51
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

tidalfmikescops

Keywords

subnotoapiclienttypescript

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:index.cjs AI (source-diff): index.cjs is a standard minified bundler output (esbuild/rollup) for this TypeScript SDK; not obfuscation. ai
source-diff net-exec-file:index.cjs AI (source-diff): Network calls (openapi-fetch HTTP client) + new Function() in minified bundle are legitimate SDK patterns, not dropper behavior. ai
semgrep semgrep:base64-decode AI (semgrep): Fires in bundled ASN.1/PEM parser (unarmor method + base64 table); standard crypto parsing pattern, not malicious. ai
phantom-deps phantom-dep:tough-cookie AI (phantom-deps): tough-cookie is declared as a runtime dependency; phantom-dep heuristic false positive for this package. ai
semgrep semgrep:hex-decode AI (semgrep): Fires in minified bundle from bundled crypto/ASN.1 dependency; not malicious payload encoding. ai
semgrep semgrep:new-function-constructor AI (semgrep): Fires in minified bundle from bundled dependency; consistent with parser/template patterns in openapi-fetch or tough-cookie. ai

Versions (showing 51 of 98)

View all versions
Version Deps Published
2.16.1 2 / 1
2.16.0 2 / 1
2.15.6 2 / 1
2.15.5 2 / 1
2.15.4 2 / 1
2.15.3 2 / 1
2.15.2 2 / 1
2.15.1 2 / 1
2.15.0 2 / 1
2.14.9 2 / 1
2.14.8 2 / 1
2.14.7 2 / 1
2.14.6 2 / 1
2.14.5 2 / 1
2.14.4 2 / 1
2.14.3 2 / 1
2.14.2 2 / 1
2.14.1 2 / 1
2.14.0 2 / 1
2.13.7 2 / 1
2.13.6 2 / 1
2.13.5 2 / 1
2.13.4 2 / 1
2.13.3 2 / 1
2.13.2 2 / 1
2.13.1 2 / 1
2.13.0 2 / 1
2.12.7 2 / 1
2.12.6 2 / 1
2.12.5 2 / 1
2.12.4 2 / 1
2.12.3 2 / 1
2.12.2 2 / 1
2.12.1 2 / 1
2.12.0 2 / 1
2.11.2 2 / 1
2.11.1 2 / 1
2.11.0 2 / 1
2.10.0 2 / 1
2.9.9 2 / 1
2.9.8 2 / 1
2.9.7 2 / 1
2.9.6 2 / 1
2.9.5 2 / 1
2.9.4 2 / 1
2.9.3 2 / 1
2.9.2 2 / 1
2.9.1 2 / 1
2.9.0 2 / 1
2.8.1 2 / 1
2.8.0 2 / 1

v2.16.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.