@subnoto/api-client
TypeScript SDK for Subnoto Public API
51
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
tidalfmikescops
Keywords
subnotoapiclienttypescript
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:index.cjs | AI (source-diff): index.cjs is a standard minified bundler output (esbuild/rollup) for this TypeScript SDK; not obfuscation. | ai | |
| source-diff | net-exec-file:index.cjs | AI (source-diff): Network calls (openapi-fetch HTTP client) + new Function() in minified bundle are legitimate SDK patterns, not dropper behavior. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Fires in bundled ASN.1/PEM parser (unarmor method + base64 table); standard crypto parsing pattern, not malicious. | ai | |
| phantom-deps | phantom-dep:tough-cookie | AI (phantom-deps): tough-cookie is declared as a runtime dependency; phantom-dep heuristic false positive for this package. | ai | |
| semgrep | semgrep:hex-decode | AI (semgrep): Fires in minified bundle from bundled crypto/ASN.1 dependency; not malicious payload encoding. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): Fires in minified bundle from bundled dependency; consistent with parser/template patterns in openapi-fetch or tough-cookie. | ai |
Versions (showing 51 of 98)
| Version | Deps | Published |
|---|---|---|
| 2.16.1 | 2 / 1 | |
| 2.16.0 | 2 / 1 | |
| 2.15.6 | 2 / 1 | |
| 2.15.5 | 2 / 1 | |
| 2.15.4 | 2 / 1 | |
| 2.15.3 | 2 / 1 | |
| 2.15.2 | 2 / 1 | |
| 2.15.1 | 2 / 1 | |
| 2.15.0 | 2 / 1 | |
| 2.14.9 | 2 / 1 | |
| 2.14.8 | 2 / 1 | |
| 2.14.7 | 2 / 1 | |
| 2.14.6 | 2 / 1 | |
| 2.14.5 | 2 / 1 | |
| 2.14.4 | 2 / 1 | |
| 2.14.3 | 2 / 1 | |
| 2.14.2 | 2 / 1 | |
| 2.14.1 | 2 / 1 | |
| 2.14.0 | 2 / 1 | |
| 2.13.7 | 2 / 1 | |
| 2.13.6 | 2 / 1 | |
| 2.13.5 | 2 / 1 | |
| 2.13.4 | 2 / 1 | |
| 2.13.3 | 2 / 1 | |
| 2.13.2 | 2 / 1 | |
| 2.13.1 | 2 / 1 | |
| 2.13.0 | 2 / 1 | |
| 2.12.7 | 2 / 1 | |
| 2.12.6 | 2 / 1 | |
| 2.12.5 | 2 / 1 | |
| 2.12.4 | 2 / 1 | |
| 2.12.3 | 2 / 1 | |
| 2.12.2 | 2 / 1 | |
| 2.12.1 | 2 / 1 | |
| 2.12.0 | 2 / 1 | |
| 2.11.2 | 2 / 1 | |
| 2.11.1 | 2 / 1 | |
| 2.11.0 | 2 / 1 | |
| 2.10.0 | 2 / 1 | |
| 2.9.9 | 2 / 1 | |
| 2.9.8 | 2 / 1 | |
| 2.9.7 | 2 / 1 | |
| 2.9.6 | 2 / 1 | |
| 2.9.5 | 2 / 1 | |
| 2.9.4 | 2 / 1 | |
| 2.9.3 | 2 / 1 | |
| 2.9.2 | 2 / 1 | |
| 2.9.1 | 2 / 1 | |
| 2.9.0 | 2 / 1 | |
| 2.8.1 | 2 / 1 | |
| 2.8.0 | 2 / 1 |
v2.16.1
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.