@sudoplatform/sudo-secure-communications
The Secure Communications SDK allows you to offer your users' secure communications while preserving their privacy. Please see the [Sudo Platform Developer Docs](https://docs.sudoplatform.com/guides/securecommunications) for an overview of Secure Communic
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:aws-appsync | AI (dependencies): Established AWS AppSync client, consistent with Sudoplatform's AWS-based backend. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): Baseline diff vs stale v0.0.1; deps reflect legitimate SDK growth over many unimported releases. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Vendored matrix-js-sdk bundle explains large file count/size, not injected code. | ai | |
| provenance | publisher-changed | AI (provenance): Publisher changed to GitHub Actions CI/CD with SLSA provenance attestation; consistent with legitimate automation migration for sudoplatform org. | ai | |
| phantom-deps | phantom-dep:redux | AI (phantom-deps): State management library referenced in config; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:fflate | AI (phantom-deps): Compression library referenced in config; stable false positive. | ai | |
| phantom-deps | phantom-dep:lodash | AI (phantom-deps): Utility library referenced in config; stable false positive. | ai | |
| phantom-deps | phantom-dep:monocle-ts | AI (phantom-deps): Optics library referenced in config; stable false positive. | ai | |
| phantom-deps | phantom-dep:newtype-ts | AI (phantom-deps): Type utility referenced in config; stable false positive. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): postinstall runs patch-package, a standard patching utility with no arbitrary code execution risk. | ai | |
| phantom-deps | phantom-dep:@matrix-org/matrix-sdk-crypto-wasm | AI (phantom-deps): Platform-specific binary package; phantom-dep heuristic is a known false positive for WASM packages. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/lib-storage | AI (phantom-deps): AWS SDK framework-scoped package; stable false positive. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/credential-provider-cognito-identity | AI (phantom-deps): AWS SDK framework-scoped package; stable false positive. | ai | |
| phantom-deps | phantom-dep:@types/md5 | AI (phantom-deps): Type definitions package; stable false positive. | ai | |
| phantom-deps | phantom-dep:async-mutex | AI (phantom-deps): Mutex utility referenced in config; stable false positive. | ai | |
| phantom-deps | phantom-dep:patch-package | AI (phantom-deps): patch-package is used in postinstall script; phantom-dep heuristic is a false positive here. | ai | |
| phantom-deps | phantom-dep:postinstall-postinstall | AI (phantom-deps): postinstall-postinstall is a known helper for chaining postinstall scripts; false positive. | ai | |
| phantom-deps | phantom-dep:fp-ts | AI (phantom-deps): Functional programming library likely used transitively or in bundled output; stable false positive. | ai |
Versions (showing 8 of 8)
| Version | Deps | Published |
|---|---|---|
| 5.5.2 | 24 / 43 | |
| 5.5.1 | 24 / 43 | |
| 5.5.0 | 24 / 43 | |
| 5.4.0 | 24 / 43 | |
| 5.3.2 | 24 / 43 | |
| 5.2.2 | 24 / 43 | |
| 5.0.1 | 27 / 44 | |
| 0.0.1 | 0 / 0 |
v5.2.2
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sudoplatform-engineering) on 2026-02-03, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v5.0.1
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sudoplatform-engineering) on 2025-11-19, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.