← Home

@sudoplatform/sudo-secure-communications

The Secure Communications SDK allows you to offer your users' secure communications while preserving their privacy. Please see the [Sudo Platform Developer Docs](https://docs.sudoplatform.com/guides/securecommunications) for an overview of Secure Communic

8
Versions
Apache-2.0
License
Yes
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

neilreadshawtbartleysudoplatform-engineeringbkchy

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:aws-appsync AI (dependencies): Established AWS AppSync client, consistent with Sudoplatform's AWS-based backend. ai
publish-pattern new-deps-added AI (publish-pattern): Baseline diff vs stale v0.0.1; deps reflect legitimate SDK growth over many unimported releases. ai
source-diff large-new-source-files AI (source-diff): Vendored matrix-js-sdk bundle explains large file count/size, not injected code. ai
provenance publisher-changed AI (provenance): Publisher changed to GitHub Actions CI/CD with SLSA provenance attestation; consistent with legitimate automation migration for sudoplatform org. ai
phantom-deps phantom-dep:redux AI (phantom-deps): State management library referenced in config; stable false positive for this package. ai
phantom-deps phantom-dep:fflate AI (phantom-deps): Compression library referenced in config; stable false positive. ai
phantom-deps phantom-dep:lodash AI (phantom-deps): Utility library referenced in config; stable false positive. ai
phantom-deps phantom-dep:monocle-ts AI (phantom-deps): Optics library referenced in config; stable false positive. ai
phantom-deps phantom-dep:newtype-ts AI (phantom-deps): Type utility referenced in config; stable false positive. ai
install-scripts install-script:postinstall AI (install-scripts): postinstall runs patch-package, a standard patching utility with no arbitrary code execution risk. ai
phantom-deps phantom-dep:@matrix-org/matrix-sdk-crypto-wasm AI (phantom-deps): Platform-specific binary package; phantom-dep heuristic is a known false positive for WASM packages. ai
phantom-deps phantom-dep:@aws-sdk/lib-storage AI (phantom-deps): AWS SDK framework-scoped package; stable false positive. ai
phantom-deps phantom-dep:@aws-sdk/credential-provider-cognito-identity AI (phantom-deps): AWS SDK framework-scoped package; stable false positive. ai
phantom-deps phantom-dep:@types/md5 AI (phantom-deps): Type definitions package; stable false positive. ai
phantom-deps phantom-dep:async-mutex AI (phantom-deps): Mutex utility referenced in config; stable false positive. ai
phantom-deps phantom-dep:patch-package AI (phantom-deps): patch-package is used in postinstall script; phantom-dep heuristic is a false positive here. ai
phantom-deps phantom-dep:postinstall-postinstall AI (phantom-deps): postinstall-postinstall is a known helper for chaining postinstall scripts; false positive. ai
phantom-deps phantom-dep:fp-ts AI (phantom-deps): Functional programming library likely used transitively or in bundled output; stable false positive. ai

Versions (showing 8 of 8)

Version Deps Published
5.5.2 24 / 43
5.5.1 24 / 43
5.5.0 24 / 43
5.4.0 24 / 43
5.3.2 24 / 43
5.2.2 24 / 43
5.0.1 27 / 44
0.0.1 0 / 0

v5.2.2

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: sudoplatform-engineering → GitHub Actions (on 2026-02-03, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sudoplatform-engineering) on 2026-02-03, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v5.0.1

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: sudoplatform-engineering → GitHub Actions (on 2025-11-19, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sudoplatform-engineering) on 2025-11-19, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.