← Home

@zero-transfer/sdk

Unified TypeScript file transfer SDK for Node.js

3
Versions
MIT
License
Yes
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

molex222

Keywords

ftpftpssftpzero-transferclientsdktypescriptfile-transfermftwebdavs3uploaddownloadstreams

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
install-scripts install-script:postinstall AI (install-scripts): Monorepo workspace-link pattern; ENOENT-guarded, only runs if scripts/link-sdk.mjs exists, no network or shell exec of external code. ai

Versions (showing 3 of 3)

Version Deps Published
0.1.6 1 / 12
0.1.5 1 / 12
0.1.3 1 / 12

v0.1.6

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: node -e "try{require('node:fs').accessSync('scripts/link-sdk.mjs');require('node:child_process').execSync('node scripts/link-sdk.mjs',{stdio:'inherit'})}catch(e){if(e.code!=='ENOENT')process.exit(1)}"

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.