← Home

acme-client

1
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

nmorsman

Keywords

acmeclientletsencryptacmev2boulder

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:hex-decode AI (semgrep): Hex decoding is used for ASN.1 OctetString construction in ACME TLS-ALPN-01 challenge (RFC 8737). Standard cryptographic protocol implementation, not malicious. ai
semgrep semgrep:base64-decode AI (semgrep): Base64 decoding is used to decode an HMAC key for JWS signing in ACME EAB. Standard cryptographic usage, not malicious. ai

Versions (showing 1 of 1)

Version Deps Published
5.4.0 5 / 10