← Home

node-opcua-client

pure nodejs OPCUA SDK - module client

19
Versions
MIT
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures gitHead linked

Maintainers

erossignon

Keywords

OPCUAopcuam2miotopc uainternet of things

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:underscore AI (phantom-deps): Common utility lib, likely used in compiled dist not scanned source. ai
phantom-deps phantom-dep:delayed AI (phantom-deps): Runtime util used indirectly; heuristic false positive for this package. ai
install-scripts install-script:postinstall AI (install-scripts): Generates local self-signed cert via node-opcua-pki; documented, stable across versions. ai
provenance publisher-changed AI (provenance): Transition from erossignon to GitHub Actions CI/CD publishing; backed by SLSA provenance attestation. ai
publish-pattern dormant-publish AI (publish-pattern): Dormancy explained by CI/CD pipeline migration; SLSA attestation confirms legitimate publish. ai
bogus-package bogus-package AI (bogus-package): node-opcua monorepo legitimately produces 100+ same-named packages; not spam or phishing. ai

Versions (showing 19 of 219)

Version Deps Published
2.6.2 49 / 9
2.6.1 49 / 9
2.5.10 48 / 9
2.5.9 48 / 9
2.5.8 48 / 9
2.5.7 48 / 9
2.5.6 48 / 9
2.5.1 48 / 9
2.4.4 48 / 9
2.4.2 48 / 9
2.4.0 48 / 9
2.3.0 48 / 9
2.1.9 48 / 9
2.1.8 48 / 9
2.1.7 48 / 7
2.1.6 48 / 7
2.1.5 48 / 7
2.1.1 47 / 7
2.0.0 45 / 7

v2.6.2

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: node test_helpers/create_certificates.js certificate -s -o certificates/client_selfsigned_cert_2048.pem

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.6.1

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: node test_helpers/create_certificates.js certificate -s -o certificates/client_selfsigned_cert_2048.pem

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.5.10

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: node test_helpers/create_certificates.js certificate -s -o certificates/client_selfsigned_cert_2048.pem

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.5.9

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: node test_helpers/create_certificates.js certificate -s -o certificates/client_selfsigned_cert_2048.pem

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.5.8

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: node test_helpers/create_certificates.js certificate -s -o certificates/client_selfsigned_cert_2048.pem

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.5.7

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: node test_helpers/create_certificates.js certificate -s -o certificates/client_selfsigned_cert_2048.pem

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.5.6

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: node test_helpers/create_certificates.js certificate -s -o certificates/client_selfsigned_cert_2048.pem

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.5.1

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: node test_helpers/create_certificates.js certificate -s -o certificates/client_selfsigned_cert_2048.pem

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.4.4

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: node test_helpers/create_certificates.js certificate -s -o certificates/client_selfsigned_cert_2048.pem

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.4.2

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: node test_helpers/create_certificates.js certificate -s -o certificates/client_selfsigned_cert_2048.pem

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.4.0

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: node test_helpers/create_certificates.js certificate -s -o certificates/client_selfsigned_cert_2048.pem

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.3.0

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: node test_helpers/create_certificates.js certificate -s -o certificates/client_selfsigned_cert_2048.pem

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.9

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: node test_helpers/create_certificates.js certificate -s -o certificates/client_selfsigned_cert_2048.pem

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.8

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: node test_helpers/create_certificates.js certificate -s -o certificates/client_selfsigned_cert_2048.pem

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.7

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: node test_helpers/create_certificates.js certificate -s -o certificates/client_selfsigned_cert_2048.pem

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.6

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: node test_helpers/create_certificates.js certificate -s -o certificates/client_selfsigned_cert_2048.pem

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.5

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: node test_helpers/create_certificates.js certificate -s -o certificates/client_selfsigned_cert_2048.pem

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.1

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: node test_helpers/create_certificates.js certificate -s -o certificates/client_selfsigned_cert_2048.pem

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.0

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: node test_helpers/create_certificates.js certificate -s -o certificates/client_selfsigned_cert_2048.pem

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.