node-opcua-client
pure nodejs OPCUA SDK - module client
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:underscore | AI (phantom-deps): Common utility lib, likely used in compiled dist not scanned source. | ai | |
| phantom-deps | phantom-dep:delayed | AI (phantom-deps): Runtime util used indirectly; heuristic false positive for this package. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Generates local self-signed cert via node-opcua-pki; documented, stable across versions. | ai | |
| provenance | publisher-changed | AI (provenance): Transition from erossignon to GitHub Actions CI/CD publishing; backed by SLSA provenance attestation. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Dormancy explained by CI/CD pipeline migration; SLSA attestation confirms legitimate publish. | ai | |
| bogus-package | bogus-package | AI (bogus-package): node-opcua monorepo legitimately produces 100+ same-named packages; not spam or phishing. | ai |
Versions (showing 19 of 219)
| Version | Deps | Published |
|---|---|---|
| 2.6.2 | 49 / 9 | |
| 2.6.1 | 49 / 9 | |
| 2.5.10 | 48 / 9 | |
| 2.5.9 | 48 / 9 | |
| 2.5.8 | 48 / 9 | |
| 2.5.7 | 48 / 9 | |
| 2.5.6 | 48 / 9 | |
| 2.5.1 | 48 / 9 | |
| 2.4.4 | 48 / 9 | |
| 2.4.2 | 48 / 9 | |
| 2.4.0 | 48 / 9 | |
| 2.3.0 | 48 / 9 | |
| 2.1.9 | 48 / 9 | |
| 2.1.8 | 48 / 9 | |
| 2.1.7 | 48 / 7 | |
| 2.1.6 | 48 / 7 | |
| 2.1.5 | 48 / 7 | |
| 2.1.1 | 47 / 7 | |
| 2.0.0 | 45 / 7 |
v2.6.2
2 findingsScript: node test_helpers/create_certificates.js certificate -s -o certificates/client_selfsigned_cert_2048.pem
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.6.1
2 findingsScript: node test_helpers/create_certificates.js certificate -s -o certificates/client_selfsigned_cert_2048.pem
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.5.10
2 findingsScript: node test_helpers/create_certificates.js certificate -s -o certificates/client_selfsigned_cert_2048.pem
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.5.9
2 findingsScript: node test_helpers/create_certificates.js certificate -s -o certificates/client_selfsigned_cert_2048.pem
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.5.8
2 findingsScript: node test_helpers/create_certificates.js certificate -s -o certificates/client_selfsigned_cert_2048.pem
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.5.7
2 findingsScript: node test_helpers/create_certificates.js certificate -s -o certificates/client_selfsigned_cert_2048.pem
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.5.6
2 findingsScript: node test_helpers/create_certificates.js certificate -s -o certificates/client_selfsigned_cert_2048.pem
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.5.1
2 findingsScript: node test_helpers/create_certificates.js certificate -s -o certificates/client_selfsigned_cert_2048.pem
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.4.4
2 findingsScript: node test_helpers/create_certificates.js certificate -s -o certificates/client_selfsigned_cert_2048.pem
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.4.2
2 findingsScript: node test_helpers/create_certificates.js certificate -s -o certificates/client_selfsigned_cert_2048.pem
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.4.0
2 findingsScript: node test_helpers/create_certificates.js certificate -s -o certificates/client_selfsigned_cert_2048.pem
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.3.0
2 findingsScript: node test_helpers/create_certificates.js certificate -s -o certificates/client_selfsigned_cert_2048.pem
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.9
2 findingsScript: node test_helpers/create_certificates.js certificate -s -o certificates/client_selfsigned_cert_2048.pem
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.8
2 findingsScript: node test_helpers/create_certificates.js certificate -s -o certificates/client_selfsigned_cert_2048.pem
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.7
2 findingsScript: node test_helpers/create_certificates.js certificate -s -o certificates/client_selfsigned_cert_2048.pem
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.6
2 findingsScript: node test_helpers/create_certificates.js certificate -s -o certificates/client_selfsigned_cert_2048.pem
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.5
2 findingsScript: node test_helpers/create_certificates.js certificate -s -o certificates/client_selfsigned_cert_2048.pem
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.1
2 findingsScript: node test_helpers/create_certificates.js certificate -s -o certificates/client_selfsigned_cert_2048.pem
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.0
2 findingsScript: node test_helpers/create_certificates.js certificate -s -o certificates/client_selfsigned_cert_2048.pem
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.