stream-chat
JS SDK for the Stream Chat API
51
Versions
SEE LICENSE IN LICENSE
License
Yes
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
tbarbuglitschellenbachvishtreestream-release-botvangalilea88zita.szuperacaleb.murphymartincupelalink512
Keywords
chatmessagingconversationreactstreamgetstreamgetstream.io
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| install-scripts | install-script:postinstall | AI (install-scripts): Conditional husky dev-hook setup, no network/exec; stable for this package. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Webhook signature verification in signing.ts; benign. | ai | |
| source-diff | net-exec-file:dist/browser.full-bundle.min.js | AI (source-diff): Bundled browser build output (Rollup+Babel); network+exec pattern is normal for a chat SDK's full bundle. | ai | |
| provenance | publisher-changed | AI (provenance): GetStream.io migrated from stream-release-bot to GitHub Actions OIDC publishing; SLSA attestation confirms legitimate CI/CD pipeline. This transition is stable for this package. | ai | |
| phantom-deps | phantom-dep:@types/jsonwebtoken | AI (phantom-deps): Intentional pattern for this isomorphic package; @types/jsonwebtoken is a type dependency needed for consumers. Stable false positive for this package. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Maintainer removal is consistent with organizational CI/CD migration to GitHub Actions; SLSA provenance attestation confirms legitimate publishing pipeline. | ai | |
| phantom-deps | phantom-dep:@types/ws | AI (phantom-deps): Intentional pattern for this isomorphic package; @types/ws is a type dependency needed for consumers. Stable false positive for this package. | ai |
Versions (showing 51 of 73)
| Version | Deps | Published |
|---|---|---|
| 9.50.1 | 9 / 23 | |
| 9.44.2 | 9 / 24 | |
| 9.44.1 | 9 / 24 | |
| 9.44.0 | 9 / 24 | |
| 9.43.2 | 9 / 24 | |
| 9.43.1 | 9 / 24 | |
| 9.43.0 | 9 / 24 | |
| 9.42.3 | 9 / 24 | |
| 9.42.2 | 9 / 24 | |
| 9.42.1 | 9 / 24 | |
| 9.42.0 | 9 / 24 | |
| 9.41.1 | 9 / 24 | |
| 9.41.0 | 9 / 24 | |
| 9.40.0 | 9 / 24 | |
| 9.39.0 | 9 / 24 | |
| 9.38.0 | 9 / 24 | |
| 9.37.0 | 9 / 24 | |
| 9.36.2 | 9 / 24 | |
| 9.36.1 | 9 / 24 | |
| 9.36.0 | 9 / 24 | |
| 9.35.1 | 9 / 24 | |
| 9.35.0 | 9 / 24 | |
| 9.34.0 | 9 / 24 | |
| 9.33.0 | 9 / 24 | |
| 9.32.0 | 9 / 24 | |
| 9.31.0 | 9 / 24 | |
| 9.30.1 | 9 / 24 | |
| 9.30.0 | 9 / 24 | |
| 9.29.0 | 9 / 24 | |
| 9.28.0 | 9 / 24 | |
| 9.27.2 | 9 / 24 | |
| 9.27.1 | 9 / 24 | |
| 9.27.0 | 9 / 24 | |
| 9.26.1 | 9 / 24 | |
| 9.26.0 | 9 / 24 | |
| 9.25.0 | 9 / 24 | |
| 9.24.0 | 9 / 24 | |
| 9.23.0 | 9 / 24 | |
| 9.22.1 | 9 / 24 | |
| 9.22.0 | 9 / 24 | |
| 9.21.0 | 9 / 24 | |
| 9.20.3 | 9 / 24 | |
| 9.20.2 | 9 / 24 | |
| 9.20.1 | 9 / 24 | |
| 9.20.0 | 9 / 24 | |
| 9.19.1 | 9 / 24 | |
| 9.19.0 | 9 / 24 | |
| 9.18.1 | 9 / 24 | |
| 9.18.0 | 9 / 24 | |
| 9.17.0 | 9 / 24 | |
| 9.16.0 | 9 / 24 |
v9.50.1
2 findings
HIGH
Package has 'postinstall' script
install-scripts
Script: node -e "require('fs').existsSync('scripts/install-husky.mjs') && import('./scripts/install-husky.mjs')"
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.