@azure/core-rest-pipeline
Isomorphic client library for making HTTP requests in node.js and browser.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@typespec/ts-http-runtime | AI (dependencies): @typespec/ts-http-runtime is a Microsoft-owned TypeSpec HTTP runtime package, consistent with Azure SDK's TypeSpec migration. Legitimate dependency from the same organization. | ai | |
| provenance | publisher-changed | AI (provenance): Publisher change from azure-sdk to microsoft1es is a known Microsoft org-level transition; microsoft1es is a long-standing trusted Microsoft publishing account. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): microsoft1es is a well-established Microsoft publishing account (2941 approved packages); this is a legitimate organizational transition. | ai | |
| phantom-deps | phantom-dep:tslib | AI (phantom-deps): tslib is a standard TypeScript helper library declared as a dependency; implicit usage in compiled output is a well-known benign pattern for TypeScript packages. | ai | |
| provenance | no-provenance | AI (provenance): microsoft1es is a well-established Microsoft publisher; lack of Sigstore provenance is common and not a meaningful risk signal for this package. | ai |
Versions (showing 49 of 49)
| Version | Deps | Published |
|---|---|---|
| 1.23.0 | 7 / 13 | |
| 1.22.2 | 7 / 14 | |
| 1.22.1 | 7 / 10 | |
| 1.22.0 | 7 / 10 | |
| 1.21.0 | 7 / 10 | |
| 1.20.0 | 7 / 10 | |
| 1.19.1 | 8 / 10 | |
| 1.19.0 | 8 / 10 | |
| 1.18.2 | 8 / 10 | |
| 1.18.1 | 8 / 10 | |
| 1.18.0 | 8 / 10 | |
| 1.17.0 | 8 / 13 | |
| 1.16.3 | 8 / 13 | |
| 1.16.2 | 8 / 13 | |
| 1.16.1 | 8 / 13 | |
| 1.16.0 | 8 / 13 | |
| 1.15.2 | 8 / 14 | |
| 1.15.1 | 8 / 14 | |
| 1.15.0 | 8 / 14 | |
| 1.14.0 | 8 / 11 | |
| 1.13.0 | 8 / 33 | |
| 1.12.2 | 9 / 35 | |
| 1.12.1 | 9 / 34 | |
| 1.12.0 | 9 / 34 | |
| 1.11.0 | 9 / 34 | |
| 1.10.3 | 9 / 34 | |
| 1.10.2 | 10 / 36 | |
| 1.10.1 | 10 / 36 | |
| 1.10.0 | 10 / 36 | |
| 1.9.2 | 10 / 36 | |
| 1.9.1 | 10 / 36 | |
| 1.9.0 | 10 / 36 | |
| 1.8.1 | 10 / 36 | |
| 1.8.0 | 9 / 36 | |
| 1.7.0 | 9 / 36 | |
| 1.6.0 | 9 / 33 | |
| 1.5.0 | 9 / 33 | |
| 1.4.0 | 9 / 34 | |
| 1.3.2 | 9 / 35 | |
| 1.3.1 | 9 / 35 | |
| 1.3.0 | 9 / 35 | |
| 1.2.0 | 9 / 35 | |
| 1.1.1 | 9 / 34 | |
| 1.1.0 | 9 / 42 | |
| 1.0.4 | 9 / 42 | |
| 1.0.3 | 9 / 42 | |
| 1.0.2 | 10 / 41 | |
| 1.0.1 | 10 / 41 | |
| 1.0.0 | 9 / 41 |
v1.22.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.22.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.22.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.21.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.20.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.19.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.19.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.18.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.18.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.18.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.17.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.16.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.16.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.16.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.16.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.15.2
2 findingsThis version was published by a different npm account than previous versions on 2024-04-11. This could indicate a legitimate maintainer transition or an account compromise.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.15.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.15.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.14.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.13.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.12.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.12.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.12.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.11.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.8.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.8.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.