@elastic/transport
Transport classes and utilities shared among Node.js Elastic client libraries
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Legitimate Elastic org maintainer rotation; SLSA provenance confirms CI/CD publish from elastic GitHub. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Elastic org-wide npm account cleanup; package still under @elastic scope with SLSA attestation. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): ikakavas is a known Elastic contributor with prior approved publishes. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Mature package with infrequent releases; dormancy is normal for stable transport libs. | ai | |
| provenance | slsa-provenance | AI (provenance): Elastic publishes via CI/CD with Sigstore attestation; stable supply chain signal for this package. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Base64 decoding in Serializer.js is legitimate deserialization of float32 vector binary data, not a malicious payload. Stable pattern for this package's serialization functionality. | ai |
Versions (showing 16 of 16)
| Version | Deps | Published |
|---|---|---|
| 9.3.6 | 8 / 20 | |
| 9.3.5 | 8 / 20 | |
| 9.3.4 | 8 / 20 | |
| 9.3.3 | 8 / 20 | |
| 9.3.2 | 8 / 20 | |
| 9.3.1 | 8 / 20 | |
| 9.3.0 | 8 / 19 | |
| 9.2.3 | 8 / 19 | |
| 9.2.2 | 8 / 19 | |
| 9.2.1 | 8 / 18 | |
| 9.2.0 | 8 / 18 | |
| 9.1.2 | 8 / 18 | |
| 9.1.1 | 8 / 18 | |
| 9.1.0 | 8 / 18 | |
| 9.0.2 | 7 / 18 | |
| 8.10.1 | 8 / 19 |
v9.3.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.3.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.3.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.3.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.3.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.3.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.3.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.2.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.2.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.2.1
2 findingsThis version was published by a different npm account than previous versions on 2025-10-24. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.2.0
2 findingsThis version was published by a different npm account than previous versions on 2025-09-29. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.1.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.1.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.1.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.0.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.10.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.