@itentialopensource/adapter-akamai_property_manager
This adapter integrates with the Akamai Property Manager API.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-added | AI (maintainer-change): Itential org regularly adds/rotates maintainers; no malicious signal across 35 versions. | ai | |
| dependencies | unvetted-dep:mocha-param | AI (dependencies): Test dependency used across Itential adapter family; stable false positive for this package. | ai | |
| dependencies | unvetted-dep:akamai-edgegrid | AI (dependencies): Official Akamai EdgeGrid SDK; legitimate runtime dependency for this Akamai API adapter. | ai | |
| phantom-deps | phantom-dep:ping | AI (phantom-deps): Referenced in config files per phantom-dep finding; stable false positive for this adapter pattern. | ai | |
| install-scripts | install-script:preinstall | AI (install-scripts): Standard Itential adapter setup hook pattern; stable across all versions of this package family. | ai | |
| phantom-deps | phantom-dep:mocha-param | AI (phantom-deps): Referenced in config/test files; stable false positive for this adapter pattern. | ai | |
| phantom-deps | phantom-dep:prompts | AI (phantom-deps): Referenced in config files per phantom-dep finding; stable false positive for this adapter pattern. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Resolves fixed path (adapterBase.js); not arbitrary module loading. Consistent across Itential adapter pattern. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): Used for connectivity/healthcheck utilities in adapter base; documented operational pattern for Itential adapters. | ai |
Versions (showing 12 of 12)
| Version | Deps | Published |
|---|---|---|
| 1.0.3 | 16 / 6 | |
| 1.0.2 | 16 / 6 | |
| 1.0.1 | 16 / 6 | |
| 1.0.0 | 16 / 6 | |
| 0.9.5 | 16 / 6 | |
| 0.9.3 | 16 / 6 | |
| 0.9.2 | 16 / 6 | |
| 0.9.1 | 16 / 6 | |
| 0.9.0 | 16 / 6 | |
| 0.8.0 | 16 / 6 | |
| 0.7.1 | 16 / 6 | |
| 0.7.0 | 16 / 6 |
v1.0.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.2
2 findingsScript: node utils/setup.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1
2 findingsScript: node utils/setup.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.0
2 findingsScript: node utils/setup.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.5
2 findingsScript: node utils/setup.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.3
2 findingsScript: node utils/setup.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.2
2 findingsScript: node utils/setup.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.1
2 findingsScript: node utils/setup.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jared.obrien) than the most recent previously approved version (itential-ci) on 2026-02-13, but jared.obrien is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.8.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jared.obrien) than the most recent previously approved version (itential-ci) on 2025-12-19, but jared.obrien is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.7.1
2 findingsScript: node utils/setup.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.7.0
2 findingsScript: node utils/setup.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.