@pnpm/network.auth-header
Gets the authorization header for the given URI
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:child-process-import | AI (semgrep): child_process is used to spawn credential helper processes, a standard pattern in package managers like pnpm. Stable and expected for this package. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Base64 decode is used to decode _password from npm/pnpm config for Basic auth header construction per RFC 7617. Entirely legitimate for an auth-header package. | ai | |
| dependencies | unvetted-dep:@pnpm/config.nerf-dart | AI (dependencies): @pnpm/config.nerf-dart is a legitimate pnpm internal utility for nerf-dart URL conversion, used across the pnpm ecosystem. | ai |
Versions (showing 7 of 7)
| Version | Deps | Published |
|---|---|---|
| 1101.0.0 | 3 / 3 | |
| 1100.0.3 | 3 / 3 | |
| 1100.0.2 | 3 / 3 | |
| 1100.0.1 | 3 / 2 | |
| 1100.0.0 | 3 / 2 | |
| 1000.0.7 | 2 / 2 | |
| 1000.0.6 | 2 / 2 |
v1101.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1100.0.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1100.0.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1100.0.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1100.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1000.0.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1000.0.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.