← Home

feedr

Use feedr to fetch the data from a remote url, respect its caching, and parse its data. Despite its name, it's not just for feed data but also for all data that you can feed into it (including binary data).

40
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

baluptonbevryme

Keywords

feedsrssxmlatomrdfjsonjsonpcsonrequestsuperagentdownloadurlcache

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): bevry→bevryme is the same Bevry organization (Benjamin Lupton); account rename/transition confirmed by package.json author/repo metadata. Change occurred in 2018; publisher has strong track record. ai
maintainer-change maintainer-removed AI (maintainer-change): bevry account removed as part of org account rename/transition to bevryme; same organization. ai
maintainer-change maintainer-added AI (maintainer-change): bevryme is the same Bevry org as bevry; legitimate account transition, not a takeover. ai
publish-pattern new-deps-added AI (publish-pattern): get-port is a well-known, benign utility package; also flagged as phantom dep (not directly imported in source). No malicious indicators. ai
dependencies unvetted-dep:request AI (dependencies): request is a well-known, widely-used HTTP library that has been a stable dependency of feedr for many versions. While deprecated, it poses no malicious risk. ai
semgrep semgrep:dynamic-require AI (semgrep): Dynamic require loads from a fixed local './plugins/' path; plugin name comes from user config, not external attacker input. Standard plugin-loading pattern for this package. ai
phantom-deps phantom-dep:get-port AI (phantom-deps): get-port is listed in dependencies and used in test infrastructure; not directly imported in main source. Stable false positive for this package. ai
phantom-deps phantom-dep:cson AI (phantom-deps): cson is listed in dependencies and used as a feed format parser; not directly imported in main index but used via plugin/format handling. Stable false positive for this package. ai

Versions (showing 40 of 40)

Version Deps Published
4.8.0 12 / 10
4.7.0 12 / 10
4.6.0 12 / 10
4.1.0 12 / 10
3.0.0 12 / 7
2.13.5 12 / 7
2.13.4 12 / 7
2.13.3 12 / 8
2.13.2 12 / 8
2.13.1 12 / 8
2.13.0 12 / 8
2.12.0 12 / 5
2.11.1 12 / 5
2.11.0 12 / 5
2.10.4 12 / 5
2.10.3 12 / 5
2.10.2 12 / 5
2.10.1 12 / 5
2.10.0 12 / 5
2.9.1 10 / 5
2.9.0 10 / 5
2.8.0 10 / 5
2.7.7 10 / 5
2.7.6 10 / 5
2.7.5 10 / 5
2.7.4 10 / 5
2.7.3 10 / 5
2.7.2 9 / 4
2.7.1 9 / 4
2.7.0 9 / 4
2.6.0 8 / 4
2.5.1 8 / 4
2.5.0 7 / 4
2.4.4 7 / 4
2.4.3 2 / 2
2.4.2 2 / 2
2.4.1 2 / 2
2.4.0 2 / 2
2.3.0 3 / 2
2.2.0 3 / 2

v4.8.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.0.0

2 findings
HIGH Publisher changed: bevry → bevryme (on 2018-01-26) provenance

This version was published by a different npm account than previous versions on 2018-01-26. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.