← Home

global-agent

Global HTTP/HTTPS proxy configurable using environment variables.

3
Versions
BSD-3-Clause
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

gajus

Keywords

httpglobalproxyagent

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:omit-undefined AI (dependencies): omit-undefined is a trivial utility dep; no malicious signals; stable for this package. ai
dependencies unvetted-dep:globalthis AI (dependencies): globalthis is a well-known polyfill package (part of the es-shims ecosystem) with no malicious history; unvetted flag is a system artifact. ai
dependencies unvetted-dep:serialize-error AI (dependencies): serialize-error is a well-known, widely-used npm package by Sindre Sorhus with no malicious history; unvetted flag is a system artifact. ai
dependencies unvetted-dep:matcher AI (dependencies): matcher is a well-known, widely-used npm package by Sindre Sorhus with no malicious history; unvetted flag is a system artifact, not a real risk. ai

Versions (showing 3 of 3)

Version Deps Published
4.1.3 4 / 28
4.0.0 7 / 34
3.0.0 6 / 25

v4.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.