global-agent
Global HTTP/HTTPS proxy configurable using environment variables.
3
Versions
BSD-3-Clause
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
gajus
Keywords
httpglobalproxyagent
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:omit-undefined | AI (dependencies): omit-undefined is a trivial utility dep; no malicious signals; stable for this package. | ai | |
| dependencies | unvetted-dep:globalthis | AI (dependencies): globalthis is a well-known polyfill package (part of the es-shims ecosystem) with no malicious history; unvetted flag is a system artifact. | ai | |
| dependencies | unvetted-dep:serialize-error | AI (dependencies): serialize-error is a well-known, widely-used npm package by Sindre Sorhus with no malicious history; unvetted flag is a system artifact. | ai | |
| dependencies | unvetted-dep:matcher | AI (dependencies): matcher is a well-known, widely-used npm package by Sindre Sorhus with no malicious history; unvetted flag is a system artifact, not a real risk. | ai |
v4.0.0
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.0.0
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.