← Home

make-fetch-happen

Opinionated, caching, retrying fetch client

9
Versions
ISC
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

saquibkhannpm-cli-opsreggiowlstronaut

Keywords

httprequestfetchmean girlscachingcachesubresource integrity

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:ssri AI (dependencies): ssri is an npm-org maintained package; unvetted status reflects pipeline lag, not a security concern for this well-known npm package. ai
dependencies unvetted-dep:cacache AI (dependencies): cacache is an npm-org maintained package; unvetted status reflects pipeline lag, not a security concern. ai
dependencies unvetted-dep:proc-log AI (dependencies): proc-log is an npm-org maintained package; unvetted status reflects pipeline lag, not a security concern. ai
dependencies unvetted-dep:@npmcli/agent AI (dependencies): @npmcli/agent is an npm-org maintained package; unvetted status reflects pipeline lag, not a security concern. ai
dependencies unvetted-dep:@npmcli/redact AI (dependencies): @npmcli/redact is an npm-org maintained package; unvetted status reflects pipeline lag, not a security concern. ai
dependencies unvetted-dep:minipass-fetch AI (dependencies): minipass-fetch is an npm-org maintained package; unvetted status reflects pipeline lag, not a security concern. ai
dependencies unvetted-dep:minipass-flush AI (dependencies): minipass-flush is a well-established minipass ecosystem package; unvetted status reflects pipeline lag, not a security concern. ai
dependencies unvetted-dep:minipass-pipeline AI (dependencies): minipass-pipeline is a well-established minipass ecosystem package; unvetted status reflects pipeline lag, not a security concern. ai
dependencies unvetted-dep:@gar/promise-retry AI (dependencies): @gar/promise-retry is a well-known retry utility used across the npm ecosystem; unvetted status reflects pipeline lag. ai
dependencies unvetted-dep:http-cache-semantics AI (dependencies): http-cache-semantics is a well-established HTTP caching library; unvetted status reflects pipeline lag, not a security concern. ai

Versions (showing 9 of 9)

Version Deps Published
16.0.1 12 / 6
16.0.0 12 / 6
15.0.6 12 / 6
15.0.5 12 / 6
15.0.4 11 / 6
15.0.3 11 / 6
15.0.2 11 / 6
15.0.1 11 / 6
15.0.0 11 / 6

v16.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v16.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v15.0.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v15.0.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v15.0.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v15.0.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v15.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v15.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.