nodemailer
Easy as cake e-mail sending from your Node.js applications
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:child-process-import | AI (semgrep): nodemailer's sendmail transport intentionally spawns the sendmail binary via child_process; this is documented functionality, not a malicious signal. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Base64 decoding is standard MIME email encoding/decoding functionality in nodemailer; no obfuscation or payload hiding present. | ai | |
| license | uncommon-license:MIT-0 | AI (license): MIT-0 is the intentional license chosen by nodemailer's author Andris Reinman; it is a valid public-domain-equivalent license, not a risk. | ai |
Versions (showing 6 of 6)
| Version | Deps | Published |
|---|---|---|
| 8.0.10 | 0 / 13 | |
| 8.0.9 | 0 / 13 | |
| 8.0.8 | 0 / 13 | |
| 8.0.7 | 0 / 13 | |
| 8.0.6 | 0 / 14 | |
| 8.0.5 | 0 / 14 |
v8.0.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.0.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.0.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.0.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.