← Home

npm-registry-client

Client for the npm registry

51
Versions
ISC
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

iarnaisaacsothiym23zkat

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance no-provenance AI (provenance): Missing provenance is a best-practice gap, not a security defect; stable for this mature package. ai
phantom-deps phantom-dep:rimraf AI (phantom-deps): rimraf is legitimately declared and used indirectly in build/CLI context; stable pattern for this package. ai
phantom-deps phantom-dep:chownr AI (phantom-deps): chownr is legitimately declared and used indirectly in build/CLI context; stable pattern for this package. ai
phantom-deps phantom-dep:mkdirp AI (phantom-deps): mkdirp is legitimately declared and used indirectly in build/CLI context; stable pattern for this package. ai
maintainer-change maintainer-added AI (maintainer-change): Added maintainers (zkat, isaacs, othiym23) are well-known npm core contributors; this reflects the historical npm team roster, not a suspicious takeover. ai
semgrep semgrep:dynamic-require AI (semgrep): Dynamic require is used to load the client's own bundled API method files from a known directory — a stable architectural pattern in this package, not user-controlled input. ai
email-domain unclaimed-email:aoaioxxysz.net AI (email-domain): This is a historical maintainer email (ogd/isaacs) not the active publisher. Package is under the official npm GitHub org and published by zkat. Domain squatting risk is low given active npm-org stewardship. ai
publish-pattern new-deps-added AI (publish-pattern): ssri is a legitimate npm-org package for subresource integrity checking, entirely appropriate for an npm registry client. Not a suspicious dependency addition. ai
dependencies unvetted-dep:request AI (dependencies): request is a long-standing HTTP library dependency in this package; not a new or suspicious addition. ai
phantom-deps phantom-dep:graceful-fs AI (phantom-deps): graceful-fs is a legitimate declared dependency used transitively/conditionally in this registry client; not a security concern. ai
provenance publisher-changed AI (provenance): The zkat → iarna transition in 2018 was a legitimate maintainer handoff within the npm org. iarna is a well-established publisher; this is not a compromise signal. ai
bogus-package bogus-package AI (bogus-package): isaacs is Isaac Z. Schlueter, creator of npm — the spam flag is a false positive. No-keywords signal is trivial for this well-known package. ai
phantom-deps phantom-dep:safe-buffer AI (phantom-deps): safe-buffer is a legitimate declared dependency for Buffer compatibility; not a security concern. ai

Versions (showing 51 of 125)

View all versions
Version Deps Published
7.1.0 13 / 5
7.0.2 13 / 4
7.0.0 13 / 4
6.5.1 13 / 4
6.5.0 13 / 4
6.4.0 13 / 4
6.3.3 13 / 4
6.3.2 13 / 4
6.3.1 13 / 4
6.3.0 13 / 4
6.2.0 13 / 4
6.1.2 13 / 4
6.1.1 13 / 3
6.1.0 13 / 3
6.0.7 13 / 3
6.0.6 13 / 3
6.0.5 13 / 3
6.0.4 13 / 3
6.0.3 13 / 3
6.0.2 13 / 3
6.0.1 13 / 3
6.0.0 13 / 3
5.1.0 13 / 3
5.0.0 12 / 3
4.0.5 12 / 2
4.0.4 12 / 2
4.0.3 12 / 2
4.0.2 12 / 1
4.0.1 12 / 1
4.0.0 12 / 1
3.2.4 12 / 3
3.2.3 12 / 3
3.2.2 12 / 3
3.2.1 12 / 2
3.2.0 12 / 2
3.1.8 12 / 2
3.1.7 12 / 2
3.1.6 12 / 2
3.1.5 12 / 2
3.1.4 12 / 2
3.1.3 12 / 2
3.1.2 12 / 2
3.1.1 12 / 2
3.1.0 13 / 1
3.0.6 11 / 1
3.0.5 11 / 1
3.0.4 11 / 1
3.0.3 11 / 1
3.0.2 11 / 1
3.0.1 11 / 1
3.0.0 11 / 1

v7.1.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: othiym23 → iarna (on 2016-02-25) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2016-02-25. This could indicate a legitimate maintainer transition or an account compromise.

v7.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: othiym23 → zkat (on 2015-08-14) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2015-08-14. This could indicate a legitimate maintainer transition or an account compromise.