undici
An HTTP/1.1 client, written from scratch for Node.js
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:base64-decode | AI (semgrep): Base64 decoding is used to load the llhttp SIMD WebAssembly binary — a well-known legitimate pattern for this package, not obfuscation. | ai |
Versions (showing 51 of 193)
| Version | Deps | Published |
|---|---|---|
| 8.3.0 | 0 / 22 | |
| 8.2.0 | 0 / 22 | |
| 8.1.0 | 0 / 22 | |
| 8.0.3 | 0 / 22 | |
| 8.0.2 | 0 / 22 | |
| 8.0.1 | 0 / 22 | |
| 8.0.0 | 0 / 22 | |
| 7.26.0 | 0 / 22 | |
| 7.25.0 | 0 / 22 | |
| 7.24.8 | 0 / 22 | |
| 7.24.7 | 0 / 22 | |
| 7.24.6 | 0 / 22 | |
| 7.24.5 | 0 / 22 | |
| 7.24.4 | 0 / 22 | |
| 7.24.3 | 0 / 22 | |
| 7.24.2 | 0 / 22 | |
| 7.24.1 | 0 / 22 | |
| 7.24.0 | 0 / 22 | |
| 6.26.0 | 0 / 24 | |
| 6.25.0 | 0 / 24 | |
| 6.24.1 | 0 / 24 | |
| 6.24.0 | 0 / 24 | |
| 6.13.0 | 0 / 23 | |
| 6.12.0 | 0 / 23 | |
| 6.11.1 | 0 / 23 | |
| 6.11.0 | 0 / 23 | |
| 6.10.2 | 0 / 23 | |
| 6.10.1 | 0 / 23 | |
| 6.10.0 | 0 / 23 | |
| 6.9.0 | 0 / 23 | |
| 6.8.0 | 0 / 23 | |
| 6.7.1 | 0 / 22 | |
| 6.7.0 | 1 / 22 | |
| 6.6.2 | 1 / 39 | |
| 6.6.1 | 1 / 39 | |
| 6.6.0 | 1 / 39 | |
| 6.5.0 | 1 / 43 | |
| 6.4.0 | 1 / 43 | |
| 6.3.0 | 1 / 39 | |
| 6.2.1 | 1 / 37 | |
| 6.2.0 | 1 / 38 | |
| 6.1.0 | 1 / 38 | |
| 6.0.1 | 1 / 37 | |
| 6.0.0 | 1 / 37 | |
| 5.28.4 | 1 / 37 | |
| 5.28.3 | 1 / 37 | |
| 5.28.2 | 1 / 37 | |
| 5.28.1 | 1 / 37 | |
| 5.28.0 | 1 / 37 | |
| 5.27.2 | 1 / 36 | |
| 5.27.1 | 1 / 36 |
v8.3.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.2.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.0.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.0.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.0.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.26.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.25.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.24.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.24.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.24.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.24.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.24.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.24.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.24.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.24.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.24.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.26.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.25.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.24.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.24.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.