urllib
Help in opening URLs (mostly HTTP) in a complex world — basic and digest authentication, redirections, timeout and more. Base undici API.
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:digest-header | AI (phantom-deps): digest-header is a declared dep referenced in config; phantom-dep heuristic fires as false positive for this package. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Reflect.get is used to access undici internal pool stats (kClients symbol) — a documented pattern for HTTP client pool introspection, not obfuscation or malicious API access. | ai |
Versions (showing 8 of 8)
| Version | Deps | Published |
|---|---|---|
| 4.9.0 | 7 / 28 | |
| 4.8.2 | 7 / 26 | |
| 4.8.1 | 7 / 26 | |
| 4.8.0 | 7 / 26 | |
| 4.7.1 | 7 / 26 | |
| 4.7.0 | 7 / 26 | |
| 4.6.12 | 7 / 26 | |
| 3.18.0 | 10 / 20 |
v4.8.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.8.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.8.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.7.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.7.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.6.12
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.18.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.