Observed Signal · Apr 26, 2026 · Supply Chain Audit · Source: DEV Community · Impact: 3/5 · Sentiment: Negative
Anthropic SDK Safe—but Two Transitive Deps Are Risky
A supply‑chain audit of the @anthropic-ai/sdk package shows the SDK itself scores healthy, but two transitive runtime dependencies present critical risks. json-schema-to-ts is a runtime dependency with a single maintainer and ~15M weekly downloads; its child dependency ts-algebra also has a sole maintainer and no release in 12+ months. The article argues standard tools like npm audit miss behavioral risk signals (single maintainer, high-download, low-maintenance) and demonstrates a depth‑2 dependency scan using the open-source Commit supply chain scanner (getcommit.dev/audit). The author recommends visibility (pinning versions, monitoring activity) rather than immediate removal and provides scan examples and curl/MCP usage for mapping dependency‑tree risk to depth 2.
Software supply‑chain issues in widely used SDKs can create high-impact attack surfaces for many production apps; visibility into transitive dependencies is operationally important but this is not a major platform policy or earnings event.
Track Anthropic Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- @anthropic-ai/sdk scores healthy at depth 1 with 14 maintainers and 15.1M downloads/week.
- json-schema-to-ts is the only runtime dependency of @anthropic-ai/sdk, has one maintainer and ~14.9M downloads/week, and is flagged CRITICAL.
- ts-algebra (a dependency of json-schema-to-ts) has one maintainer, ~12.3M downloads/week and no release in over 12 months, and is flagged CRITICAL.
- The Commit supply chain scanner (getcommit.dev/audit) supports depth-2 npm dependency traversal and the article includes curl and MCP examples to map dependency-tree risk.
Connected Companies & Entities
4 Entities mappedOntology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
npm audit isn't enough: simulated Node supply‑chain attack
A developer simulated supply‑chain attack vectors against a real Node.js project (Next.js, Railway, PostgreSQL, TypeScript and ~23 direct dependencies) and found that npm audit — which only flags known CVE‑based vulnerabilities — missed practical risks. The simulation uncovered 847 transitive packages, three suspiciously similar package names (typosquatting candidates by similarity), 47 packages with install lifecycle scripts (some performing network calls or writing outside node_modules), and a likely maintainer‑takeover fingerprint (15 months of inactivity followed by a vague new release). The author implemented mitigations: run npm ci --ignore-scripts in CI, add Socket.dev behavioral analysis to the pipeline, and require manual review of lifecycle‑script diffs in PRs. The article argues npm audit is a compliance/CVE tool and recommends behavioral, integrity and CI‑isolation controls to reduce supply‑chain risk.
npm audit insufficient: simulated Node supply-chain attack
A developer simulated supply‑chain attack vectors against a real Node.js project (Next.js, Railway, PostgreSQL, TypeScript) to evaluate what npm audit misses. The simulation found npm audit only reports known CVEs and does not model trust-based threats. Key findings: the project had 23 direct dependencies and 847 transitive packages; npm audit reported zero critical vulnerabilities; 47 packages in the dependency tree had lifecycle scripts (preinstall/install/postinstall); three transitive packages showed name similarity (typosquatting risk); and one package exhibited a maintainer‑takeover fingerprint (long inactivity then a recent vague release). The author implemented mitigations: run npm ci --ignore-scripts in CI, segregate install steps from deploy/secrets, add behavioral analysis (Socket.dev), validate integrity hashes, and require manual review of lifecycle script diffs in PRs. Publication date: 2026-05-07.
48% of Dependencies Are Unmaintained — SCA Tools Miss It
Kota Kanbe presented research at VulnCon 2026 showing that conventional SCA/vulnerability scanners (Trivy, Snyk, Grype) miss a large class of risk: unmaintained packages. Analysis of ~16,000 packages across ~100 organizations (published in Nikkei, March 2026) found 48.5% of production dependencies exhibit lifecycle risk (40.6% Active, 10.9% Legacy-Safe, 34.6% Stalled, 13.9% EOL). Kanbe released uzomuzo, an open-source tool (Apache 2.0) that classifies package lifecycle in seven stages using signals from deps.dev, the GitHub API and registry heuristics, evaluates build integrity, prioritizes removals, and integrates with CI. He demonstrates scanning (e.g., HashiCorp Vault: 209 deps, 11 EOL) and uses an LLM to trace data flow and produce attack scenarios. uzomuzo provides commands for scanning, prioritizing removal, and CI gating.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
