Menu

Post image 1
Post image 2
1 / 2
0

The Anthropic SDK Looks Safe. Two of Its Transitive Dependencies Aren't.

DEV Community·Pico·26 days ago
#E4oxi0Ca
Reading 0:00
15s threshold

Sole maintainer. 16M+ weekly downloads. No release in two years. Run a standard supply chain audit on @anthropic-ai/sdk . You get this: @anthropic-ai/sdk: score=86 14 maintainers 17.9M downloads/week ✅ HEALTHY Enter fullscreen mode Exit fullscreen mode Looks fine. Anthropic maintains it actively, large team, widely used. Move on. Run it again at depth 2 — checking what the SDK's dependencies depend on: @anthropic-ai/sdk score=86 14 maint 17.9M/wk ✅ HEALTHY └─ json-schema-to-ts score=71 1 maint 16.5M/wk 🔴 CRITICAL: sole maintainer + >10M/wk └─ ts-algebra score=64 1 maint 13.5M/wk 🔴 CRITICAL: sole maintainer + no release in two years └─ @babel/runtime score=93 4 maint 139M/wk ✅ HEALTHY Enter fullscreen mode Exit fullscreen mode json-schema-to-ts is the only runtime dependency of the Anthropic SDK. One maintainer. 16.5 million weekly downloads. The exact attack profile that hit LiteLLM in March 2026 and axios in March 2026 (via North Korea/UNC1069).…

Continue reading — create a free account

Join HashtagPLUS to read full articles, follow hashtags, vote, and join the conversation.

Read More