← Home

@algolia/client-search

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

haroenvshortcutseric-zahariaflufmarioalgoliasylvainmorgan-algolia2

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern dormant-publish AI (publish-pattern): Package has 302 versions over 2338 days; apparent dormancy is an artifact of scoped package tracking, not actual inactivity. SLSA attestation confirms legitimate publish. ai
source-diff obfuscated-file:dist/browser.d.ts AI (source-diff): TypeScript declaration files (.d.ts) with long lines from union types and JSDoc are a known false positive for obfuscation detection. Content is clearly readable type definitions. ai
source-diff obfuscated-file:dist/fetch.d.ts AI (source-diff): TypeScript declaration files (.d.ts) with long lines from union types and JSDoc are a known false positive for obfuscation detection. Content is clearly readable type definitions. ai
source-diff obfuscated-file:dist/node.d.ts AI (source-diff): TypeScript declaration files (.d.ts) with long lines from union types and JSDoc are a known false positive for obfuscation detection. Content is clearly readable type definitions. ai
source-diff obfuscated-file:dist/worker.d.ts AI (source-diff): TypeScript declaration files (.d.ts) with long lines from union types and JSDoc are a known false positive for obfuscation detection. Content is clearly readable type definitions. ai
source-diff obfuscated-file:dist/node.d.cts AI (source-diff): TypeScript declaration files (.d.cts) with long lines from union types and JSDoc are a known false positive for obfuscation detection. Content is clearly readable type definitions. ai
dependencies unvetted-dep:@algolia/requester-browser-xhr AI (dependencies): First-party Algolia monorepo sibling package, always published at the same version as this package. Not an independent risk. ai
dependencies unvetted-dep:@algolia/requester-node-http AI (dependencies): First-party Algolia monorepo sibling package, always published at the same version as this package. Not an independent risk. ai
dependencies unvetted-dep:@algolia/requester-fetch AI (dependencies): First-party Algolia monorepo sibling package, always published at the same version as this package. Not an independent risk. ai

Versions (showing 51 of 154)

View all versions
Version Deps Published
5.56.0 4 / 6
5.55.2 4 / 6
5.55.1 4 / 6
5.55.0 4 / 6
5.54.1 4 / 6
5.54.0 4 / 6
5.53.0 4 / 6
5.52.1 4 / 6
5.52.0 4 / 6
5.51.0 4 / 6
5.50.2 4 / 6
5.50.1 4 / 6
5.50.0 4 / 6
5.49.2 4 / 6
5.49.1 4 / 6
5.49.0 4 / 6
5.48.2 4 / 6
5.48.1 4 / 6
5.48.0 4 / 6
5.46.0 4 / 6
5.45.0 4 / 6
5.44.0 4 / 6
5.43.0 4 / 6
5.42.0 4 / 6
5.41.0 4 / 6
5.40.1 4 / 6
5.40.0 4 / 6
5.39.0 4 / 6
5.38.0 4 / 6
5.37.0 4 / 6
5.36.0 4 / 6
5.35.0 4 / 6
5.34.1 4 / 6
5.34.0 4 / 6
5.33.0 4 / 6
5.32.0 4 / 6
5.31.0 4 / 6
5.30.0 4 / 6
5.29.0 4 / 6
5.28.0 4 / 6
5.27.0 4 / 6
5.26.0 4 / 6
5.25.0 4 / 6
5.24.0 4 / 6
5.23.4 4 / 6
5.23.3 4 / 6
5.23.2 4 / 6
5.23.1 4 / 6
5.23.0 4 / 6
5.22.0 4 / 6
5.21.0 4 / 6

v5.56.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.55.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.