← Home

@algolia/ingestion

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

haroenvtkruggsarahdayancyril.descossyalgabetalg-bgastinneemmanuel.fortinrobertmogosjinsteeventexperiences_algoliaalg-adminsarahdayanalgoliamorgan-algolia2fluferic-zahariasylvainmarioalgoliashortcuts

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/worker.d.ts AI (source-diff): Auto-generated TypeScript declaration file for new worker build target; content is readable Algolia API types, not obfuscated code. ai
source-diff obfuscated-file:dist/fetch.d.ts AI (source-diff): TypeScript declaration files for a large API client legitimately produce long lines when bundled. The sample shows readable JSDoc and type definitions, not obfuscation. ai
source-diff obfuscated-file:dist/node.d.ts AI (source-diff): TypeScript declaration files (.d.ts) for a large API client SDK naturally have long lines due to generated union types. The sample shows well-commented, readable type definitions — not obfuscation. ai
source-diff obfuscated-file:dist/node.d.cts AI (source-diff): TypeScript declaration files (.d.cts) for a large API client SDK naturally have long lines due to generated union types. The sample shows well-commented, readable type definitions — not obfuscation. ai
source-diff obfuscated-file:dist/browser.d.ts AI (source-diff): TypeScript declaration files (.d.ts) for a large API client SDK naturally have long lines due to generated union types. The sample shows well-commented, readable type definitions — not obfuscation. ai
maintainer-change maintainer-removed AI (maintainer-change): Official Algolia package; maintainer removal alongside additions reflects normal team transitions, not a hostile takeover. ai
provenance publisher-changed AI (provenance): Publisher changed to GitHub Actions as part of Algolia's migration to automated CI/CD publishing, confirmed by SLSA provenance attestation. This is a positive supply chain signal for this official Algolia package. ai
maintainer-change maintainer-added AI (maintainer-change): Official Algolia package; maintainer roster changes reflect normal team evolution within the Algolia org, not a takeover. ai
dependencies unvetted-dep:@algolia/client-common AI (dependencies): First-party Algolia sibling package from the same monorepo, published in lockstep. Not a third-party risk. ai
dependencies unvetted-dep:@algolia/requester-browser-xhr AI (dependencies): First-party Algolia sibling package from the same monorepo, published in lockstep. Not a third-party risk. ai
dependencies unvetted-dep:@algolia/requester-node-http AI (dependencies): First-party Algolia sibling package from the same monorepo, published in lockstep. Not a third-party risk. ai
dependencies unvetted-dep:@algolia/requester-fetch AI (dependencies): First-party Algolia sibling package from the same monorepo, published in lockstep. Not a third-party risk. ai

Versions (showing 51 of 85)

View all versions
Version Deps Published
1.56.0 4 / 6
1.55.2 4 / 6
1.55.1 4 / 6
1.55.0 4 / 6
1.54.1 4 / 6
1.54.0 4 / 6
1.53.0 4 / 6
1.52.1 4 / 6
1.52.0 4 / 6
1.51.0 4 / 6
1.50.2 4 / 6
1.50.1 4 / 6
1.50.0 4 / 6
1.49.2 4 / 6
1.49.1 4 / 6
1.49.0 4 / 6
1.48.2 4 / 6
1.48.1 4 / 6
1.48.0 4 / 6
1.47.0 4 / 6
1.46.4 4 / 6
1.46.3 4 / 6
1.46.2 4 / 6
1.46.1 4 / 6
1.46.0 4 / 6
1.45.0 4 / 6
1.44.0 4 / 6
1.43.0 4 / 6
1.42.0 4 / 6
1.41.0 4 / 6
1.40.1 4 / 6
1.40.0 4 / 6
1.39.0 4 / 6
1.38.0 4 / 6
1.37.0 4 / 6
1.36.0 4 / 6
1.35.0 4 / 6
1.34.1 4 / 6
1.34.0 4 / 6
1.33.0 4 / 6
1.32.0 4 / 6
1.31.0 4 / 6
1.30.0 4 / 6
1.29.0 4 / 6
1.28.0 4 / 6
1.27.0 4 / 6
1.26.0 4 / 6
1.25.0 4 / 6
1.24.0 4 / 6
1.23.4 4 / 6
1.23.3 4 / 6

v1.56.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.55.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.