@algolia/requester-fetch
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | no-provenance | AI (provenance): Algolia v4 packages predate widespread Sigstore adoption; absence of provenance attestation is expected for this package line. | ai | |
| provenance | missing-githead | AI (provenance): Established Algolia monorepo package with strong publisher track record; missing gitHead likely reflects a CI/CD tooling change, not a supply chain compromise. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): New maintainers include Algolia-named accounts (marioalgolia, etc.), consistent with internal team changes at Algolia. SLSA provenance from official repo corroborates legitimacy. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Package has 251 versions in registry; apparent dormancy is likely a tracking artifact. SLSA provenance and official Algolia repo confirm legitimate publishing. | ai | |
| provenance | publisher-changed | AI (provenance): Transition to CI/CD-attested GitHub Actions publish on canonical Algolia repo; provenance improved, not takeover. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): @algolia/client-common is a first-party sibling package in the same Algolia monorepo at the same version (5.45.0). Not a suspicious third-party dependency. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Algolia org-level maintainer rotation; publisher 'shortcuts' has 152 approved packages. Normal team change for a large org's monorepo package. | ai |
v5.56.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.55.2
2 findings[Reject — re-review on republish] (prior reject: AI (provenance): Publisher changed from GitHub Actions to a human account with no prior history on this package; consistent with account takeover pattern.) This version was published by a different npm account than previous versions on 2026-07-07. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.