@alwaysmeticulous/api
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): SLSA provenance attestation present; missing gitHead is a minor metadata gap, not a supply chain risk for this package. | ai | |
| provenance | publisher-changed | AI (provenance): Publisher is GitHub Actions with SLSA provenance attestation; this is an intentional CI/CD publishing transition for this package. | ai | |
| typosquat | typosquat.levenshtein:hapi | AI (typosquat): Scoped package @alwaysmeticulous/api; suffix match against 'hapi' is a stable false positive. | ai | |
| typosquat | typosquat.levenshtein:pg | AI (typosquat): Scoped package; suffix match against 'pg' is a stable false positive. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped package; suffix match against 'joi' is a stable false positive. | ai | |
| typosquat | typosquat.levenshtein:ajv | AI (typosquat): Scoped package; suffix match against 'ajv' is a stable false positive. | ai |
Versions (showing 100 of 109)
| Version | Deps | Published |
|---|---|---|
| 2.312.0 | 0 / 0 | |
| 2.310.0 | 0 / 0 | |
| 2.307.0 | 0 / 0 | |
| 2.306.0 | 0 / 0 | |
| 2.297.0 | 0 / 0 | |
| 2.295.0 | 0 / 0 | |
| 2.294.0 | 0 / 0 | |
| 2.293.0 | 0 / 0 | |
| 2.292.1 | 0 / 0 | |
| 2.292.0 | 0 / 0 | |
| 2.291.2 | 0 / 0 | |
| 2.290.2 | 0 / 0 | |
| 2.290.0 | 0 / 0 | |
| 2.289.1 | 0 / 0 | |
| 2.288.2 | 0 / 0 | |
| 2.288.0 | 0 / 0 | |
| 2.286.0 | 0 / 0 | |
| 2.285.2 | 0 / 0 | |
| 2.285.1 | 0 / 0 | |
| 2.285.0 | 0 / 0 | |
| 2.283.1 | 0 / 0 | |
| 2.280.0 | 0 / 0 | |
| 2.276.2 | 0 / 0 | |
| 2.275.0 | 0 / 0 | |
| 2.274.2 | 0 / 0 | |
| 2.273.0 | 0 / 0 | |
| 2.267.0 | 0 / 0 | |
| 2.264.0 | 0 / 0 | |
| 2.262.0 | 0 / 0 | |
| 2.259.0 | 0 / 0 | |
| 2.257.1 | 0 / 0 | |
| 2.256.0 | 0 / 0 | |
| 2.255.0 | 0 / 0 | |
| 2.254.1 | 0 / 0 | |
| 2.251.1 | 0 / 0 | |
| 2.251.0 | 0 / 0 | |
| 2.250.7 | 0 / 0 | |
| 2.250.6 | 0 / 0 | |
| 2.250.3 | 0 / 0 | |
| 2.250.2 | 0 / 0 | |
| 2.248.14 | 0 / 0 | |
| 2.248.0 | 0 / 0 | |
| 2.246.0 | 0 / 0 | |
| 2.242.6 | 0 / 0 | |
| 2.242.5 | 0 / 0 | |
| 2.242.4 | 0 / 0 | |
| 2.241.0 | 0 / 0 | |
| 2.240.3 | 0 / 0 | |
| 2.239.3 | 0 / 0 | |
| 2.235.2 | 0 / 0 | |
| 2.233.0 | 0 / 0 | |
| 2.232.0 | 0 / 0 | |
| 2.231.0 | 0 / 0 | |
| 2.227.1 | 0 / 0 | |
| 2.225.0 | 0 / 0 | |
| 2.224.0 | 0 / 0 | |
| 2.223.0 | 0 / 0 | |
| 2.221.2 | 0 / 0 | |
| 2.221.0 | 0 / 0 | |
| 2.219.0 | 0 / 0 | |
| 2.218.3 | 0 / 0 | |
| 2.218.2 | 0 / 0 | |
| 2.218.1 | 0 / 0 | |
| 2.217.0 | 0 / 0 | |
| 2.214.1 | 0 / 0 | |
| 2.214.0 | 0 / 0 | |
| 2.212.0 | 0 / 0 | |
| 2.206.5 | 0 / 0 | |
| 2.206.4 | 0 / 0 | |
| 2.206.3 | 0 / 0 | |
| 2.206.2 | 0 / 0 | |
| 2.206.0 | 0 / 0 | |
| 2.201.0 | 0 / 0 | |
| 2.199.1 | 0 / 0 | |
| 2.194.1 | 0 / 0 | |
| 2.192.0 | 0 / 0 | |
| 2.189.0 | 0 / 0 | |
| 2.188.0 | 0 / 0 | |
| 2.186.0 | 0 / 0 | |
| 2.185.1 | 0 / 0 | |
| 2.185.0 | 0 / 0 | |
| 2.184.0 | 0 / 0 | |
| 2.183.0 | 0 / 0 | |
| 2.181.0 | 0 / 0 | |
| 2.180.0 | 0 / 0 | |
| 2.178.0 | 0 / 0 | |
| 2.177.0 | 0 / 0 | |
| 2.175.0 | 0 / 0 | |
| 2.173.0 | 0 / 0 | |
| 2.172.0 | 0 / 0 | |
| 2.171.0 | 0 / 0 | |
| 2.169.0 | 0 / 0 | |
| 2.166.0 | 0 / 0 | |
| 2.164.0 | 0 / 0 | |
| 2.163.0 | 0 / 0 | |
| 2.158.1 | 0 / 0 | |
| 2.157.0 | 0 / 0 | |
| 2.155.0 | 0 / 0 | |
| 2.154.1 | 0 / 0 | |
| 2.153.0 | 0 / 0 |
v2.312.0
1 findingThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.
v2.310.0
1 findingThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.
v2.307.0
1 findingThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.
v2.306.0
1 findingThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. The axios attack (March 2026) exhibited exactly this pattern.
v2.218.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.218.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.218.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.217.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.214.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.214.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.212.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.206.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.206.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.206.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.206.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.206.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.201.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.199.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.194.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.192.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.189.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.188.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.186.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.185.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.185.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.184.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.183.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.181.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.180.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.178.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.177.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.175.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.173.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.172.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.171.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.169.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.166.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.164.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.163.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.158.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.157.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.155.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.154.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.153.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.