@atproto/api
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| typosquat | typosquat.levenshtein:hapi | AI (typosquat): @atproto/api is the official Bluesky ATProto client, not a typosquat of hapi. | ai | |
| typosquat | typosquat.levenshtein:pg | AI (typosquat): @atproto/api is the official Bluesky ATProto client, not a typosquat of pg. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): @atproto/api is the official Bluesky ATProto client, not a typosquat of joi. | ai | |
| typosquat | typosquat.levenshtein:ajv | AI (typosquat): @atproto/api is the official Bluesky ATProto client, not a typosquat of ajv. | ai |
Versions (showing 24 of 24)
| Version | Deps | Published |
|---|---|---|
| 0.20.9 | 8 / 5 | |
| 0.20.8 | 8 / 5 | |
| 0.20.7 | 8 / 5 | |
| 0.20.6 | 8 / 5 | |
| 0.20.5 | 8 / 5 | |
| 0.20.4 | 8 / 5 | |
| 0.20.3 | 8 / 5 | |
| 0.20.2 | 8 / 5 | |
| 0.20.1 | 8 / 5 | |
| 0.20.0 | 8 / 5 | |
| 0.19.19 | 8 / 5 | |
| 0.19.18 | 8 / 5 | |
| 0.19.17 | 8 / 5 | |
| 0.19.16 | 8 / 5 | |
| 0.19.15 | 8 / 5 | |
| 0.19.14 | 8 / 5 | |
| 0.19.13 | 8 / 5 | |
| 0.19.12 | 8 / 5 | |
| 0.19.11 | 8 / 5 | |
| 0.19.10 | 8 / 5 | |
| 0.19.9 | 8 / 5 | |
| 0.19.8 | 8 / 5 | |
| 0.19.7 | 8 / 5 | |
| 0.19.6 | 8 / 5 |
v0.20.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.19.19
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.19.18
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.19.17
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.19.16
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.19.15
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.19.14
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.19.13
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.19.12
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.19.11
2 findingsPackage name '@atproto/api' is 1 edit(s) away from popular package 'hapi'.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.19.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.19.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.19.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.19.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.19.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.