@atproto/api
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:typed-emitter | AI (phantom-deps): Used dependency; likely missed by static import scan in bundled output. | ai | |
| phantom-deps | phantom-dep:zod | AI (phantom-deps): Used dependency; likely missed by static import scan in bundled output. | ai | |
| dependencies | unvetted-dep:@atproto/uri | AI (dependencies): Official sibling package in the same atproto monorepo. | ai | |
| provenance | publisher-changed | AI (provenance): Manual→GitHub Actions CI/CD with SLSA attestation; legitimate publish-flow transition for official package. | ai | |
| typosquat | typosquat.levenshtein:hapi | AI (typosquat): @atproto/api is the official Bluesky ATProto client, not a typosquat of hapi. | ai | |
| typosquat | typosquat.levenshtein:ajv | AI (typosquat): @atproto/api is the official Bluesky ATProto client, not a typosquat of ajv. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): @atproto/api is the official Bluesky ATProto client, not a typosquat of joi. | ai | |
| typosquat | typosquat.levenshtein:pg | AI (typosquat): @atproto/api is the official Bluesky ATProto client, not a typosquat of pg. | ai |
Versions (showing 51 of 230)
| Version | Deps | Published |
|---|---|---|
| 0.20.34 | 8 / 5 | |
| 0.20.33 | 8 / 5 | |
| 0.20.32 | 8 / 5 | |
| 0.20.31 | 8 / 5 | |
| 0.20.30 | 8 / 5 | |
| 0.20.29 | 8 / 5 | |
| 0.20.28 | 8 / 5 | |
| 0.20.27 | 8 / 5 | |
| 0.20.26 | 8 / 5 | |
| 0.20.25 | 8 / 5 | |
| 0.20.23 | 8 / 5 | |
| 0.20.22 | 8 / 5 | |
| 0.20.21 | 8 / 5 | |
| 0.20.20 | 8 / 5 | |
| 0.20.19 | 8 / 5 | |
| 0.20.18 | 8 / 5 | |
| 0.20.17 | 8 / 5 | |
| 0.20.16 | 8 / 4 | |
| 0.20.15 | 8 / 5 | |
| 0.20.14 | 8 / 5 | |
| 0.20.13 | 8 / 5 | |
| 0.20.12 | 8 / 5 | |
| 0.20.11 | 8 / 5 | |
| 0.20.10 | 8 / 5 | |
| 0.20.9 | 8 / 5 | |
| 0.20.8 | 8 / 5 | |
| 0.20.7 | 8 / 5 | |
| 0.20.6 | 8 / 5 | |
| 0.20.5 | 8 / 5 | |
| 0.20.4 | 8 / 5 | |
| 0.20.3 | 8 / 5 | |
| 0.20.2 | 8 / 5 | |
| 0.20.1 | 8 / 5 | |
| 0.20.0 | 8 / 5 | |
| 0.19.19 | 8 / 5 | |
| 0.19.18 | 8 / 5 | |
| 0.19.17 | 8 / 5 | |
| 0.19.16 | 8 / 5 | |
| 0.19.15 | 8 / 5 | |
| 0.19.14 | 8 / 5 | |
| 0.19.13 | 8 / 5 | |
| 0.19.12 | 8 / 5 | |
| 0.19.11 | 8 / 5 | |
| 0.19.10 | 8 / 5 | |
| 0.19.9 | 8 / 5 | |
| 0.19.8 | 8 / 5 | |
| 0.19.7 | 8 / 5 | |
| 0.19.6 | 8 / 5 | |
| 0.19.5 | 8 / 5 | |
| 0.19.4 | 8 / 5 | |
| 0.19.3 | 8 / 5 |
v0.20.34
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20.33
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20.32
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20.31
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20.30
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20.29
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20.28
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20.27
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20.26
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20.25
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20.23
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.19.5
2 findingsThis version was published by a different npm account than previous versions on 2026-03-26. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.19.4
2 findingsThis version was published by a different npm account than previous versions on 2026-03-18. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.19.3
2 findingsThis version was published by a different npm account than previous versions on 2026-03-04. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.