@atproto/api
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:typed-emitter | AI (phantom-deps): Used dependency; likely missed by static import scan in bundled output. | ai | |
| phantom-deps | phantom-dep:zod | AI (phantom-deps): Used dependency; likely missed by static import scan in bundled output. | ai | |
| dependencies | unvetted-dep:@atproto/uri | AI (dependencies): Official sibling package in the same atproto monorepo. | ai | |
| provenance | publisher-changed | AI (provenance): Manual→GitHub Actions CI/CD with SLSA attestation; legitimate publish-flow transition for official package. | ai | |
| typosquat | typosquat.levenshtein:hapi | AI (typosquat): @atproto/api is the official Bluesky ATProto client, not a typosquat of hapi. | ai | |
| typosquat | typosquat.levenshtein:ajv | AI (typosquat): @atproto/api is the official Bluesky ATProto client, not a typosquat of ajv. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): @atproto/api is the official Bluesky ATProto client, not a typosquat of joi. | ai | |
| typosquat | typosquat.levenshtein:pg | AI (typosquat): @atproto/api is the official Bluesky ATProto client, not a typosquat of pg. | ai |
Versions (showing 100 of 230)
| Version | Deps | Published |
|---|---|---|
| 0.20.34 | 8 / 5 | |
| 0.20.33 | 8 / 5 | |
| 0.20.32 | 8 / 5 | |
| 0.20.31 | 8 / 5 | |
| 0.20.30 | 8 / 5 | |
| 0.20.29 | 8 / 5 | |
| 0.20.28 | 8 / 5 | |
| 0.20.27 | 8 / 5 | |
| 0.20.26 | 8 / 5 | |
| 0.20.25 | 8 / 5 | |
| 0.20.23 | 8 / 5 | |
| 0.20.22 | 8 / 5 | |
| 0.20.21 | 8 / 5 | |
| 0.20.20 | 8 / 5 | |
| 0.20.19 | 8 / 5 | |
| 0.20.18 | 8 / 5 | |
| 0.20.17 | 8 / 5 | |
| 0.20.16 | 8 / 4 | |
| 0.20.15 | 8 / 5 | |
| 0.20.14 | 8 / 5 | |
| 0.20.13 | 8 / 5 | |
| 0.20.12 | 8 / 5 | |
| 0.20.11 | 8 / 5 | |
| 0.20.10 | 8 / 5 | |
| 0.20.9 | 8 / 5 | |
| 0.20.8 | 8 / 5 | |
| 0.20.7 | 8 / 5 | |
| 0.20.6 | 8 / 5 | |
| 0.20.5 | 8 / 5 | |
| 0.20.4 | 8 / 5 | |
| 0.20.3 | 8 / 5 | |
| 0.20.2 | 8 / 5 | |
| 0.20.1 | 8 / 5 | |
| 0.20.0 | 8 / 5 | |
| 0.19.19 | 8 / 5 | |
| 0.19.18 | 8 / 5 | |
| 0.19.17 | 8 / 5 | |
| 0.19.16 | 8 / 5 | |
| 0.19.15 | 8 / 5 | |
| 0.19.14 | 8 / 5 | |
| 0.19.13 | 8 / 5 | |
| 0.19.12 | 8 / 5 | |
| 0.19.11 | 8 / 5 | |
| 0.19.10 | 8 / 5 | |
| 0.19.9 | 8 / 5 | |
| 0.19.8 | 8 / 5 | |
| 0.19.7 | 8 / 5 | |
| 0.19.6 | 8 / 5 | |
| 0.19.5 | 8 / 5 | |
| 0.19.4 | 8 / 5 | |
| 0.19.3 | 8 / 5 | |
| 0.19.2 | 8 / 5 | |
| 0.19.1 | 8 / 5 | |
| 0.19.0 | 8 / 5 | |
| 0.18.21 | 8 / 5 | |
| 0.18.20 | 8 / 5 | |
| 0.18.19 | 8 / 5 | |
| 0.18.18 | 8 / 5 | |
| 0.18.17 | 8 / 5 | |
| 0.18.16 | 8 / 5 | |
| 0.18.15 | 8 / 5 | |
| 0.18.14 | 8 / 5 | |
| 0.18.13 | 8 / 5 | |
| 0.18.12 | 8 / 5 | |
| 0.18.11 | 8 / 5 | |
| 0.18.10 | 8 / 5 | |
| 0.18.9 | 8 / 5 | |
| 0.18.8 | 8 / 5 | |
| 0.18.7 | 8 / 5 | |
| 0.18.6 | 8 / 5 | |
| 0.18.5 | 8 / 5 | |
| 0.18.4 | 8 / 5 | |
| 0.18.3 | 8 / 4 | |
| 0.18.2 | 8 / 4 | |
| 0.18.1 | 8 / 4 | |
| 0.18.0 | 8 / 4 | |
| 0.17.7 | 8 / 4 | |
| 0.17.6 | 8 / 4 | |
| 0.15.0 | 8 / 4 | |
| 0.14.22 | 8 / 4 | |
| 0.14.21 | 8 / 4 | |
| 0.14.20 | 8 / 4 | |
| 0.14.19 | 8 / 4 | |
| 0.14.18 | 8 / 4 | |
| 0.14.17 | 8 / 4 | |
| 0.14.16 | 8 / 4 | |
| 0.14.15 | 8 / 4 | |
| 0.14.14 | 8 / 4 | |
| 0.14.13 | 8 / 4 | |
| 0.14.12 | 8 / 4 | |
| 0.14.11 | 8 / 4 | |
| 0.14.10 | 8 / 4 | |
| 0.14.9 | 8 / 4 | |
| 0.14.8 | 8 / 4 | |
| 0.14.7 | 8 / 4 | |
| 0.14.6 | 8 / 4 | |
| 0.14.5 | 8 / 4 | |
| 0.14.4 | 8 / 4 | |
| 0.14.3 | 8 / 4 | |
| 0.14.2 | 8 / 4 |
v0.20.34
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20.33
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20.32
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20.31
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20.30
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20.29
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20.28
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20.27
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20.26
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20.25
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20.23
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.19.5
2 findingsThis version was published by a different npm account than previous versions on 2026-03-26. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.19.4
2 findingsThis version was published by a different npm account than previous versions on 2026-03-18. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.19.3
2 findingsThis version was published by a different npm account than previous versions on 2026-03-04. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.19.2
2 findingsThis version was published by a different npm account than previous versions on 2026-03-04. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.19.1
2 findingsThis version was published by a different npm account than previous versions on 2026-03-03. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.19.0
2 findingsThis version was published by a different npm account than previous versions on 2026-02-23. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.18.21
2 findingsThis version was published by a different npm account than previous versions on 2026-02-10. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.18.20
2 findingsThis version was published by a different npm account than previous versions on 2026-01-30. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.18.19
2 findingsThis version was published by a different npm account than previous versions on 2026-01-30. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.18.18
2 findingsThis version was published by a different npm account than previous versions on 2026-01-28. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.18.17
2 findingsThis version was published by a different npm account than previous versions on 2026-01-23. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.18.16
2 findingsThis version was published by a different npm account than previous versions on 2026-01-15. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.18.15
2 findingsThis version was published by a different npm account than previous versions on 2026-01-14. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.18.14
2 findingsThis version was published by a different npm account than previous versions on 2026-01-12. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.18.13
2 findingsThis version was published by a different npm account than previous versions on 2026-01-08. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.18.12
2 findingsThis version was published by a different npm account than previous versions on 2026-01-08. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.18.11
2 findingsThis version was published by a different npm account than previous versions on 2026-01-07. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.18.10
2 findingsThis version was published by a different npm account than previous versions on 2026-01-06. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.18.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.18.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.18.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.18.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.18.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.18.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.18.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.18.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.18.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.18.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.17.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.17.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.15.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.22
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.21
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.20
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.19
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.18
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.17
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.16
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.15
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.