@autorest/typescript
[Autorest](https://github.com/Azure/autorest/blob/master/docs/readme.md) is a suite of tools to automatically generate SDKs for cloud services. This project provides an autorest extension that generates SDKs in TypeScript.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@azure/core-auth | AI (phantom-deps): Azure framework type injected into generated client code; not directly imported by the generator itself. | ai | |
| phantom-deps | phantom-dep:@azure/core-paging | AI (phantom-deps): Azure framework type injected into generated client code; not directly imported by the generator itself. | ai | |
| phantom-deps | phantom-dep:@azure/core-tracing | AI (phantom-deps): Azure framework type injected into generated client code; not directly imported by the generator itself. | ai | |
| phantom-deps | phantom-dep:@azure/core-rest-pipeline | AI (phantom-deps): Azure framework type injected into generated client code; not directly imported by the generator itself. | ai | |
| phantom-deps | phantom-dep:@azure/core-http-compat | AI (phantom-deps): Azure framework type injected into generated client code; not directly imported by the generator itself. | ai | |
| phantom-deps | phantom-dep:@azure-rest/core-client | AI (phantom-deps): Referenced in config files for generated RLC clients; stable pattern for this codegen package. | ai | |
| phantom-deps | phantom-dep:dotenv | AI (phantom-deps): Referenced in config files, not directly imported; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:source-map-support | AI (phantom-deps): Referenced in config files; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@types/lodash | AI (phantom-deps): Type-only package used by generated code; stable false positive for this codegen package. | ai |
Versions (showing 6 of 6)
| Version | Deps | Published |
|---|---|---|
| 6.0.72 | 23 / 41 | |
| 6.0.69 | 23 / 41 | |
| 6.0.68 | 23 / 41 | |
| 6.0.67 | 23 / 41 | |
| 6.0.66 | 23 / 41 | |
| 6.0.65 | 23 / 41 |
v6.0.72
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.0.69
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.0.68
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.0.67
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.0.66
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.0.65
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.