← Home

@datadog/datadog-api-client

60
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

datadog

Keywords

apifetchdatadogtypescriptopenapi-clientopenapi-generator

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file-transition:dist/packages/datadog-api-client-v1/models/MonthlyUsageAttributionSupportedMetrics.d.ts AI (source-diff): Generated long TypeScript union type declaration, not obfuscation; benign codegen output. ai
semgrep semgrep:child-process-import AI (semgrep): Internal bin/check-licenses.js dev script, not shipped runtime behavior. ai
phantom-deps phantom-dep:durations AI (phantom-deps): Declared runtime dep, likely used via generated/bundled code. ai
phantom-deps phantom-dep:btoa AI (phantom-deps): Used polyfill dep for browser/node compat, common false positive. ai
semgrep semgrep:dynamic-require AI (semgrep): Same license-check script loading local package.json, not arbitrary code. ai
source-diff obfuscated-file:dist/packages/datadog-api-client-v1/models/SyntheticsMobileDeviceID.js AI (source-diff): Generated OpenAPI enum exports on one line; not obfuscation. ai
source-diff obfuscated-file:dist/packages/datadog-api-client-v1/models/SyntheticsMobileDeviceID.d.ts AI (source-diff): Generated OpenAPI enum type union on one line; not obfuscation. ai
phantom-deps phantom-dep:es6-promise AI (phantom-deps): Polyfill referenced via config, stable FP. ai
phantom-deps phantom-dep:@types/node AI (phantom-deps): @types/node is a TypeScript type package consumed by the compiler, not imported at runtime. Phantom-dep finding is a stable false positive for this package. ai
dependencies unvetted-dep:@types/buffer-from AI (dependencies): @types/buffer-from is a DefinitelyTyped type definition package with no runtime behavior; low risk for this established Datadog package. ai
dependencies unvetted-dep:@types/pako AI (dependencies): @types/pako is a DefinitelyTyped type definition package with no runtime behavior; low risk for this established Datadog package. ai
phantom-deps phantom-dep:@types/buffer-from AI (phantom-deps): @types/buffer-from is a TypeScript type package consumed by the compiler, not imported at runtime. Phantom-dep finding is a stable false positive for this package. ai
phantom-deps phantom-dep:@types/pako AI (phantom-deps): @types/pako is a TypeScript type package consumed by the compiler, not imported at runtime. Phantom-dep finding is a stable false positive for this package. ai

Versions (showing 60 of 60)

Version Deps Published
1.60.0 8 / 24
1.59.0 8 / 24
1.58.0 8 / 24
1.57.0 8 / 24
1.56.0 8 / 24
1.53.0 8 / 24
1.52.0 8 / 24
1.51.0 9 / 24
1.50.0 9 / 24
1.49.0 9 / 24
1.48.0 9 / 24
1.47.0 9 / 24
1.46.0 9 / 24
1.45.0 9 / 24
1.44.0 9 / 24
1.43.0 9 / 24
1.42.0 9 / 24
1.41.0 9 / 24
1.40.0 9 / 24
1.39.0 9 / 24
1.38.0 9 / 24
1.37.0 9 / 24
1.36.0 9 / 24
1.35.0 9 / 24
1.34.1 9 / 24
1.33.1 9 / 24
1.33.0 9 / 24
1.32.0 9 / 24
1.31.0 9 / 24
1.30.0 9 / 24
1.29.0 10 / 25
1.28.0 10 / 25
1.27.0 10 / 25
1.26.0 10 / 25
1.25.0 10 / 25
1.24.0 10 / 25
1.23.0 10 / 25
1.22.0 10 / 25
1.21.0 10 / 25
1.20.0 10 / 25
1.19.0 10 / 25
1.18.0 10 / 25
1.17.0 10 / 25
1.16.0 10 / 24
1.15.0 10 / 24
1.14.0 10 / 24
1.13.0 10 / 24
1.12.0 10 / 23
1.11.0 10 / 23
1.10.0 12 / 29
1.9.0 12 / 29
1.8.0 12 / 29
1.7.0 12 / 29
1.6.0 12 / 29
1.5.0 12 / 29
1.4.0 12 / 29
1.3.0 12 / 29
1.2.0 12 / 28
1.1.0 12 / 28
1.0.0 12 / 28

v1.60.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.34.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.33.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.33.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.32.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.31.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.30.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.29.0

3 findings
HIGH New obfuscated file: dist/packages/datadog-api-client-v1/models/SyntheticsMobileDeviceID.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/packages/datadog-api-client-v1/models/SyntheticsMobileDeviceID.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.28.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.27.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.26.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.25.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.24.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.23.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.22.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.21.0

2 findings
HIGH Modified file became obfuscated: dist/packages/datadog-api-client-v1/models/MonthlyUsageAttributionSupportedMetrics.d.ts source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.20.0

2 findings
HIGH Modified file became obfuscated: dist/packages/datadog-api-client-v1/models/MonthlyUsageAttributionSupportedMetrics.d.ts source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.19.0

2 findings
HIGH Modified file became obfuscated: dist/packages/datadog-api-client-v1/models/MonthlyUsageAttributionSupportedMetrics.d.ts source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.18.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.17.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.16.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.15.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.14.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.13.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.12.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.11.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.10.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.9.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.8.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.