@maxim_mazurok/gapi.client.accessapproval-v1
TypeScript typings for Access Approval API v1
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): SLSA provenance attestation present; gitHead absence is minor given Sigstore-backed CI/CD publish chain. | ai | |
| dependencies | unvetted-dep:@types/gapi.client.discovery-v1 | AI (dependencies): Pure TypeScript type dependency; no runtime code risk. Stable pattern across all versions of this typings package. | ai | |
| phantom-deps | phantom-dep:@types/gapi.client | AI (phantom-deps): Type-only dependency loaded by convention in gapi typings packages; not directly imported by design. | ai | |
| phantom-deps | phantom-dep:@types/gapi.client.discovery-v1 | AI (phantom-deps): Type-only dependency loaded by convention in gapi typings packages; not directly imported by design. | ai |
Versions (showing 27 of 27)
| Version | Deps | Published |
|---|---|---|
| 0.3.20260605 | 2 / 0 | |
| 0.3.20260529 | 2 / 0 | |
| 0.3.20260522 | 2 / 0 | |
| 0.3.20260515 | 2 / 0 | |
| 0.3.20260506 | 2 / 0 | |
| 0.3.20260424 | 2 / 0 | |
| 0.3.20260407 | 2 / 0 | |
| 0.2.20260407 | 2 / 0 | |
| 0.2.20260313 | 2 / 0 | |
| 0.1.20260126 | 2 / 0 | |
| 0.1.20260116 | 2 / 0 | |
| 0.1.20260112 | 2 / 0 | |
| 0.1.20260106 | 2 / 0 | |
| 0.1.20251117 | 2 / 0 | |
| 0.1.20251031 | 2 / 0 | |
| 0.1.20251027 | 2 / 0 | |
| 0.1.20251006 | 2 / 0 | |
| 0.1.20250912 | 2 / 0 | |
| 0.1.20250821 | 2 / 0 | |
| 0.0.20250805 | 2 / 0 | |
| 0.0.20250716 | 2 / 0 | |
| 0.0.20250715 | 2 / 0 | |
| 0.0.20250704 | 2 / 0 | |
| 0.0.20250620 | 2 / 0 | |
| 0.0.20250508 | 2 / 0 | |
| 0.0.20250429 | 2 / 0 | |
| 0.0.20250428 | 2 / 0 |
v0.3.20260605
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3.20260529
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3.20260522
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3.20260515
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3.20260506
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3.20260407
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.20260407
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.20260313
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.20260126
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.20260116
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.20260112
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.20260106
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.20251117
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.20251031
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.20251027
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.20251006
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.20250912
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.20250821
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.20250805
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.20250716
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.20250715
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.20250704
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.20250620
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.20250508
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.20250429
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.20250428
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.