All @medplum/fhirtypes versions
@medplum/fhirtypes @2.1.26
Maintainers
Keywords
Changes from v5.0.15
No metadata changes detected.
File Changes
Risk Dispositions (2 applicable to this version, 0 other)
Accepted rules are downgraded to INFO on future analyses; rejected rules escalate to CRITICAL.
| Rule | Source | Disposition | Author | Reason | |
|---|---|---|---|---|---|
regressed-provenance |
provenance | reject | AI | AI (provenance): Provenance regression combined with publisher change and version downgrade is a strong supply-chain compromise indicator for this package. | |
publisher-changed |
provenance | reject | AI | AI (provenance): Publisher changed from GitHub Actions to a human account alongside provenance loss — consistent with account takeover pattern. |
SAST Findings (2)
This version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. The axios attack (March 2026) exhibited exactly this pattern.
This version was published by a different npm account than previous versions on 2026-02-23. This could indicate a legitimate maintainer transition or an account compromise.
Review Summary
Risk score: 60. Findings: 2 high (+50), 1 medium (+10).
Commit: a1b33b73f169 Browse source
Published to npm: