← Home

@mollie/api-client

10
Versions
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures gitHead linked

Maintainers

mollienlvernondegoedeemkisrobin-ambachtsheerluciana.mollieainur.sharaevotaviobragahreinbergerrebecabordini-molliesameer.swigor.abreucarlos.louro.molliejanpaepke

Keywords

molliepaymentserviceproviderapiclientpaymentsgateway

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Change is from manual maintainer to GitHub Actions CI/CD with SLSA attestation — expected for this org's release automation adoption. ai
publish-pattern dormant-publish AI (publish-pattern): Official Mollie package with SLSA provenance; dormancy reflects release cadence, not takeover. ai
maintainer-change maintainer-added AI (maintainer-change): New maintainers all carry mollie-branded usernames; consistent with org-level team rotation. ai
maintainer-change maintainer-removed AI (maintainer-change): Removal paired with org-branded replacements; consistent with legitimate team change at Mollie. ai
phantom-deps phantom-dep:@types/node-fetch AI (phantom-deps): @types/node-fetch is a type declaration package; not directly imported but used for type augmentation — stable false positive. ai

Versions (showing 10 of 10)

Version Deps Published
4.6.0 3 / 23
4.5.0 3 / 22
4.4.0 3 / 22
4.3.3 3 / 21
4.3.2 3 / 21
4.3.1 3 / 21
4.3.0 3 / 21
4.2.0 3 / 21
4.1.0 3 / 21
4.0.0 3 / 21

v4.6.0

2 findings
HIGH Publisher changed: janpaepke → GitHub Actions (on 2026-06-30) provenance

This version was published by a different npm account than previous versions on 2026-06-30. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.3.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.3.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: pimm → janpaepke (on 2025-04-02) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2025-04-02. This could indicate a legitimate maintainer transition or an account compromise.

v4.2.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: pimm → janpaepke (on 2025-03-03) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2025-03-03. This could indicate a legitimate maintainer transition or an account compromise.

v4.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.