← Home

@orpc/react-query

<div align="center"> <image align="center" src="https://orpc.dev/logo.webp" width=280 alt="oRPC logo" /> </div>

51
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

dinwwwh

Keywords

orpcreact-querytanstack queryreact

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
maintainer-change maintainer-takeover AI (maintainer-change): dinwwwh confirmed as known maintainer by email match on prior approved versions; SLSA provenance attestation present. ai
maintainer-change maintainer-added AI (maintainer-change): dinwwwh is a known maintainer matched by email; not a new external actor. ai
maintainer-change maintainer-removed AI (maintainer-change): Legitimate maintainer transition; dinwwwh confirmed as known maintainer with SLSA-attested publish. ai

Versions (showing 51 of 76)

View all versions
Version Deps Published
1.14.12 2 / 3
1.14.10 2 / 3
1.14.9 2 / 3
1.14.8 2 / 3
1.14.6 2 / 3
1.14.5 2 / 3
1.14.4 2 / 3
1.14.0 2 / 3
1.13.6 2 / 3
1.13.5 2 / 3
1.13.4 2 / 3
1.13.2 2 / 3
1.13.1 2 / 3
1.13.0 2 / 3
1.12.3 2 / 3
1.12.2 2 / 3
1.12.1 2 / 3
1.12.0 2 / 3
1.11.3 2 / 3
1.11.2 2 / 3
1.11.1 2 / 3
1.11.0 2 / 3
1.10.4 2 / 3
1.10.3 2 / 3
1.10.2 2 / 3
1.10.1 2 / 3
1.10.0 2 / 3
1.9.4 2 / 3
1.9.3 2 / 3
1.9.2 2 / 3
1.9.1 2 / 3
1.9.0 2 / 3
1.8.9 2 / 3
1.8.8 2 / 3
1.8.7 2 / 3
1.8.6 2 / 3
1.8.5 2 / 3
1.8.4 2 / 3
1.8.3 2 / 3
1.8.2 2 / 3
1.8.1 2 / 3
1.8.0 2 / 3
1.7.11 2 / 3
1.7.10 2 / 3
1.7.9 2 / 3
1.7.8 2 / 3
1.7.7 2 / 3
1.7.6 2 / 3
1.7.5 2 / 3
1.7.4 2 / 3
1.7.3 2 / 3

v1.14.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.14.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.14.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.14.8

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: dinwwwh → GitHub Actions (on 2026-07-13, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (dinwwwh) on 2026-07-13, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.