@ottocode/api
Type-safe API client for ottocode server
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| typosquat | typosquat.levenshtein:hapi | AI (typosquat): False positive: '@ottocode/api' is a scoped package; the edit distance is computed against the bare 'api' suffix, not the full name. No impersonation of hapi. | ai | |
| typosquat | typosquat.levenshtein:pg | AI (typosquat): False positive: edit distance is against the 'api' suffix of a scoped package. No impersonation of pg. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): False positive: edit distance is against the 'api' suffix of a scoped package. No impersonation of joi. | ai | |
| typosquat | typosquat.levenshtein:ajv | AI (typosquat): False positive: edit distance is against the 'api' suffix of a scoped package. No impersonation of ajv. | ai |
Versions (showing 23 of 143)
| Version | Deps | Published |
|---|---|---|
| 0.1.195 | 2 / 3 | |
| 0.1.194 | 2 / 3 | |
| 0.1.193 | 2 / 3 | |
| 0.1.192 | 2 / 3 | |
| 0.1.191 | 2 / 3 | |
| 0.1.190 | 2 / 3 | |
| 0.1.189 | 2 / 3 | |
| 0.1.188 | 2 / 3 | |
| 0.1.187 | 2 / 3 | |
| 0.1.186 | 2 / 3 | |
| 0.1.185 | 2 / 3 | |
| 0.1.184 | 2 / 3 | |
| 0.1.183 | 2 / 3 | |
| 0.1.182 | 2 / 3 | |
| 0.1.181 | 2 / 3 | |
| 0.1.180 | 2 / 3 | |
| 0.1.179 | 2 / 3 | |
| 0.1.178 | 2 / 3 | |
| 0.1.177 | 2 / 3 | |
| 0.1.176 | 2 / 3 | |
| 0.1.175 | 2 / 3 | |
| 0.1.174 | 2 / 3 | |
| 0.1.173 | 2 / 3 |
v0.1.195
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.194
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.193
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.192
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.191
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.190
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.189
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.188
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.187
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.186
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.185
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.184
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.183
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.182
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.181
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.180
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.179
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.178
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.177
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.176
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.175
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.174
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.173
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.