← Home

@scalar/api-client

the open source API testing client

51
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

cameronrohanimarclavescalar_geoffhwkrhanspagelamritkbgrcsscalar-machine

Keywords

apiclientgraphqlpostman alternativeresttesting

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/Editor-BomsGWHx.js AI (source-diff): Bundled Vite output with readable imports/comments; not obfuscation. ai
source-diff obfuscated-file:dist/monacoeditorwork/editor.worker.bundle.js AI (source-diff): Monaco editor esbuild worker bundle, not obfuscation; readable source paths. ai
source-diff obfuscated-file:dist/v2/features/editor/schemas/openapi-3.1-schema.json.js AI (source-diff): Minified OpenAPI 3.1 JSON schema module, benign data. ai
source-diff net-exec-file:dist/monacoeditorwork/yaml.worker.bundle.js AI (source-diff): Bundled monaco worker; net+exec pattern is minified library code, not a dropper. ai
source-diff obfuscated-file:dist/monacoeditorwork/yaml.worker.bundle.js AI (source-diff): Monaco editor esbuild worker bundle, not obfuscation. ai
source-diff obfuscated-file:dist/monacoeditorwork/json.worker.bundle.js AI (source-diff): Monaco editor esbuild worker bundle, not obfuscation. ai
publish-pattern new-deps-added AI (publish-pattern): jsonc-parser is a well-known Microsoft-maintained package; addition is consistent with the v2 refactor. ai
dependencies unvetted-dep:@scalar/blocks AI (dependencies): Same-org @scalar/* package; consistent with Scalar's monorepo pattern across all versions. ai
phantom-deps phantom-dep:@scalar/json-magic AI (phantom-deps): Same-org package; stable FP for this package. ai
phantom-deps phantom-dep:yaml AI (phantom-deps): Used in config/type files; stable FP for this package. ai
phantom-deps phantom-dep:zod AI (phantom-deps): Used in type/config files; stable FP for this package. ai
phantom-deps phantom-dep:@scalar/themes AI (phantom-deps): Same-org package; likely re-exported or used via convention, stable FP. ai
phantom-deps phantom-dep:type-fest AI (phantom-deps): type-fest is a type-only utility; phantom-dep false positive for this package. ai
dependencies unvetted-dep:@scalar/analytics-client AI (dependencies): Internal @scalar monorepo sibling package; expected dependency pattern. ai
dependencies unvetted-dep:@scalar/use-codemirror AI (dependencies): First-party @scalar monorepo sibling; stable pattern across versions. ai
dependencies unvetted-dep:@scalar/validation AI (dependencies): First-party @scalar monorepo sibling; stable pattern across versions. ai
dependencies unvetted-dep:@scalar/use-toasts AI (dependencies): First-party @scalar monorepo sibling; stable pattern across versions. ai
dependencies unvetted-dep:@scalar/use-hooks AI (dependencies): First-party @scalar monorepo sibling; stable pattern across versions. ai
dependencies unvetted-dep:@scalar/typebox AI (dependencies): First-party @scalar monorepo sibling; stable pattern across versions. ai
dependencies unvetted-dep:@scalar/icons AI (dependencies): First-party @scalar monorepo sibling; stable pattern across versions. ai
dependencies unvetted-dep:@scalar/themes AI (dependencies): First-party @scalar monorepo sibling; stable pattern across versions. ai
phantom-deps phantom-dep:@types/har-format AI (phantom-deps): Type-only package; not directly imported at runtime by convention. ai
phantom-deps phantom-dep:vite-plugin-monaco-editor AI (phantom-deps): Vite plugin loaded via vite config, not direct import; stable false positive for this package. ai
phantom-deps phantom-dep:@headlessui/tailwindcss AI (phantom-deps): Tailwind plugin loaded via config, not direct import; stable false positive for this package. ai
phantom-deps phantom-dep:focus-trap AI (phantom-deps): focus-trap is a runtime dep used via headlessui/vue; phantom-dep heuristic false positive for this package. ai

Versions (showing 51 of 109)

View all versions
Version Deps Published
3.13.7 30 / 11
3.13.6 30 / 11
3.13.5 30 / 11
3.13.4 30 / 11
3.13.3 30 / 11
3.13.2 30 / 11
3.13.1 30 / 11
3.13.0 30 / 11
3.12.0 30 / 11
3.11.0 31 / 11
3.10.4 31 / 11
3.10.3 31 / 11
3.10.2 31 / 11
3.10.1 31 / 11
3.10.0 32 / 11
3.9.0 32 / 11
3.8.5 32 / 11
3.8.4 32 / 11
3.8.3 32 / 11
3.8.2 32 / 11
3.8.1 32 / 11
3.8.0 32 / 11
3.6.1 38 / 15
3.6.0 38 / 15
3.5.1 38 / 13
3.5.0 38 / 13
3.4.0 38 / 13
3.3.1 38 / 13
3.3.0 38 / 13
3.2.2 37 / 13
3.2.1 37 / 13
3.2.0 37 / 13
3.1.0 37 / 13
3.0.0 38 / 12
2.43.0 44 / 14
2.42.0 42 / 14
2.41.0 42 / 14
2.40.0 42 / 14
2.39.4 43 / 14
2.39.3 43 / 14
2.39.2 43 / 14
2.39.1 43 / 14
2.39.0 43 / 14
2.38.4 43 / 14
2.38.3 43 / 14
2.38.2 43 / 14
2.38.1 43 / 15
2.38.0 43 / 15
2.37.0 43 / 15
2.36.2 43 / 15
2.36.1 42 / 15

v3.13.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.13.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.13.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.13.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.13.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.13.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.13.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.13.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.8.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.8.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.39.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.39.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.39.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.38.4

3 findings
HIGH New obfuscated file: dist/Editor-BomsGWHx.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/monacoeditorwork/editor.worker.bundle.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.38.3

3 findings
HIGH New obfuscated file: dist/Editor-BomsGWHx.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/monacoeditorwork/editor.worker.bundle.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.38.2

3 findings
HIGH New obfuscated file: dist/Editor-BomsGWHx.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/monacoeditorwork/editor.worker.bundle.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.38.1

6 findings
HIGH New obfuscated file: dist/monacoeditorwork/editor.worker.bundle.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/monacoeditorwork/json.worker.bundle.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/v2/features/editor/schemas/openapi-3.1-schema.json.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/monacoeditorwork/yaml.worker.bundle.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/monacoeditorwork/yaml.worker.bundle.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.38.0

6 findings
HIGH New obfuscated file: dist/monacoeditorwork/editor.worker.bundle.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/monacoeditorwork/json.worker.bundle.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/v2/features/editor/schemas/openapi-3.1-schema.json.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/monacoeditorwork/yaml.worker.bundle.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/monacoeditorwork/yaml.worker.bundle.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.37.0

6 findings
HIGH New obfuscated file: dist/monacoeditorwork/editor.worker.bundle.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/monacoeditorwork/json.worker.bundle.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/v2/features/editor/schemas/openapi-3.1-schema.json.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/monacoeditorwork/yaml.worker.bundle.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/monacoeditorwork/yaml.worker.bundle.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.36.2

6 findings
HIGH New obfuscated file: dist/monacoeditorwork/editor.worker.bundle.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/monacoeditorwork/json.worker.bundle.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/v2/features/editor/schemas/openapi-3.1-schema.json.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/monacoeditorwork/yaml.worker.bundle.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/monacoeditorwork/yaml.worker.bundle.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.