← Home

@vtex/api

10
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

lbebberalcararturpimentelfelippenardialinevillacacaio.oliveiravictorgesguilhermebruzzicmdalbemiagontmedinasalesfelipediegoximenesandreldsajgfidelisvcalasansthiagomurakamimarcoskwkmlurianrogerlucenaarthurepcigorframosgustavorosolemanaluizamtgrafarubimtergolrafabacbivillarbrenoguigsdahervictorhmpmarcosvcpjeymissonnatalia_godottiagonapolir-araripeaugusto.lazarokaisermannericreisathoscoutotlgimenesanitavincentbrunojdofirstdoitaugustobafonsopracaamoreiranandoacoelhokevinchevalliervtexlab-userbrenovtexeduardoformigamayzabelnatameloemersonlaurentinoviniagostinilucasaarcoverdelariciamotageraldo.fernandesmateuspontesvitorlgomesmarcelovicentegcmaianabthiagolcmwendermatheuslealvimendescamarathiago.pereira.vtexkevinvtexmyllena.alvesenzomercajardelymarisdaniyelnnrdenissilvavtexvinhagsgeorgebrindeiromarcos_vtexlaisribeirodevleortexlucasfp13-vtexbrunoamuiluisgomes01_extvtexfdaciuk_vtexsophreisvtexsagginvtexwilliamcunhavtexamandascmvtexgabriel_bozellithaynannunesyasmintelesemersonvtexv2guieevc-vtexevertonstrackarthurtriis1vtexmmartinsolivrerissonvtexernestosbarbosawisney.cardealgabriellymourampcardosorafael.pereiraamilton.vtexoremluis.mafraluis.mollmannleidymgdevguilhermeribeiro30

Keywords

vtex

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition from manual publish to GitHub Actions CI/CD is an improvement; consistent with VTEX org automation. ai
npm-metadata url-dep:stats-lite AI (npm-metadata): Long-standing vtex-owned GitHub dep; stable pattern for this package. ai
npm-metadata url-dep:@types/ramda AI (npm-metadata): types/npm-ramda#dist is the canonical community types source; stable for this package. ai
phantom-deps phantom-dep:bluebird AI (phantom-deps): bluebird is a declared dep used transitively; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:@types/koa AI (phantom-deps): Type-only dep for framework; not directly imported at runtime by design. ai
phantom-deps phantom-dep:@wry/equality AI (phantom-deps): Stable false positive for this package. ai
phantom-deps phantom-dep:@types/koa-compose AI (phantom-deps): Type-only dep; not directly imported at runtime by design. ai
typosquat typosquat.levenshtein:ajv AI (typosquat): Scoped @vtex/api is not a typosquat of ajv; false positive. ai
typosquat typosquat.levenshtein:joi AI (typosquat): Scoped @vtex/api is not a typosquat of joi; false positive. ai
typosquat typosquat.levenshtein:pg AI (typosquat): Scoped @vtex/api is not a typosquat of pg; false positive. ai
semgrep semgrep:dynamic-require AI (semgrep): Loads service.json config file at a known path; not arbitrary module loading. ai
semgrep semgrep:base64-decode AI (semgrep): Decodes a base64-encoded JSON binding value; standard framework pattern, not obfuscation. ai
typosquat typosquat.levenshtein:hapi AI (typosquat): Scoped @vtex/api is not a typosquat of hapi; Levenshtein match is a false positive for scoped packages. ai

Versions (showing 10 of 10)

Version Deps Published
7.3.1 46 / 34
7.3.0 46 / 34
7.2.7 46 / 34
7.2.6 46 / 34
7.2.1 45 / 34
7.2.0 45 / 34
7.1.0 41 / 34
7.0.1 41 / 34
7.0.0 41 / 34
6.51.0 41 / 34

v7.3.0

3 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

HIGH Publisher changed: tiagonapoli → GitHub Actions (on 2025-12-16) provenance

This version was published by a different npm account than previous versions on 2025-12-16. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.2.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v7.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v6.51.0

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.