@vtex/api
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Transition from manual publish to GitHub Actions CI/CD is an improvement; consistent with VTEX org automation. | ai | |
| npm-metadata | url-dep:stats-lite | AI (npm-metadata): Long-standing vtex-owned GitHub dep; stable pattern for this package. | ai | |
| npm-metadata | url-dep:@types/ramda | AI (npm-metadata): types/npm-ramda#dist is the canonical community types source; stable for this package. | ai | |
| phantom-deps | phantom-dep:bluebird | AI (phantom-deps): bluebird is a declared dep used transitively; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:@types/koa | AI (phantom-deps): Type-only dep for framework; not directly imported at runtime by design. | ai | |
| phantom-deps | phantom-dep:@wry/equality | AI (phantom-deps): Stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@types/koa-compose | AI (phantom-deps): Type-only dep; not directly imported at runtime by design. | ai | |
| typosquat | typosquat.levenshtein:ajv | AI (typosquat): Scoped @vtex/api is not a typosquat of ajv; false positive. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped @vtex/api is not a typosquat of joi; false positive. | ai | |
| typosquat | typosquat.levenshtein:pg | AI (typosquat): Scoped @vtex/api is not a typosquat of pg; false positive. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Loads service.json config file at a known path; not arbitrary module loading. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Decodes a base64-encoded JSON binding value; standard framework pattern, not obfuscation. | ai | |
| typosquat | typosquat.levenshtein:hapi | AI (typosquat): Scoped @vtex/api is not a typosquat of hapi; Levenshtein match is a false positive for scoped packages. | ai |
Versions (showing 10 of 10)
| Version | Deps | Published |
|---|---|---|
| 7.3.1 | 46 / 34 | |
| 7.3.0 | 46 / 34 | |
| 7.2.7 | 46 / 34 | |
| 7.2.6 | 46 / 34 | |
| 7.2.1 | 45 / 34 | |
| 7.2.0 | 45 / 34 | |
| 7.1.0 | 41 / 34 | |
| 7.0.1 | 41 / 34 | |
| 7.0.0 | 41 / 34 | |
| 6.51.0 | 41 / 34 |
v7.3.0
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
This version was published by a different npm account than previous versions on 2025-12-16. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.2.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.1.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.0.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.51.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.