discord-api-types
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Change to GitHub Actions CI publish with SLSA attestation on official discordjs repo; benign transition. | ai | |
| provenance | regressed-provenance | AI (provenance): Known maintainer manual publish; no payload/diff changes. Occasional non-CI publish is normal for this package. | ai |
Versions (showing 51 of 241)
| Version | Deps | Published |
|---|---|---|
| 0.38.52 | 0 / 30 | |
| 0.38.51 | 0 / 30 | |
| 0.38.50 | 0 / 30 | |
| 0.38.49 | 0 / 30 | |
| 0.38.48 | 0 / 30 | |
| 0.38.47 | 0 / 30 | |
| 0.38.46 | 0 / 30 | |
| 0.38.45 | 0 / 30 | |
| 0.38.44 | 0 / 30 | |
| 0.38.43 | 0 / 30 | |
| 0.38.42 | 0 / 30 | |
| 0.38.41 | 0 / 30 | |
| 0.38.40 | 0 / 30 | |
| 0.38.39 | 0 / 30 | |
| 0.38.38 | 0 / 30 | |
| 0.38.37 | 0 / 30 | |
| 0.38.36 | 0 / 30 | |
| 0.38.35 | 0 / 30 | |
| 0.38.34 | 0 / 30 | |
| 0.38.33 | 0 / 30 | |
| 0.38.32 | 0 / 30 | |
| 0.38.31 | 0 / 30 | |
| 0.38.30 | 0 / 30 | |
| 0.38.29 | 0 / 30 | |
| 0.38.28 | 0 / 30 | |
| 0.38.27 | 0 / 30 | |
| 0.38.26 | 0 / 30 | |
| 0.38.25 | 0 / 30 | |
| 0.38.24 | 0 / 30 | |
| 0.38.23 | 0 / 30 | |
| 0.38.22 | 0 / 30 | |
| 0.38.21 | 0 / 30 | |
| 0.38.20 | 0 / 30 | |
| 0.38.19 | 0 / 30 | |
| 0.38.18 | 0 / 30 | |
| 0.38.17 | 0 / 30 | |
| 0.38.16 | 0 / 29 | |
| 0.38.15 | 0 / 29 | |
| 0.38.14 | 0 / 29 | |
| 0.38.13 | 0 / 29 | |
| 0.38.12 | 0 / 29 | |
| 0.38.11 | 0 / 29 | |
| 0.38.10 | 0 / 29 | |
| 0.38.9 | 0 / 29 | |
| 0.38.8 | 0 / 26 | |
| 0.38.7 | 0 / 26 | |
| 0.38.6 | 0 / 26 | |
| 0.38.5 | 0 / 25 | |
| 0.38.4 | 0 / 25 | |
| 0.38.3 | 0 / 25 | |
| 0.38.2 | 0 / 25 |
v0.38.52
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.38.51
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.38.50
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.38.31
2 findingsThis version was published by a different npm account than previous versions on 2025-10-23. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.38.11
1 finding[Accepted risk] This version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. The axios attack (March 2026) exhibited exactly this pattern.
v0.38.10
1 finding[Accepted risk] This version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. The axios attack (March 2026) exhibited exactly this pattern.
v0.38.9
1 finding[Accepted risk] This version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. The axios attack (March 2026) exhibited exactly this pattern.