discord-api-types
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Change to GitHub Actions CI publish with SLSA attestation on official discordjs repo; benign transition. | ai | |
| provenance | regressed-provenance | AI (provenance): Known maintainer manual publish; no payload/diff changes. Occasional non-CI publish is normal for this package. | ai |
Versions (showing 100 of 241)
| Version | Deps | Published |
|---|---|---|
| 0.38.52 | 0 / 30 | |
| 0.38.51 | 0 / 30 | |
| 0.38.50 | 0 / 30 | |
| 0.38.49 | 0 / 30 | |
| 0.38.48 | 0 / 30 | |
| 0.38.47 | 0 / 30 | |
| 0.38.46 | 0 / 30 | |
| 0.38.45 | 0 / 30 | |
| 0.38.44 | 0 / 30 | |
| 0.38.43 | 0 / 30 | |
| 0.38.42 | 0 / 30 | |
| 0.38.41 | 0 / 30 | |
| 0.38.40 | 0 / 30 | |
| 0.38.39 | 0 / 30 | |
| 0.38.38 | 0 / 30 | |
| 0.38.37 | 0 / 30 | |
| 0.38.36 | 0 / 30 | |
| 0.38.35 | 0 / 30 | |
| 0.38.34 | 0 / 30 | |
| 0.38.33 | 0 / 30 | |
| 0.38.32 | 0 / 30 | |
| 0.38.31 | 0 / 30 | |
| 0.38.30 | 0 / 30 | |
| 0.38.29 | 0 / 30 | |
| 0.38.28 | 0 / 30 | |
| 0.38.27 | 0 / 30 | |
| 0.38.26 | 0 / 30 | |
| 0.38.25 | 0 / 30 | |
| 0.38.24 | 0 / 30 | |
| 0.38.23 | 0 / 30 | |
| 0.38.22 | 0 / 30 | |
| 0.38.21 | 0 / 30 | |
| 0.38.20 | 0 / 30 | |
| 0.38.19 | 0 / 30 | |
| 0.38.18 | 0 / 30 | |
| 0.38.17 | 0 / 30 | |
| 0.38.16 | 0 / 29 | |
| 0.38.15 | 0 / 29 | |
| 0.38.14 | 0 / 29 | |
| 0.38.13 | 0 / 29 | |
| 0.38.12 | 0 / 29 | |
| 0.38.11 | 0 / 29 | |
| 0.38.10 | 0 / 29 | |
| 0.38.9 | 0 / 29 | |
| 0.38.8 | 0 / 26 | |
| 0.38.7 | 0 / 26 | |
| 0.38.6 | 0 / 26 | |
| 0.38.5 | 0 / 25 | |
| 0.38.4 | 0 / 25 | |
| 0.38.3 | 0 / 25 | |
| 0.38.2 | 0 / 25 | |
| 0.38.1 | 0 / 25 | |
| 0.38.0 | 0 / 25 | |
| 0.37.120 | 0 / 25 | |
| 0.37.119 | 0 / 25 | |
| 0.37.118 | 0 / 25 | |
| 0.37.117 | 0 / 25 | |
| 0.37.116 | 0 / 25 | |
| 0.37.115 | 0 / 25 | |
| 0.37.114 | 0 / 25 | |
| 0.37.113 | 0 / 25 | |
| 0.37.112 | 0 / 25 | |
| 0.37.111 | 0 / 25 | |
| 0.37.110 | 0 / 25 | |
| 0.37.109 | 0 / 25 | |
| 0.37.108 | 0 / 25 | |
| 0.37.107 | 0 / 26 | |
| 0.37.106 | 0 / 26 | |
| 0.37.105 | 0 / 26 | |
| 0.37.104 | 0 / 26 | |
| 0.37.103 | 0 / 26 | |
| 0.37.102 | 0 / 26 | |
| 0.37.101 | 0 / 26 | |
| 0.37.100 | 0 / 26 | |
| 0.37.99 | 0 / 26 | |
| 0.37.98 | 0 / 26 | |
| 0.37.97 | 0 / 26 | |
| 0.37.96 | 0 / 26 | |
| 0.37.95 | 0 / 26 | |
| 0.37.94 | 0 / 26 | |
| 0.37.93 | 0 / 26 | |
| 0.37.92 | 0 / 26 | |
| 0.37.91 | 0 / 26 | |
| 0.37.90 | 0 / 26 | |
| 0.37.89 | 0 / 26 | |
| 0.37.88 | 0 / 26 | |
| 0.37.87 | 0 / 26 | |
| 0.37.86 | 0 / 26 | |
| 0.37.85 | 0 / 26 | |
| 0.37.84 | 0 / 26 | |
| 0.37.83 | 0 / 26 | |
| 0.37.82 | 0 / 26 | |
| 0.37.81 | 0 / 26 | |
| 0.37.80 | 0 / 26 | |
| 0.37.79 | 0 / 26 | |
| 0.37.78 | 0 / 26 | |
| 0.37.77 | 0 / 26 | |
| 0.37.76 | 0 / 26 | |
| 0.37.75 | 0 / 26 | |
| 0.37.74 | 0 / 26 |
v0.38.52
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.38.51
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.38.50
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.38.31
2 findingsThis version was published by a different npm account than previous versions on 2025-10-23. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.38.11
1 finding[Accepted risk] This version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. The axios attack (March 2026) exhibited exactly this pattern.
v0.38.10
1 finding[Accepted risk] This version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. The axios attack (March 2026) exhibited exactly this pattern.
v0.38.9
1 finding[Accepted risk] This version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. The axios attack (March 2026) exhibited exactly this pattern.
v0.38.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.38.0
2 findingsThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. The axios attack (March 2026) exhibited exactly this pattern.
This version was published by a different npm account (vladfrangu) than the most recent previously approved version (crawl) on 2025-02-16, but vladfrangu is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.37.120
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.37.119
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.37.118
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.37.117
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.37.116
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.37.115
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.37.114
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.37.113
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.37.112
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.37.111
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.37.110
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.37.109
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.37.108
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.37.107
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.37.106
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.37.105
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.37.104
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.37.103
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.37.102
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.37.101
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.37.100
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.37.99
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.37.98
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.37.97
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.37.96
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.37.95
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.37.94
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.37.93
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.37.92
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.37.91
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.37.90
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.37.89
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.37.88
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.37.87
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.37.86
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.37.85
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.37.84
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.37.83
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.37.82
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.37.81
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.37.80
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.37.79
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.37.78
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.37.77
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.37.76
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.37.75
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.37.74
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.