express-rate-limit
Basic IP rate-limiting middleware for Express. Use to limit repeated requests to public APIs and/or endpoints such as password reset.
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | regressed-provenance | AI (provenance): Manual publish by known maintainer on a 48M/wk canonical package; no compromise indicator. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): ip-address replaces deprecated ip dep; legitimate established package. | ai | |
| provenance | publisher-changed | AI (provenance): Publisher changed to GitHub Actions with SLSA provenance — this is a CI/CD publishing migration, standard for mature packages. | ai |
Versions (showing 51 of 116)
| Version | Deps | Published |
|---|---|---|
| 8.6.1 | 2 / 25 | |
| 8.6.0 | 2 / 25 | |
| 8.5.2 | 1 / 23 | |
| 8.5.1 | 1 / 23 | |
| 8.5.0 | 1 / 23 | |
| 8.4.1 | 1 / 23 | |
| 8.4.0 | 1 / 23 | |
| 8.3.2 | 1 / 23 | |
| 8.3.1 | 1 / 23 | |
| 8.3.0 | 1 / 23 | |
| 8.0.2 | 1 / 23 | |
| 8.0.0 | 1 / 24 | |
| 7.5.1 | 0 / 22 | |
| 7.5.0 | 0 / 22 | |
| 7.4.1 | 0 / 22 | |
| 7.4.0 | 0 / 22 | |
| 7.3.1 | 0 / 22 | |
| 7.3.0 | 0 / 22 | |
| 7.2.0 | 0 / 22 | |
| 7.1.5 | 0 / 22 | |
| 7.1.4 | 0 / 21 | |
| 7.1.3 | 0 / 21 | |
| 7.1.2 | 0 / 21 | |
| 7.1.1 | 0 / 21 | |
| 7.1.0 | 0 / 21 | |
| 7.0.2 | 0 / 21 | |
| 7.0.1 | 0 / 22 | |
| 7.0.0 | 0 / 22 | |
| 6.11.2 | 0 / 22 | |
| 6.11.1 | 0 / 22 | |
| 6.11.0 | 0 / 22 | |
| 6.10.0 | 0 / 22 | |
| 6.9.0 | 0 / 19 | |
| 6.8.1 | 0 / 19 | |
| 6.8.0 | 0 / 19 | |
| 6.7.2 | 0 / 19 | |
| 6.7.1 | 0 / 19 | |
| 6.7.0 | 0 / 19 | |
| 6.6.0 | 0 / 19 | |
| 6.5.2 | 0 / 19 | |
| 6.5.1 | 0 / 19 | |
| 6.4.0 | 0 / 19 | |
| 6.3.0 | 0 / 19 | |
| 6.2.1 | 0 / 19 | |
| 6.2.0 | 0 / 19 | |
| 6.1.0 | 0 / 19 | |
| 6.0.5 | 0 / 19 | |
| 6.0.4 | 0 / 19 | |
| 6.0.3 | 0 / 19 | |
| 6.0.2 | 0 / 19 | |
| 6.0.1 | 0 / 18 |
v8.6.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.6.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.3.0
2 findingsThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. The axios attack (March 2026) exhibited exactly this pattern.
This version was published by a different npm account (gamemaker1) than the most recent previously approved version (nfriedly) on 2026-03-05, but gamemaker1 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v8.0.2
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: gamemaker1.
[Accepted risk] This version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. The axios attack (March 2026) exhibited exactly this pattern.