← Home

@algolia/client-personalization

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

ejaldorauharoenvrayrutjesjerskasamousstherealwebbytkruggsylvainhlorrissaintgenezbroujoe-krebskombuchasylvaincrawler-teamamcdaid106devinalgoliajveneziaotomatiksarahdayanmaximehuangguitekmatthewbondshaejazcyril.descossytatsuromathouguixavdhagdavidrasemotteplnechshortcutspraagyajoshialphonsebleodaufabienmottedaltondickalgoliadhaya.bbengreenbankalgabetalg-bgastinneemmanuel.fortindylantientcheuandy_dsrobertmogosjcohonner-algoliacatalgoliaraed-algoliaaymeric.giraudetpjankowski5312eventexperiences_algoliataylorcjohnson_algoliasfaiqhinstantsearch-botflufleviwhalenabodelotmprevell97jkahoantoine.gilleswwalserbhinchley-algolialouishousiauxjsok_algoliaalg-adminhugowitmariamthiam01drodrigulnscyganek-algoliajasonberrybhcastlegavinwade12vascobettencourtmariaaalungucdhawke-algoliafelipe-bernalmorgan-algolia2sirockin_algoliajulia-francaisjcalgoaallam.algtecu23nyagudayevsamykettanijonathaningrammarioalgoliamasterstrikeoctavianiacobminjaslavkoviceric-zahariacmarguta-algoliaharsharora-algoliablaineventurinesarahdayanalgoliagavaudan-algoliamszmaj-algoliayutodalgsamyphilboothcarloscamposfredalgoliawabascript2lotfirafiklachlan.robertson

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
maintainer-change maintainer-added AI (maintainer-change): New maintainers all have Algolia-affiliated names (e.g. marioalgolia, masterstrike); routine team rotation at a large org. ai
publish-pattern dormant-publish AI (publish-pattern): Dormancy explained by major v4→v5 SDK rewrite; publisher is verified Algolia org account publishing to official repo. ai
source-diff source-size-tripled AI (source-diff): Size increase reflects v5 architectural change: packages now ship bundled dist artifacts. New deps are all first-party @algolia packages at matching version. ai
publish-pattern new-deps-added AI (publish-pattern): New deps are first-party @algolia/requester-* packages at same version (5.45.0), replacing old transporter abstraction in v5 rewrite. ai
maintainer-change maintainer-removed AI (maintainer-change): Maintainer removal consistent with org restructuring during major version release; publisher is verified Algolia account. ai

Versions (showing 51 of 123)

View all versions
Version Deps Published
5.53.0 4 / 6
5.52.1 4 / 6
5.52.0 4 / 6
5.51.0 4 / 6
5.50.2 4 / 6
5.50.1 4 / 6
5.50.0 4 / 6
5.49.2 4 / 6
5.49.1 4 / 6
5.49.0 4 / 6
5.48.2 4 / 6
5.48.1 4 / 6
5.46.0 4 / 6
5.45.0 4 / 6
5.44.0 4 / 6
5.43.0 4 / 6
5.42.0 4 / 6
5.41.0 4 / 6
5.40.1 4 / 6
5.40.0 4 / 6
5.39.0 4 / 6
5.38.0 4 / 6
5.37.0 4 / 6
5.36.0 4 / 6
5.35.0 4 / 6
5.34.1 4 / 6
5.34.0 4 / 6
5.33.0 4 / 6
5.32.0 4 / 6
5.31.0 4 / 6
5.30.0 4 / 6
5.29.0 4 / 6
5.28.0 4 / 6
5.27.0 4 / 6
5.26.0 4 / 6
5.25.0 4 / 6
5.24.0 4 / 6
5.23.4 4 / 6
5.23.3 4 / 6
5.23.2 4 / 6
5.23.1 4 / 6
5.23.0 4 / 6
5.22.0 4 / 6
5.21.0 4 / 6
5.20.4 4 / 6
5.20.3 4 / 6
5.20.2 4 / 6
5.20.1 4 / 6
5.20.0 4 / 6
5.19.0 4 / 6
5.18.0 4 / 6

v5.53.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.52.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.52.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.51.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.50.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.50.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.50.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.49.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.49.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.49.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.48.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.48.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.46.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.45.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.44.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.43.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.42.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.41.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.40.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.40.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.39.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.38.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.37.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.36.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.35.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.34.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.34.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.33.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.32.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.31.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.30.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.29.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.28.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.27.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.26.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.25.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.24.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.23.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.23.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.23.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.23.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.23.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.22.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.21.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.20.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.20.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.20.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.20.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.20.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.19.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.18.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.