← Home

@datadog/datadog-api-client

22
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

datadog

Keywords

apifetchdatadogtypescriptopenapi-clientopenapi-generator

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@types/node AI (phantom-deps): @types/node is a TypeScript type package consumed by the compiler, not imported at runtime. Phantom-dep finding is a stable false positive for this package. ai
phantom-deps phantom-dep:@types/pako AI (phantom-deps): @types/pako is a TypeScript type package consumed by the compiler, not imported at runtime. Phantom-dep finding is a stable false positive for this package. ai
phantom-deps phantom-dep:@types/buffer-from AI (phantom-deps): @types/buffer-from is a TypeScript type package consumed by the compiler, not imported at runtime. Phantom-dep finding is a stable false positive for this package. ai
dependencies unvetted-dep:@types/pako AI (dependencies): @types/pako is a DefinitelyTyped type definition package with no runtime behavior; low risk for this established Datadog package. ai
dependencies unvetted-dep:@types/buffer-from AI (dependencies): @types/buffer-from is a DefinitelyTyped type definition package with no runtime behavior; low risk for this established Datadog package. ai

Versions (showing 22 of 22)

Version Deps Published
1.58.0 8 / 24
1.57.0 8 / 24
1.56.0 8 / 24
1.53.0 8 / 24
1.52.0 8 / 24
1.51.0 9 / 24
1.50.0 9 / 24
1.49.0 9 / 24
1.48.0 9 / 24
1.47.0 9 / 24
1.46.0 9 / 24
1.45.0 9 / 24
1.44.0 9 / 24
1.43.0 9 / 24
1.42.0 9 / 24
1.41.0 9 / 24
1.40.0 9 / 24
1.39.0 9 / 24
1.38.0 9 / 24
1.37.0 9 / 24
1.36.0 9 / 24
1.35.0 9 / 24

v1.58.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.57.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.56.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.45.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.44.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.43.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.42.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.41.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.40.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.39.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.38.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.37.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.36.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.35.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.