@octokit/endpoint
Turns REST API endpoints into generic request options
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | source-size-tripled | AI (source-diff): Size increase is explained by adoption of Pika Pack multi-format build pipeline producing dist-node, dist-web, and bundled web variants. Legitimate architectural change. | ai | |
| provenance | missing-githead | AI (provenance): Octokit migrated to @pika/pack build system in this version; gitHead absence is a known side effect of the Pika publish flow, not a sign of tampering. | ai | |
| source-diff | large-new-source-files | AI (source-diff): New files are @pika/pack dist outputs (dist-node, dist-web, dist-types, dist-src) — intentional multi-format distribution, confirmed by pika:true in package.json. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): deepmerge is a well-known, widely-used utility package pinned to an exact version (2.2.1). Its use is appropriate for a package that merges REST API request options. No malicious signal. | ai | |
| provenance | publisher-changed | AI (provenance): gr2m is the canonical Octokit maintainer and package author; octokitbot was an automation account. The transition back to the primary maintainer is legitimate and expected for this package. | ai | |
| provenance | no-provenance | AI (provenance): Package predates Sigstore provenance on npm (published 2019); absence of attestation is expected for this era and not a risk signal. | ai | |
| dependencies | unvetted-dep:universal-user-agent | AI (dependencies): universal-user-agent is a well-known Octokit ecosystem utility for user-agent string generation; stable dependency across all @octokit/* packages. | ai |
Versions (showing 51 of 85)
| Version | Deps | Published |
|---|---|---|
| 11.0.3 | 2 / 9 | |
| 11.0.2 | 2 / 10 | |
| 11.0.1 | 2 / 10 | |
| 11.0.0 | 2 / 10 | |
| 10.1.4 | 2 / 10 | |
| 10.1.3 | 2 / 10 | |
| 9.0.6 | 2 / 10 | |
| 9.0.4 | 2 / 10 | |
| 9.0.3 | 2 / 10 | |
| 9.0.2 | 3 / 10 | |
| 9.0.1 | 3 / 10 | |
| 9.0.0 | 3 / 10 | |
| 8.0.1 | 3 / 10 | |
| 8.0.0 | 3 / 10 | |
| 7.0.6 | 3 / 10 | |
| 7.0.5 | 3 / 11 | |
| 7.0.4 | 3 / 11 | |
| 7.0.3 | 3 / 11 | |
| 7.0.2 | 3 / 11 | |
| 7.0.1 | 3 / 11 | |
| 7.0.0 | 3 / 11 | |
| 6.0.12 | 3 / 11 | |
| 6.0.11 | 3 / 11 | |
| 6.0.10 | 3 / 11 | |
| 6.0.9 | 3 / 11 | |
| 6.0.8 | 3 / 11 | |
| 6.0.7 | 3 / 11 | |
| 6.0.6 | 3 / 11 | |
| 6.0.5 | 3 / 11 | |
| 6.0.4 | 3 / 11 | |
| 6.0.3 | 3 / 11 | |
| 6.0.2 | 3 / 11 | |
| 6.0.1 | 3 / 11 | |
| 6.0.0 | 3 / 11 | |
| 5.5.3 | 3 / 11 | |
| 5.5.2 | 3 / 11 | |
| 5.5.1 | 3 / 11 | |
| 5.5.0 | 3 / 11 | |
| 5.4.1 | 2 / 18 | |
| 5.4.0 | 2 / 18 | |
| 5.3.6 | 2 / 16 | |
| 5.3.5 | 2 / 16 | |
| 5.3.4 | 2 / 16 | |
| 5.3.3 | 3 / 17 | |
| 5.3.2 | 4 / 19 | |
| 5.3.1 | 4 / 19 | |
| 5.3.0 | 4 / 19 | |
| 5.2.2 | 4 / 19 | |
| 5.2.1 | 4 / 19 | |
| 5.2.0 | 4 / 19 | |
| 5.1.8 | 4 / 19 |
v11.0.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.0.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v10.1.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v10.1.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.0.6
1 findingThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. The axios attack (March 2026) exhibited exactly this pattern.
v9.0.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.0.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.0.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.0.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.0.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.0.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.0.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.0.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.0.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.0.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.0.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.0.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.0.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.0.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.0.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.0.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.0.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.0.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.0.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.0.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.0.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.0.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.0.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.0.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.0.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.0.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.0.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.5.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.5.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.5.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.5.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.4.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.4.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.3.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.3.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.3.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.3.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.3.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.3.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.3.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.2.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.2.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: octokitbot.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.2.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: octokitbot.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.1.8
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: octokitbot.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.