@storybook/client-api
Storybook Client API
44
Versions
MIT
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
ndelangenshilmantmeasdayghengeveldwinkervsbecksyannbfkylegachjreinholdkasperpeulenvalentinpalkovicdomyenstorybook-bot
Keywords
storybook
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@storybook/core-events | AI (phantom-deps): Same-org scoped package used indirectly. Legitimate for this package. | ai | |
| phantom-deps | phantom-dep:lodash | AI (phantom-deps): Declared in package.json; used indirectly through utilities. Legitimate for this package. | ai | |
| phantom-deps | phantom-dep:store2 | AI (phantom-deps): Declared in package.json; used indirectly. Legitimate for this package. | ai | |
| phantom-deps | phantom-dep:memoizerific | AI (phantom-deps): Declared in package.json; used indirectly. Legitimate for this package. | ai | |
| phantom-deps | phantom-dep:fast-deep-equal | AI (phantom-deps): Declared in package.json; used indirectly. Legitimate for this package. | ai | |
| phantom-deps | phantom-dep:@storybook/channels | AI (phantom-deps): Same-org scoped package used indirectly through public API. Legitimate for this package. | ai | |
| phantom-deps | phantom-dep:regenerator-runtime | AI (phantom-deps): Known implicit runtime dependency; declared in package.json. Legitimate for this package. | ai | |
| provenance | publisher-changed | AI (provenance): storybook-bot is the official Storybook automation publisher with a strong track record (13196 approved). This reflects a legitimate org-wide migration to bot-based publishing, not a compromise. | ai | |
| bogus-package | bogus-package | AI (bogus-package): This is a documented deprecated facade/shim package that re-exports from @storybook/preview-api. Tiny payload and minimal README are expected and stable for this package. | ai | |
| dependencies | unvetted-dep:@types/qs | AI (dependencies): @types/qs is a standard TypeScript type definition package for the qs library; its inclusion as a dependency is a known Storybook pattern and poses no security risk. | ai | |
| phantom-deps | phantom-dep:@types/qs | AI (phantom-deps): TypeScript type package declared as dependency for type resolution; not directly imported at runtime. Normal pattern for Storybook packages. | ai | |
| provenance | no-provenance | AI (provenance): Package predates Sigstore provenance on npm; published by a highly trusted maintainer with 13,868 approved packages. Absence of provenance is expected for this era. | ai | |
| phantom-deps | phantom-dep:@types/webpack-env | AI (phantom-deps): TypeScript type package for webpack environment globals; loaded by convention, not direct import. Standard for bundler-aware libraries. | ai | |
| phantom-deps | phantom-dep:@storybook/channel-postmessage | AI (phantom-deps): Same-org sibling package; loaded by framework convention rather than direct import. Expected pattern for Storybook ecosystem packages. | ai |
Versions (showing 44 of 244)
| Version | Deps | Published |
|---|---|---|
| 5.3.3 | 16 / 0 | |
| 5.3.2 | 16 / 0 | |
| 5.3.1 | 16 / 0 | |
| 5.3.0 | 16 / 0 | |
| 5.2.8 | 16 / 0 | |
| 5.2.7 | 15 / 0 | |
| 5.2.6 | 15 / 0 | |
| 5.2.5 | 15 / 0 | |
| 5.2.4 | 15 / 0 | |
| 5.2.3 | 15 / 0 | |
| 5.2.2 | 15 / 0 | |
| 5.2.1 | 15 / 0 | |
| 5.2.0 | 15 / 0 | |
| 5.1.11 | 12 / 0 | |
| 5.1.10 | 12 / 0 | |
| 5.1.9 | 12 / 0 | |
| 5.1.8 | 12 / 0 | |
| 5.1.7 | 12 / 0 | |
| 5.1.5 | 12 / 0 | |
| 5.1.4 | 12 / 0 | |
| 5.1.3 | 12 / 0 | |
| 5.1.1 | 12 / 0 | |
| 5.0.11 | 14 / 0 | |
| 5.0.10 | 14 / 0 | |
| 5.0.9 | 14 / 0 | |
| 5.0.8 | 14 / 0 | |
| 5.0.7 | 14 / 0 | |
| 5.0.6 | 14 / 0 | |
| 5.0.5 | 14 / 0 | |
| 5.0.4 | 14 / 0 | |
| 5.0.3 | 13 / 0 | |
| 5.0.2 | 13 / 0 | |
| 5.0.1 | 13 / 0 | |
| 5.0.0 | 13 / 0 | |
| 0.0.0-pr-34011-sha-c45b0f3f | 2 / 0 | |
| 0.0.0-pr-34011-sha-1f3f0b01 | 2 / 0 | |
| 0.0.0-pr-33859-sha-95913f7f | 2 / 0 | |
| 0.0.0-pr-33859-sha-3b5f3a7d | 2 / 0 | |
| 0.0.0-pr-33859-sha-2907ae70 | 2 / 0 | |
| 0.0.0-pr-33859-sha-13cfcf7c | 2 / 0 | |
| 0.0.0-pr-33846-sha-e0cc7193 | 2 / 0 | |
| 0.0.0-pr-33846-sha-d3bab8e5 | 2 / 0 | |
| 0.0.0-pr-33846-sha-a9ac2fb4 | 2 / 0 | |
| 0.0.0-pr-33846-sha-6794f13b | 2 / 0 |