@types/yargs
TypeScript definitions for yargs
51
Versions
MIT
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
No source commit
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
types
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| email-domain | unclaimed-email:https://github.com/poelstra | AI (email-domain): The 'email' field contains a GitHub profile URL, not an email address. The analyzer incorrectly treats the URL as an email domain. No actual domain hijack risk exists. | ai | |
| dependencies | unvetted-dep:@types/yargs-parser | AI (dependencies): @types/yargs-parser is the standard companion types package for yargs-parser; its inclusion in @types/yargs is expected and stable across all versions. | ai | |
| phantom-deps | phantom-dep:@types/yargs-parser | AI (phantom-deps): @types/* packages are resolved by TypeScript convention, not direct imports; phantom-dep finding is a stable false positive for this package. | ai | |
| provenance | no-provenance | AI (provenance): DefinitelyTyped packages published via the `types` publisher do not currently use Sigstore provenance; this is a known and stable characteristic of this publisher. | ai |
Versions (showing 51 of 145)
| Version | Deps | Published |
|---|---|---|
| 17.0.35 | 1 / 0 | |
| 17.0.34 | 1 / 0 | |
| 17.0.33 | 1 / 0 | |
| 17.0.32 | 1 / 0 | |
| 17.0.31 | 1 / 0 | |
| 17.0.30 | 1 / 0 | |
| 17.0.29 | 1 / 0 | |
| 17.0.28 | 1 / 0 | |
| 17.0.27 | 1 / 0 | |
| 17.0.26 | 1 / 0 | |
| 17.0.25 | 1 / 0 | |
| 17.0.24 | 1 / 0 | |
| 17.0.23 | 1 / 0 | |
| 17.0.22 | 1 / 0 | |
| 17.0.21 | 1 / 0 | |
| 17.0.20 | 1 / 0 | |
| 17.0.19 | 1 / 0 | |
| 17.0.18 | 1 / 0 | |
| 17.0.17 | 1 / 0 | |
| 17.0.16 | 1 / 0 | |
| 17.0.15 | 1 / 0 | |
| 17.0.14 | 1 / 0 | |
| 17.0.13 | 1 / 0 | |
| 17.0.12 | 1 / 0 | |
| 17.0.11 | 1 / 0 | |
| 17.0.10 | 1 / 0 | |
| 17.0.9 | 1 / 0 | |
| 17.0.8 | 1 / 0 | |
| 17.0.7 | 1 / 0 | |
| 17.0.6 | 1 / 0 | |
| 17.0.5 | 1 / 0 | |
| 17.0.4 | 1 / 0 | |
| 17.0.3 | 1 / 0 | |
| 17.0.2 | 1 / 0 | |
| 17.0.1 | 1 / 0 | |
| 17.0.0 | 1 / 0 | |
| 16.0.11 | 1 / 0 | |
| 16.0.10 | 1 / 0 | |
| 16.0.9 | 1 / 0 | |
| 16.0.8 | 1 / 0 | |
| 16.0.7 | 1 / 0 | |
| 16.0.6 | 1 / 0 | |
| 16.0.5 | 1 / 0 | |
| 16.0.4 | 1 / 0 | |
| 16.0.3 | 1 / 0 | |
| 16.0.2 | 1 / 0 | |
| 16.0.1 | 1 / 0 | |
| 16.0.0 | 1 / 0 | |
| 15.0.20 | 1 / 0 | |
| 15.0.19 | 1 / 0 | |
| 15.0.18 | 1 / 0 |
v17.0.35
1 finding
INFO
No provenance attestation
provenance
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v15.0.19
1 finding
INFO
No provenance attestation
provenance
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v15.0.18
1 finding
INFO
No provenance attestation
provenance
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.