← Home

algoliasearch

59
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

haroenvshortcutseric-zahariaflufiam4xvvospeedbluebobylitoredoxpixelasticproudlygeek

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@algolia/client-recommendation AI (dependencies): First-party @algolia scoped package, part of the same coordinated monorepo release at matching version 4.0.0. No independent risk. ai
semgrep semgrep:base64-decode AI (semgrep): Base64 decoding in this package is used for parsing Algolia secured API keys — a documented, legitimate feature with no malicious payload risk. ai
provenance missing-githead AI (provenance): Diff baseline is v5.x; v4.x maintenance releases have different build/publish tooling. Not indicative of compromise. ai
publish-pattern new-deps-added AI (publish-pattern): All added deps are @algolia/* at matching version — standard v4.x dependency tree. Diff misleading due to v5.x baseline. ai
phantom-deps phantom-dep:@algolia/requester-browser-xhr AI (phantom-deps): Same as above — v4 sub-package architecture uses indirect bundled references rather than direct imports. ai
phantom-deps phantom-dep:@algolia/cache-browser-local-storage AI (phantom-deps): algoliasearch v4 bundles sub-packages into dist files; indirect usage via bundle is the documented architecture for this package family. ai
phantom-deps phantom-dep:@algolia/logger-console AI (phantom-deps): Same as above — v4 sub-package architecture uses indirect bundled references rather than direct imports. ai
phantom-deps phantom-dep:@algolia/client-account AI (phantom-deps): Same as above — v4 sub-package architecture uses indirect bundled references rather than direct imports. ai
provenance publisher-changed AI (provenance): Algolia migrated to GitHub Actions CI/CD publishing, corroborated by SLSA provenance attestation. This is a legitimate organizational change for this major company's package. ai
maintainer-change maintainer-added AI (maintainer-change): New maintainer 'fluf' is consistent with internal Algolia team management for this established, company-owned package. ai
dependencies unvetted-dep:@algolia/requester-node-http AI (dependencies): First-party Algolia monorepo sub-package, always released in lockstep with algoliasearch. Not a third-party dependency. ai
dependencies unvetted-dep:@algolia/requester-browser-xhr AI (dependencies): First-party Algolia monorepo sub-package, always released in lockstep with algoliasearch. Not a third-party dependency. ai
dependencies unvetted-dep:@algolia/abtesting AI (dependencies): First-party Algolia monorepo sub-package, always released in lockstep with algoliasearch. Not a third-party dependency. ai
dependencies unvetted-dep:@algolia/client-query-suggestions AI (dependencies): First-party Algolia monorepo sub-package, always released in lockstep with algoliasearch. Not a third-party dependency. ai
phantom-deps phantom-dep:@algolia/requester-fetch AI (phantom-deps): Declared as a dependency and referenced in config files; consistent with bundling setup in this monorepo package. Not a true phantom dependency. ai
dependencies unvetted-dep:@algolia/client-personalization AI (dependencies): First-party Algolia monorepo sub-package, always released in lockstep with algoliasearch. Not a third-party dependency. ai
dependencies unvetted-dep:@algolia/ingestion AI (dependencies): First-party Algolia monorepo sub-package, always released in lockstep with algoliasearch. Not a third-party dependency. ai
dependencies unvetted-dep:@algolia/recommend AI (dependencies): First-party Algolia monorepo sub-package, always released in lockstep with algoliasearch. Not a third-party dependency. ai
dependencies unvetted-dep:@algolia/monitoring AI (dependencies): First-party Algolia monorepo sub-package, always released in lockstep with algoliasearch. Not a third-party dependency. ai
dependencies unvetted-dep:@algolia/client-common AI (dependencies): First-party Algolia monorepo sub-package, always released in lockstep with algoliasearch. Not a third-party dependency. ai
dependencies unvetted-dep:@algolia/client-search AI (dependencies): First-party Algolia monorepo sub-package, always released in lockstep with algoliasearch. Not a third-party dependency. ai
dependencies unvetted-dep:@algolia/client-insights AI (dependencies): First-party Algolia monorepo sub-package, always released in lockstep with algoliasearch. Not a third-party dependency. ai
dependencies unvetted-dep:@algolia/requester-fetch AI (dependencies): First-party Algolia monorepo sub-package, always released in lockstep with algoliasearch. Not a third-party dependency. ai
dependencies unvetted-dep:@algolia/client-abtesting AI (dependencies): First-party Algolia monorepo sub-package, always released in lockstep with algoliasearch. Not a third-party dependency. ai
dependencies unvetted-dep:@algolia/client-analytics AI (dependencies): First-party Algolia monorepo sub-package, always released in lockstep with algoliasearch. Not a third-party dependency. ai

Versions (showing 59 of 159)

Version Deps Published
4.25.1 15 / 0
4.25.0 15 / 0
4.24.0 15 / 0
4.23.3 15 / 0
4.23.2 15 / 0
4.23.1 15 / 0
4.23.0 15 / 0
4.22.1 14 / 0
4.22.0 14 / 0
4.21.1 14 / 0
4.21.0 14 / 0
4.20.0 14 / 0
4.19.1 14 / 0
4.19.0 14 / 0
4.18.0 14 / 0
4.17.2 14 / 0
4.17.1 14 / 0
4.17.0 14 / 0
4.16.0 14 / 0
4.15.0 14 / 0
4.14.3 14 / 0
4.14.2 14 / 0
4.14.1 14 / 0
4.14.0 14 / 0
4.13.1 14 / 0
4.13.0 14 / 0
4.12.2 14 / 0
4.12.1 14 / 0
4.12.0 14 / 0
4.11.0 14 / 0
4.10.5 14 / 0
4.10.4 14 / 0
4.10.3 14 / 0
4.10.2 14 / 0
4.10.0 14 / 0
4.9.3 14 / 0
4.9.2 14 / 0
4.9.1 14 / 0
4.9.0 14 / 0
4.8.6 14 / 0
4.8.5 14 / 0
4.8.4 14 / 0
4.8.3 14 / 0
4.8.2 14 / 0
4.8.1 14 / 0
4.8.0 14 / 0
4.7.0 14 / 0
4.6.0 14 / 0
4.5.1 14 / 0
4.5.0 14 / 0
4.4.0 14 / 0
4.3.1 14 / 0
4.3.0 14 / 0
4.2.0 14 / 0
4.1.0 14 / 0
4.0.3 14 / 0
4.0.2 14 / 0
4.0.1 14 / 0
4.0.0 14 / 0

v4.25.1

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: shortcuts.

v4.25.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: shortcuts.

v4.24.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.23.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.23.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.23.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.23.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.22.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.22.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.21.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.21.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.20.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.19.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.19.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.18.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.17.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.17.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.17.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.16.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.15.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.14.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.14.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.14.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.14.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.13.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.13.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.12.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.12.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.12.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.11.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.10.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.10.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.10.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.10.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.10.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.9.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.9.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.9.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.9.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.8.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.8.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.8.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.8.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.8.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.8.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.8.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.5.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.3.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.