algoliasearch
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@algolia/client-recommendation | AI (dependencies): First-party @algolia scoped package, part of the same coordinated monorepo release at matching version 4.0.0. No independent risk. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Base64 decoding in this package is used for parsing Algolia secured API keys — a documented, legitimate feature with no malicious payload risk. | ai | |
| provenance | missing-githead | AI (provenance): Diff baseline is v5.x; v4.x maintenance releases have different build/publish tooling. Not indicative of compromise. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): All added deps are @algolia/* at matching version — standard v4.x dependency tree. Diff misleading due to v5.x baseline. | ai | |
| phantom-deps | phantom-dep:@algolia/requester-browser-xhr | AI (phantom-deps): Same as above — v4 sub-package architecture uses indirect bundled references rather than direct imports. | ai | |
| phantom-deps | phantom-dep:@algolia/cache-browser-local-storage | AI (phantom-deps): algoliasearch v4 bundles sub-packages into dist files; indirect usage via bundle is the documented architecture for this package family. | ai | |
| phantom-deps | phantom-dep:@algolia/logger-console | AI (phantom-deps): Same as above — v4 sub-package architecture uses indirect bundled references rather than direct imports. | ai | |
| phantom-deps | phantom-dep:@algolia/client-account | AI (phantom-deps): Same as above — v4 sub-package architecture uses indirect bundled references rather than direct imports. | ai | |
| provenance | publisher-changed | AI (provenance): Algolia migrated to GitHub Actions CI/CD publishing, corroborated by SLSA provenance attestation. This is a legitimate organizational change for this major company's package. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): New maintainer 'fluf' is consistent with internal Algolia team management for this established, company-owned package. | ai | |
| dependencies | unvetted-dep:@algolia/requester-node-http | AI (dependencies): First-party Algolia monorepo sub-package, always released in lockstep with algoliasearch. Not a third-party dependency. | ai | |
| dependencies | unvetted-dep:@algolia/requester-browser-xhr | AI (dependencies): First-party Algolia monorepo sub-package, always released in lockstep with algoliasearch. Not a third-party dependency. | ai | |
| dependencies | unvetted-dep:@algolia/abtesting | AI (dependencies): First-party Algolia monorepo sub-package, always released in lockstep with algoliasearch. Not a third-party dependency. | ai | |
| dependencies | unvetted-dep:@algolia/client-query-suggestions | AI (dependencies): First-party Algolia monorepo sub-package, always released in lockstep with algoliasearch. Not a third-party dependency. | ai | |
| phantom-deps | phantom-dep:@algolia/requester-fetch | AI (phantom-deps): Declared as a dependency and referenced in config files; consistent with bundling setup in this monorepo package. Not a true phantom dependency. | ai | |
| dependencies | unvetted-dep:@algolia/client-personalization | AI (dependencies): First-party Algolia monorepo sub-package, always released in lockstep with algoliasearch. Not a third-party dependency. | ai | |
| dependencies | unvetted-dep:@algolia/ingestion | AI (dependencies): First-party Algolia monorepo sub-package, always released in lockstep with algoliasearch. Not a third-party dependency. | ai | |
| dependencies | unvetted-dep:@algolia/recommend | AI (dependencies): First-party Algolia monorepo sub-package, always released in lockstep with algoliasearch. Not a third-party dependency. | ai | |
| dependencies | unvetted-dep:@algolia/monitoring | AI (dependencies): First-party Algolia monorepo sub-package, always released in lockstep with algoliasearch. Not a third-party dependency. | ai | |
| dependencies | unvetted-dep:@algolia/client-common | AI (dependencies): First-party Algolia monorepo sub-package, always released in lockstep with algoliasearch. Not a third-party dependency. | ai | |
| dependencies | unvetted-dep:@algolia/client-search | AI (dependencies): First-party Algolia monorepo sub-package, always released in lockstep with algoliasearch. Not a third-party dependency. | ai | |
| dependencies | unvetted-dep:@algolia/client-insights | AI (dependencies): First-party Algolia monorepo sub-package, always released in lockstep with algoliasearch. Not a third-party dependency. | ai | |
| dependencies | unvetted-dep:@algolia/requester-fetch | AI (dependencies): First-party Algolia monorepo sub-package, always released in lockstep with algoliasearch. Not a third-party dependency. | ai | |
| dependencies | unvetted-dep:@algolia/client-abtesting | AI (dependencies): First-party Algolia monorepo sub-package, always released in lockstep with algoliasearch. Not a third-party dependency. | ai | |
| dependencies | unvetted-dep:@algolia/client-analytics | AI (dependencies): First-party Algolia monorepo sub-package, always released in lockstep with algoliasearch. Not a third-party dependency. | ai |
Versions (showing 59 of 159)
| Version | Deps | Published |
|---|---|---|
| 4.25.1 | 15 / 0 | |
| 4.25.0 | 15 / 0 | |
| 4.24.0 | 15 / 0 | |
| 4.23.3 | 15 / 0 | |
| 4.23.2 | 15 / 0 | |
| 4.23.1 | 15 / 0 | |
| 4.23.0 | 15 / 0 | |
| 4.22.1 | 14 / 0 | |
| 4.22.0 | 14 / 0 | |
| 4.21.1 | 14 / 0 | |
| 4.21.0 | 14 / 0 | |
| 4.20.0 | 14 / 0 | |
| 4.19.1 | 14 / 0 | |
| 4.19.0 | 14 / 0 | |
| 4.18.0 | 14 / 0 | |
| 4.17.2 | 14 / 0 | |
| 4.17.1 | 14 / 0 | |
| 4.17.0 | 14 / 0 | |
| 4.16.0 | 14 / 0 | |
| 4.15.0 | 14 / 0 | |
| 4.14.3 | 14 / 0 | |
| 4.14.2 | 14 / 0 | |
| 4.14.1 | 14 / 0 | |
| 4.14.0 | 14 / 0 | |
| 4.13.1 | 14 / 0 | |
| 4.13.0 | 14 / 0 | |
| 4.12.2 | 14 / 0 | |
| 4.12.1 | 14 / 0 | |
| 4.12.0 | 14 / 0 | |
| 4.11.0 | 14 / 0 | |
| 4.10.5 | 14 / 0 | |
| 4.10.4 | 14 / 0 | |
| 4.10.3 | 14 / 0 | |
| 4.10.2 | 14 / 0 | |
| 4.10.0 | 14 / 0 | |
| 4.9.3 | 14 / 0 | |
| 4.9.2 | 14 / 0 | |
| 4.9.1 | 14 / 0 | |
| 4.9.0 | 14 / 0 | |
| 4.8.6 | 14 / 0 | |
| 4.8.5 | 14 / 0 | |
| 4.8.4 | 14 / 0 | |
| 4.8.3 | 14 / 0 | |
| 4.8.2 | 14 / 0 | |
| 4.8.1 | 14 / 0 | |
| 4.8.0 | 14 / 0 | |
| 4.7.0 | 14 / 0 | |
| 4.6.0 | 14 / 0 | |
| 4.5.1 | 14 / 0 | |
| 4.5.0 | 14 / 0 | |
| 4.4.0 | 14 / 0 | |
| 4.3.1 | 14 / 0 | |
| 4.3.0 | 14 / 0 | |
| 4.2.0 | 14 / 0 | |
| 4.1.0 | 14 / 0 | |
| 4.0.3 | 14 / 0 | |
| 4.0.2 | 14 / 0 | |
| 4.0.1 | 14 / 0 | |
| 4.0.0 | 14 / 0 |
v4.25.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: shortcuts.
v4.25.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: shortcuts.
v4.24.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.23.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.23.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.23.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.23.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.22.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.22.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.21.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.21.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.20.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.19.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.19.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.18.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.17.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.17.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.17.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.16.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.15.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.14.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.14.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.14.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.14.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.13.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.13.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.12.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.12.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.12.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.11.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.10.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.10.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.10.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.10.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.10.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.9.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.9.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.9.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.9.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.8.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.8.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.8.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.8.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.8.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.8.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.8.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.7.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.6.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.5.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.5.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.4.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.3.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.3.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.2.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.1.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.0.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.0.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.0.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.