generated: '2026-08-13' method: searched source: https://registry.npmjs.org/ checked: '2026-08-13' notes: >- Chili Piper publishes first-party browser embed libraries under the @chilipiper npm scope. No first-party server-side SDK was found on PyPI, Maven Central, NuGet, pkg.go.dev, RubyGems, Packagist or crates.io - the Edge API is consumed directly over HTTPS with a bearer token. currency_finding: >- Both first-party npm packages are stale relative to the API they front. The current Concierge distribution (@chilipiper/conciergejs-fire) last published 2025-10-03 and the older @chilipiper/concierge last published 2025-02-13 - roughly 10 and 18 months before this check, while the Edge API and MCP agent surface shipped changes as recently as 2026-08 (see changelog/chili-piper-changelog.yml). Chili Piper's developer investment is visibly going into the MCP/agent surface rather than the browser embed packages. repository_finding: >- Both packages declare repository git+ssh://git@github.com/Chili-Piper/concierge.git and homepage https://github.com/Chili-Piper/concierge#readme, but that repository returns HTTP 404 - it is private or deleted, and it does not appear among the 15 public repos in the Chili-Piper GitHub org. A consumer following the published source link from npm reaches a dead page. packages: - language: javascript registry: npm name: "@chilipiper/concierge" url: https://www.npmjs.com/package/@chilipiper/concierge install: npm install @chilipiper/concierge version: 1.1.93 published: '2025-02-13' first_published: '2022-08-03' release_count: 6 license: MIT repository: https://github.com/Chili-Piper/concierge repository_status: 404 official: true status: superseded description: Chili Piper Concierge browser embed - form submission handoff to routing and scheduling. note: 'Superseded by @chilipiper/conciergejs-fire. 6 releases total; last published 2025-02-13.' - language: javascript registry: npm name: "@chilipiper/conciergejs-fire" url: https://www.npmjs.com/package/@chilipiper/conciergejs-fire install: npm install @chilipiper/conciergejs-fire version: 1.3.6045 published: '2025-10-03' first_published: '2024-09-10' release_count: 9 license: MIT repository: https://github.com/Chili-Piper/concierge repository_status: 404 official: true status: current description: Chili Piper Concierge Fire browser embed - the current Concierge JS snippet distribution. note: >- The current Concierge distribution. In practice the embed is loaded from the per-tenant CDN path https://.chilipiper.com/concierge-js/cjs/concierge.js rather than from npm, and that loader URL is unpinned - a consumer cannot tell which build they are served. See components/chili-piper-components.yml. third_party: - language: javascript registry: npm name: react-chilipiper-concierge url: https://www.npmjs.com/package/react-chilipiper-concierge official: false note: Community React wrapper, not published by Chili Piper. - language: javascript registry: npm name: "@masterodin/chilipiper-concierge" url: https://www.npmjs.com/package/@masterodin/chilipiper-concierge official: false note: Community fork of the Concierge embed. cdn_distribution: - name: Concierge JS loader registry: cdn url: 'https://.chilipiper.com/concierge-js/cjs/concierge.js' version: null published: null note: >- Per-tenant, unpinned CDN path with no version segment and no metadata endpoint to query, so there is no way for a consumer - or for this pipeline - to determine which build is being served. Recorded as a null version deliberately: this is the finding, not a gap in the check. registries_checked: - {registry: npm, result: found} - {registry: pypi, result: none, evidence: 'https://pypi.org/pypi/chilipiper/json -> 404'} - {registry: maven-central, result: none} - {registry: nuget, result: none} - {registry: pkg.go.dev, result: none} - {registry: rubygems, result: none} - {registry: packagist, result: none} - {registry: crates.io, result: none}