← Home

@amplitude/analytics-client-common

51
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

curtisbliukelson.warnersdk.deveric_amplitudedaniel-graham-amplitudejjwang123

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Amplitude migrated to GitHub Actions CI publishing with SLSA attestation; stable pattern for this org. ai
npm-metadata no-description AI (npm-metadata): Amplitude's package.json intentionally has empty description; stable false positive for this package. ai

Versions (showing 51 of 113)

View all versions
Version Deps Published
2.4.58 4 / 0
2.4.57 4 / 0
2.4.56 4 / 0
2.4.55 4 / 0
2.4.54 4 / 0
2.4.53 4 / 0
2.4.52 4 / 0
2.4.51 4 / 0
2.4.50 4 / 0
2.4.49 4 / 0
2.4.48 4 / 0
2.4.47 4 / 0
2.4.46 4 / 0
2.4.45 4 / 0
2.4.44 4 / 0
2.4.43 4 / 0
2.4.42 4 / 0
2.4.41 4 / 0
2.4.36 4 / 0
2.4.34 4 / 0
2.4.33 4 / 0
2.4.31 4 / 0
2.4.30 4 / 0
2.4.28 4 / 0
2.4.22 4 / 0
2.4.21 4 / 0
2.4.20 4 / 0
2.4.19 4 / 0
2.4.18 4 / 0
2.4.17 4 / 0
2.4.16 4 / 0
2.4.15 4 / 0
2.4.14 4 / 0
2.4.13 4 / 0
2.4.12 4 / 0
2.4.11 4 / 0
2.4.10 4 / 0
2.4.9 4 / 0
2.4.8 4 / 0
2.4.7 4 / 0
2.4.6 4 / 0
2.4.5 4 / 0
2.4.4 4 / 0
2.4.3 4 / 0
2.4.2 4 / 0
2.4.1 4 / 0
2.4.0 4 / 0
2.3.42 4 / 0
2.3.41 4 / 0
2.3.40 4 / 0
2.3.39 4 / 0

v2.4.58

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.4.57

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.4.56

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.4.55

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.4.54

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.4.53

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.4.52

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.