@amplitude/experiment-tag
Amplitude Experiment Javascript Snippet
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@amplitude/experiment-core | AI (phantom-deps): Same-org dep likely bundled into dist; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:dom-mutator | AI (phantom-deps): URL dep bundled into dist output; phantom-dep heuristic is a stable FP here. | ai | |
| phantom-deps | phantom-dep:@amplitude/experiment-js-client | AI (phantom-deps): Same-org dep likely bundled into dist; stable false positive for this package. | ai | |
| dependencies | unvetted-dep:rollup-plugin-license | AI (dependencies): rollup-plugin-license is a build tool; its presence in runtime deps appears to be a packaging artifact alongside its devDependency declaration. | ai | |
| phantom-deps | phantom-dep:rollup-plugin-license | AI (phantom-deps): Build-time tool declared in both deps and devDeps; not imported at runtime. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Amplitude org package; sparse README/keywords are cosmetic, not indicative of spam. | ai | |
| npm-metadata | url-dep:dom-mutator | AI (npm-metadata): Git dep is pinned to a specific commit SHA, not a mutable branch; stable pattern for this Amplitude package. | ai | |
| phantom-deps | phantom-dep:@amplitude/analytics-core | AI (phantom-deps): First-party Amplitude dep; phantom-dep heuristic likely misfires on bundled output. | ai |
Versions (showing 8 of 8)
| Version | Deps | Published |
|---|---|---|
| 0.23.4 | 6 / 4 | |
| 0.23.3 | 6 / 4 | |
| 0.21.1 | 6 / 3 | |
| 0.19.1 | 6 / 3 | |
| 0.19.0 | 6 / 3 | |
| 0.9.1 | 5 / 3 | |
| 0.6.2 | 4 / 2 | |
| 0.6.0 | 4 / 2 |
v0.23.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.23.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.21.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.19.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.19.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.9.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.