← Home

@amplitude/plugin-page-view-tracking-browser

100
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

curtisbliukelson.warnersdk.deveric_amplitudedaniel-graham-amplitudejjwang123

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Migration from individual npm account to GitHub Actions CI/CD; SLSA provenance confirms legitimate org pipeline. ai
maintainer-change maintainer-added AI (maintainer-change): Amplitude org regularly rotates npm team members; consistent with internal team management. ai
maintainer-change maintainer-removed AI (maintainer-change): Mass removal consistent with Amplitude org restructuring npm access, not a hostile takeover. ai
publish-pattern new-deps-added AI (publish-pattern): @amplitude/analytics-core is a first-party Amplitude package; not a suspicious third-party dep. ai
provenance missing-githead AI (provenance): Published via GitHub Actions with SLSA provenance; gitHead absence is a CI config change, not a threat. ai
publish-pattern dormant-publish AI (publish-pattern): Monorepo with 249 versions; dormancy reflects per-package publish cadence, not account compromise. ai

Versions (showing 100 of 152)

Version Deps Published
2.11.11 2 / 7
2.11.10 2 / 7
2.11.9 2 / 7
2.11.8 2 / 7
2.11.7 2 / 7
2.11.6 2 / 7
2.11.5 2 / 7
2.11.4 2 / 7
2.11.3 2 / 7
2.11.2 2 / 7
2.11.1 2 / 7
2.11.0 2 / 7
2.10.2 2 / 7
2.10.1 2 / 7
2.10.0 2 / 7
2.9.6 2 / 7
2.9.5 2 / 7
2.9.4 2 / 7
2.9.3 2 / 7
2.9.2 2 / 7
2.9.1 2 / 7
2.9.0 2 / 7
2.8.7 2 / 7
2.8.6 2 / 7
2.8.5 2 / 7
2.8.4 2 / 7
2.8.3 2 / 7
2.8.2 2 / 7
2.8.1 2 / 7
2.8.0 2 / 7
2.7.3 2 / 7
2.7.2 2 / 7
2.7.1 2 / 7
2.7.0 2 / 7
2.6.12 2 / 7
2.6.11 2 / 7
2.6.10 2 / 7
2.6.9 2 / 7
2.6.8 2 / 7
2.6.7 2 / 7
2.6.6 2 / 7
2.6.5 2 / 7
2.6.4 2 / 7
2.6.3 2 / 7
2.6.2 2 / 7
2.6.1 2 / 7
2.6.0 2 / 7
2.5.7 2 / 7
2.5.6 2 / 7
2.5.5 2 / 7
2.5.4 2 / 7
2.5.3 2 / 7
2.5.2 2 / 7
2.5.1 4 / 7
2.5.0 4 / 7
2.4.4 3 / 7
2.4.3 3 / 7
2.4.2 3 / 7
2.4.1 3 / 7
2.4.0 3 / 7
2.3.48 3 / 7
2.3.47 3 / 7
2.3.46 3 / 7
2.3.45 3 / 7
2.3.44 3 / 7
2.3.43 3 / 7
2.3.42 3 / 7
2.3.41 3 / 7
2.3.40 3 / 7
2.3.39 3 / 7
2.3.38 3 / 7
2.3.37 3 / 7
2.3.36 3 / 7
2.3.35 3 / 7
2.3.34 3 / 7
2.3.33 3 / 7
2.3.32 3 / 7
2.3.31 3 / 7
2.3.30 3 / 7
2.3.29 3 / 8
2.3.27 3 / 8
2.3.26 3 / 8
2.3.25 3 / 8
2.3.24 3 / 8
2.3.23 3 / 8
2.3.22 3 / 8
2.3.21 3 / 8
2.3.20 3 / 8
2.3.19 3 / 8
2.3.18 3 / 8
2.3.17 3 / 8
2.3.16 3 / 8
2.3.15 3 / 8
2.3.14 3 / 8
2.3.13 3 / 8
2.3.12 3 / 8
2.3.11 3 / 8
2.3.10 3 / 8
2.3.9 3 / 8
2.3.8 3 / 8
Showing 100 of 152 Next page →

v2.11.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.11.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.11.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.11.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.11.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.11.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.11.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.19

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.3.18

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.3.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.3.16

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.3.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.3.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.3.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.3.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.3.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.3.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.3.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.3.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.