← Home

@amplitude/plugin-web-attribution-browser

<p align="center"> <a href="https://amplitude.com" target="_blank" align="center"> <img src="https://static.amplitude.com/lightning/46c85bfd91905de8047f1ee65c7c93d6fa9ee6ea/static/media/amplitude-logo-with-text.4fb9e463.svg" width="280"> </a> <b

100
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

curtisbliukelson.warnersdk.deveric_amplitudedaniel-graham-amplitudejjwang123

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Amplitude migrated to GitHub Actions CI publishing with SLSA attestation; this is the expected pattern for their SDK monorepo. ai
phantom-deps phantom-dep:@amplitude/analytics-core AI (phantom-deps): Same-org Amplitude package; used as a type/peer dependency pattern across the monorepo. ai

Versions (showing 100 of 125)

Version Deps Published
2.2.21 4 / 7
2.2.20 4 / 7
2.2.19 4 / 7
2.2.18 4 / 7
2.2.17 4 / 7
2.2.16 4 / 7
2.2.15 4 / 7
2.2.14 4 / 7
2.2.13 4 / 7
2.2.12 4 / 7
2.2.11 4 / 7
2.2.10 4 / 7
2.2.9 4 / 7
2.2.8 4 / 7
2.2.7 4 / 7
2.2.6 4 / 7
2.2.5 4 / 8
2.2.3 4 / 8
2.2.1 4 / 8
2.1.120 4 / 8
2.1.119 4 / 8
2.1.117 4 / 8
2.1.116 4 / 8
2.1.114 4 / 8
2.1.112 4 / 8
2.1.109 4 / 8
2.1.107 4 / 8
2.1.106 4 / 8
2.1.105 4 / 8
2.1.104 4 / 8
2.1.103 4 / 8
2.1.102 4 / 8
2.1.101 4 / 8
2.1.100 4 / 8
2.1.99 4 / 8
2.1.98 4 / 8
2.1.97 4 / 8
2.1.96 4 / 8
2.1.95 4 / 8
2.1.94 4 / 8
2.1.93 4 / 8
2.1.92 4 / 8
2.1.91 4 / 8
2.1.90 4 / 8
2.1.89 4 / 8
2.1.88 4 / 8
2.1.87 4 / 8
2.1.86 4 / 8
2.1.85 4 / 8
2.1.84 4 / 8
2.1.83 4 / 8
2.1.82 4 / 8
2.1.81 4 / 8
2.1.80 4 / 8
2.1.79 4 / 8
2.1.78 4 / 8
2.1.77 4 / 8
2.1.76 4 / 8
2.1.75 4 / 8
2.1.74 4 / 8
2.1.73 4 / 8
2.1.72 4 / 8
2.1.71 4 / 8
2.1.70 4 / 8
2.1.69 4 / 8
2.1.68 4 / 8
2.1.67 4 / 8
2.1.66 4 / 8
2.1.65 4 / 8
2.1.64 4 / 8
2.1.63 4 / 8
2.1.62 4 / 8
2.1.61 4 / 8
2.1.60 4 / 8
2.1.59 4 / 8
2.1.58 4 / 8
2.1.57 4 / 8
2.1.56 4 / 8
2.1.55 4 / 8
2.1.54 4 / 8
2.1.53 4 / 8
2.1.51 4 / 8
2.1.50 4 / 8
2.1.49 4 / 8
2.1.48 4 / 8
2.1.47 4 / 8
2.1.46 4 / 8
2.1.45 4 / 8
2.1.44 4 / 8
2.1.43 4 / 8
2.1.42 4 / 8
2.1.41 4 / 8
2.1.40 4 / 8
2.1.39 4 / 8
2.1.38 4 / 8
2.1.37 4 / 8
2.1.36 4 / 8
2.1.35 4 / 8
2.1.34 4 / 8
2.1.33 4 / 8
Showing 100 of 125 Next page →

v2.2.21

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.20

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.19

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.18

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.17

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.16

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.15

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.43

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.42

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.41

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.40

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.39

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.38

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.37

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.36

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.35

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.34

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.33

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.