← Home

@amplitude/session-replay-browser

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

curtisbliukelson.warnersdk.deveric_amplitudedaniel-graham-amplitudejjwang123

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:lib/scripts/index-min.js AI (source-diff): Rollup/terser minified bundle, not obfuscation; canonical Amplitude SDK build output. ai
install-scripts install-script:postinstall AI (install-scripts): Local rimraf of upstream finder.ts; no network/exec, stable across versions. ai
source-diff encoded-string-file:lib/scripts/session-replay-browser-min.js AI (source-diff): Minified bundle output; standard TypeScript compilation artifacts. ai
source-diff encoded-string-file:lib/scripts/session-replay-browser-esm.js AI (source-diff): Minified bundle output; standard TypeScript compilation artifacts. ai
source-diff encoded-string-file:lib/scripts/amplitude-min.umd.js AI (source-diff): Minified UMD bundle with source map; stable pattern for this package. ai
npm-metadata no-description AI (npm-metadata): Empty description is intentional for this scoped Amplitude package; stable across versions. ai
source-diff encoded-string-file:lib/scripts/amplitude-min.js AI (source-diff): Minified bundle with source map; stable pattern for this package. ai
provenance missing-githead AI (provenance): SLSA provenance attestation present; gitHead absence is a minor metadata gap, not a supply-chain risk for this well-established package. ai
source-diff obfuscated-file:lib/scripts/session-replay-browser-esm.js AI (source-diff): Standard minified build artifact from Amplitude's public repo; expected for this package. ai
source-diff obfuscated-file:lib/scripts/session-replay-min.js AI (source-diff): Standard rollup/terser minified build artifact with source map; consistent with Amplitude's documented build pipeline. ai
source-diff obfuscated-file:lib/scripts/console-plugin-min.js AI (source-diff): Standard rollup/terser minified build artifact with source map; consistent with Amplitude's documented build pipeline. ai
source-diff obfuscated-file:lib/scripts/rrweb-record-min.js AI (source-diff): Standard rollup/terser minified build artifact with source map; consistent with Amplitude's documented build pipeline. ai
source-diff obfuscated-file:lib/scripts/session-replay-browser-min.js AI (source-diff): Standard rollup/terser minified build artifact with source map; consistent with Amplitude's documented build pipeline. ai
source-diff obfuscated-file:lib/scripts/targeting-min.js AI (source-diff): Standard rollup/terser minified build artifact with source map; consistent with Amplitude's documented build pipeline. ai
dependencies unvetted-dep:@amplitude/rrweb-utils AI (dependencies): First-party Amplitude scoped package; consistent with session-replay SDK across all versions. ai
dependencies unvetted-dep:@amplitude/rrweb-record AI (dependencies): First-party Amplitude scoped package; consistent with session-replay SDK across all versions. ai
dependencies unvetted-dep:@amplitude/rrweb-types AI (dependencies): First-party Amplitude scoped package; consistent with session-replay SDK across all versions. ai
dependencies unvetted-dep:@amplitude/rrweb-packer AI (dependencies): Amplitude's own rrweb-packer fork; expected dependency for session-replay SDK. ai
dependencies unvetted-dep:@amplitude/rrweb-plugin-console-record AI (dependencies): Amplitude's own rrweb plugin fork; expected dependency for session-replay SDK. ai
dependencies unvetted-dep:@amplitude/rrweb-snapshot AI (dependencies): Amplitude's own rrweb-snapshot fork; expected dependency for session-replay SDK. ai
dependencies unvetted-dep:@amplitude/rrweb AI (dependencies): Amplitude's own rrweb fork; expected core dependency for session-replay SDK across all versions. ai
phantom-deps phantom-dep:@amplitude/rrweb-utils AI (phantom-deps): First-party @amplitude scoped dep in monorepo; phantom-dep heuristic is a false positive here. ai
semgrep semgrep:base64-decode AI (semgrep): Base64 in minified console plugin bundle is expected for session-replay encoding; no malicious payload. ai
phantom-deps phantom-dep:@rollup/plugin-replace AI (phantom-deps): Build-time rollup plugin loaded by convention; phantom-dep false positive. ai
phantom-deps phantom-dep:@amplitude/analytics-client-common AI (phantom-deps): First-party @amplitude scoped dep in monorepo; phantom-dep heuristic is a false positive here. ai
phantom-deps phantom-dep:@amplitude/experiment-core AI (phantom-deps): First-party @amplitude scoped dep in monorepo; phantom-dep heuristic is a false positive here. ai
phantom-deps phantom-dep:@amplitude/rrweb-packer AI (phantom-deps): First-party @amplitude scoped dep in monorepo; phantom-dep heuristic is a false positive here. ai
semgrep semgrep:api-obfuscation-reflect AI (semgrep): Reflect.get used for history API monkey-patching in session-replay; standard technique, not obfuscation. ai

Versions (showing 51 of 151)

Version Deps Published
1.19.3 11 / 12
1.19.2 11 / 12
1.19.1 10 / 12
1.19.0 10 / 12
1.18.1 9 / 12
1.18.0 9 / 12
1.17.0 9 / 12
1.16.0 9 / 12
1.15.1 9 / 12
1.15.0 7 / 12
1.14.3 7 / 12
1.14.2 7 / 12
1.14.1 7 / 12
1.14.0 7 / 12
1.13.9 7 / 12
1.13.8 7 / 12
1.13.7 7 / 12
1.13.6 7 / 12
1.13.5 7 / 12
1.13.4 7 / 12
1.13.3 7 / 12
1.13.2 7 / 12
1.13.1 7 / 12
1.13.0 7 / 12
1.12.3 7 / 12
1.12.2 7 / 12
1.12.1 7 / 12
1.12.0 7 / 12
1.11.5 7 / 12
1.11.4 7 / 12
1.11.3 7 / 12
1.11.2 7 / 12
1.11.1 7 / 12
1.11.0 7 / 12
1.10.0 7 / 12
1.9.4 7 / 12
1.9.3 7 / 12
1.9.2 8 / 12
1.9.1 8 / 12
1.9.0 8 / 12
1.8.0 7 / 9
1.7.0 7 / 9
1.6.1 7 / 9
1.6.0 7 / 9
1.5.2 7 / 9
1.5.1 7 / 9
1.5.0 7 / 9
1.4.0 7 / 9
1.3.2 7 / 7
1.3.1 6 / 7
1.3.0 6 / 7

v1.19.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.19.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.19.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.19.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.18.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.18.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.17.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.16.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.15.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.15.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.14.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.14.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.14.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.14.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.13.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.13.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.13.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.13.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.13.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.13.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.13.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.13.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.13.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.13.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.12.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.12.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.12.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.12.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.11.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.11.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.11.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.11.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.11.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.11.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.10.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.9.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.9.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.9.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.9.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.9.0

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: rimraf ../../node_modules/@medv/finder/finder.ts # This is required until the package is fixed upstream

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.8.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.6.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.5.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.5.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.3.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.3.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.