@amplitude/session-replay-browser
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:lib/scripts/index-min.js | AI (source-diff): Rollup/terser minified bundle, not obfuscation; canonical Amplitude SDK build output. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Local rimraf of upstream finder.ts; no network/exec, stable across versions. | ai | |
| source-diff | encoded-string-file:lib/scripts/session-replay-browser-min.js | AI (source-diff): Minified bundle output; standard TypeScript compilation artifacts. | ai | |
| source-diff | encoded-string-file:lib/scripts/session-replay-browser-esm.js | AI (source-diff): Minified bundle output; standard TypeScript compilation artifacts. | ai | |
| source-diff | encoded-string-file:lib/scripts/amplitude-min.umd.js | AI (source-diff): Minified UMD bundle with source map; stable pattern for this package. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Empty description is intentional for this scoped Amplitude package; stable across versions. | ai | |
| source-diff | encoded-string-file:lib/scripts/amplitude-min.js | AI (source-diff): Minified bundle with source map; stable pattern for this package. | ai | |
| provenance | missing-githead | AI (provenance): SLSA provenance attestation present; gitHead absence is a minor metadata gap, not a supply-chain risk for this well-established package. | ai | |
| source-diff | obfuscated-file:lib/scripts/session-replay-browser-esm.js | AI (source-diff): Standard minified build artifact from Amplitude's public repo; expected for this package. | ai | |
| source-diff | obfuscated-file:lib/scripts/session-replay-min.js | AI (source-diff): Standard rollup/terser minified build artifact with source map; consistent with Amplitude's documented build pipeline. | ai | |
| source-diff | obfuscated-file:lib/scripts/console-plugin-min.js | AI (source-diff): Standard rollup/terser minified build artifact with source map; consistent with Amplitude's documented build pipeline. | ai | |
| source-diff | obfuscated-file:lib/scripts/rrweb-record-min.js | AI (source-diff): Standard rollup/terser minified build artifact with source map; consistent with Amplitude's documented build pipeline. | ai | |
| source-diff | obfuscated-file:lib/scripts/session-replay-browser-min.js | AI (source-diff): Standard rollup/terser minified build artifact with source map; consistent with Amplitude's documented build pipeline. | ai | |
| source-diff | obfuscated-file:lib/scripts/targeting-min.js | AI (source-diff): Standard rollup/terser minified build artifact with source map; consistent with Amplitude's documented build pipeline. | ai | |
| dependencies | unvetted-dep:@amplitude/rrweb-utils | AI (dependencies): First-party Amplitude scoped package; consistent with session-replay SDK across all versions. | ai | |
| dependencies | unvetted-dep:@amplitude/rrweb-record | AI (dependencies): First-party Amplitude scoped package; consistent with session-replay SDK across all versions. | ai | |
| dependencies | unvetted-dep:@amplitude/rrweb-types | AI (dependencies): First-party Amplitude scoped package; consistent with session-replay SDK across all versions. | ai | |
| dependencies | unvetted-dep:@amplitude/rrweb-packer | AI (dependencies): Amplitude's own rrweb-packer fork; expected dependency for session-replay SDK. | ai | |
| dependencies | unvetted-dep:@amplitude/rrweb-plugin-console-record | AI (dependencies): Amplitude's own rrweb plugin fork; expected dependency for session-replay SDK. | ai | |
| dependencies | unvetted-dep:@amplitude/rrweb-snapshot | AI (dependencies): Amplitude's own rrweb-snapshot fork; expected dependency for session-replay SDK. | ai | |
| dependencies | unvetted-dep:@amplitude/rrweb | AI (dependencies): Amplitude's own rrweb fork; expected core dependency for session-replay SDK across all versions. | ai | |
| phantom-deps | phantom-dep:@amplitude/rrweb-utils | AI (phantom-deps): First-party @amplitude scoped dep in monorepo; phantom-dep heuristic is a false positive here. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Base64 in minified console plugin bundle is expected for session-replay encoding; no malicious payload. | ai | |
| phantom-deps | phantom-dep:@rollup/plugin-replace | AI (phantom-deps): Build-time rollup plugin loaded by convention; phantom-dep false positive. | ai | |
| phantom-deps | phantom-dep:@amplitude/analytics-client-common | AI (phantom-deps): First-party @amplitude scoped dep in monorepo; phantom-dep heuristic is a false positive here. | ai | |
| phantom-deps | phantom-dep:@amplitude/experiment-core | AI (phantom-deps): First-party @amplitude scoped dep in monorepo; phantom-dep heuristic is a false positive here. | ai | |
| phantom-deps | phantom-dep:@amplitude/rrweb-packer | AI (phantom-deps): First-party @amplitude scoped dep in monorepo; phantom-dep heuristic is a false positive here. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Reflect.get used for history API monkey-patching in session-replay; standard technique, not obfuscation. | ai |
Versions (showing 51 of 151)
| Version | Deps | Published |
|---|---|---|
| 1.19.3 | 11 / 12 | |
| 1.19.2 | 11 / 12 | |
| 1.19.1 | 10 / 12 | |
| 1.19.0 | 10 / 12 | |
| 1.18.1 | 9 / 12 | |
| 1.18.0 | 9 / 12 | |
| 1.17.0 | 9 / 12 | |
| 1.16.0 | 9 / 12 | |
| 1.15.1 | 9 / 12 | |
| 1.15.0 | 7 / 12 | |
| 1.14.3 | 7 / 12 | |
| 1.14.2 | 7 / 12 | |
| 1.14.1 | 7 / 12 | |
| 1.14.0 | 7 / 12 | |
| 1.13.9 | 7 / 12 | |
| 1.13.8 | 7 / 12 | |
| 1.13.7 | 7 / 12 | |
| 1.13.6 | 7 / 12 | |
| 1.13.5 | 7 / 12 | |
| 1.13.4 | 7 / 12 | |
| 1.13.3 | 7 / 12 | |
| 1.13.2 | 7 / 12 | |
| 1.13.1 | 7 / 12 | |
| 1.13.0 | 7 / 12 | |
| 1.12.3 | 7 / 12 | |
| 1.12.2 | 7 / 12 | |
| 1.12.1 | 7 / 12 | |
| 1.12.0 | 7 / 12 | |
| 1.11.5 | 7 / 12 | |
| 1.11.4 | 7 / 12 | |
| 1.11.3 | 7 / 12 | |
| 1.11.2 | 7 / 12 | |
| 1.11.1 | 7 / 12 | |
| 1.11.0 | 7 / 12 | |
| 1.10.0 | 7 / 12 | |
| 1.9.4 | 7 / 12 | |
| 1.9.3 | 7 / 12 | |
| 1.9.2 | 8 / 12 | |
| 1.9.1 | 8 / 12 | |
| 1.9.0 | 8 / 12 | |
| 1.8.0 | 7 / 9 | |
| 1.7.0 | 7 / 9 | |
| 1.6.1 | 7 / 9 | |
| 1.6.0 | 7 / 9 | |
| 1.5.2 | 7 / 9 | |
| 1.5.1 | 7 / 9 | |
| 1.5.0 | 7 / 9 | |
| 1.4.0 | 7 / 9 | |
| 1.3.2 | 7 / 7 | |
| 1.3.1 | 6 / 7 | |
| 1.3.0 | 6 / 7 |
v1.19.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.19.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.19.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.19.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.18.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.18.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.17.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.16.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.15.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.15.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.14.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.14.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.14.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.14.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.13.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.13.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.13.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.13.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.13.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.13.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.13.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.13.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.13.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.13.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.12.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.12.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.12.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.12.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.11.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.11.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.11.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.11.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.11.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.11.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.10.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.0
2 findingsScript: rimraf ../../node_modules/@medv/finder/finder.ts # This is required until the package is fixed upstream
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.8.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.6.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.6.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.5.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.5.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.5.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.