← Home

@grafana/data

64
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

gf_joshhuntgrafanabot

Keywords

typescript

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/cjs/index.d.cts AI (source-diff): Long-line TS declaration bundle, not code obfuscation. ai
source-diff obfuscated-file:dist/esm/index.d.mts AI (source-diff): Long-line TS declaration bundle, not code obfuscation. ai
source-diff large-new-source-files AI (source-diff): New generated value-format data files, not injected code. ai
publish-pattern rapid-publish AI (publish-pattern): Monorepo lockstep release pattern across @grafana/* packages. ai
publish-pattern new-deps-added AI (publish-pattern): Well-known libs (zod, d3-scale-chromatic) added for documented theme-schema feature. ai
phantom-deps phantom-dep:tslib AI (phantom-deps): tslib is a well-known implicit runtime dep for TypeScript compiled output; stable false positive for this package. ai
phantom-deps phantom-dep:@types/d3-interpolate AI (phantom-deps): Framework-scoped @types package; stable false positive for this package. ai
phantom-deps phantom-dep:uplot AI (phantom-deps): uplot referenced in config/type exports; stable false positive for this package. ai
phantom-deps phantom-dep:@types/systemjs AI (phantom-deps): Framework-scoped @types package; stable false positive for this package. ai
phantom-deps phantom-dep:@types/string-hash AI (phantom-deps): Framework-scoped @types package; stable false positive for this package. ai
phantom-deps phantom-dep:fast_array_intersect AI (phantom-deps): Referenced in config files per analyzer note; stable false positive for this package. ai

Versions (showing 64 of 64)

Version Deps Published
13.1.1 27 / 20
13.1.0 27 / 20
13.0.4 29 / 21
13.0.3 29 / 21
13.0.2 29 / 21
13.0.1 29 / 21
13.0.0 29 / 21
12.4.6 29 / 21
12.4.5 29 / 21
12.4.4 29 / 21
12.4.3 29 / 21
12.4.2 29 / 21
12.4.1 29 / 21
12.4.0 29 / 21
12.3.9 27 / 18
12.3.8 27 / 18
12.3.7 27 / 18
12.3.6 27 / 18
12.3.5 27 / 18
12.3.4 27 / 18
12.3.3 27 / 18
12.3.2 27 / 18
12.3.1 27 / 18
12.3.0 27 / 18
12.2.10 27 / 16
12.2.9 27 / 16
12.2.8 27 / 16
12.2.7 27 / 16
12.2.6 27 / 16
12.2.5 27 / 16
12.2.4 27 / 16
12.2.3 27 / 16
12.2.2 27 / 16
12.2.1 27 / 16
12.2.0 27 / 16
12.1.10 26 / 17
12.1.9 26 / 17
12.1.8 26 / 17
12.1.7 26 / 17
12.1.6 26 / 17
12.1.5 26 / 17
12.1.4 26 / 17
12.1.3 26 / 17
12.1.2 26 / 17
12.1.1 26 / 17
12.1.0 26 / 17
12.0.10 25 / 18
12.0.9 25 / 18
12.0.8 25 / 18
12.0.5 25 / 18
12.0.4 25 / 18
12.0.3 25 / 18
12.0.2 25 / 18
12.0.1 25 / 18
12.0.0 25 / 18
11.6.16 24 / 18
11.6.15 24 / 18
11.6.14 24 / 18
11.6.13 24 / 18
11.6.12 24 / 18
11.6.11 24 / 18
11.6.10 24 / 18
11.6.9 24 / 18
11.6.8 24 / 18

v13.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.0.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v12.4.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v12.3.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v12.1.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v12.1.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v12.1.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v12.1.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v12.1.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v12.1.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v12.1.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v12.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v12.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v12.0.10

3 findings
HIGH New obfuscated file: dist/cjs/index.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/esm/index.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v12.0.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v12.0.5

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: grafanabot → GitHub Actions (on 2025-09-24, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (grafanabot) on 2025-09-24, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v12.0.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v12.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v12.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v12.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v12.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v11.6.14

3 findings
HIGH New obfuscated file: dist/cjs/index.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/esm/index.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v11.6.13

3 findings
HIGH New obfuscated file: dist/cjs/index.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/esm/index.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v11.6.12

3 findings
HIGH New obfuscated file: dist/cjs/index.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/esm/index.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v11.6.11

3 findings
HIGH New obfuscated file: dist/cjs/index.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/esm/index.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v11.6.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v11.6.9

3 findings
HIGH New obfuscated file: dist/cjs/index.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/esm/index.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v11.6.8

3 findings
HIGH New obfuscated file: dist/cjs/index.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/esm/index.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.