← Home

@graphql-hive/plugin-opentelemetry

51
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

dotansimhakamilkisielaardatanenisdenjotheguild-bot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:tslib AI (phantom-deps): tslib is a standard TypeScript runtime helper; stable implicit dep for this package. ai
phantom-deps phantom-dep:@graphql-mesh/types AI (phantom-deps): Type-only dep referenced in config files; not a real phantom dep concern. ai
phantom-deps phantom-dep:@opentelemetry/sdk-node AI (phantom-deps): Referenced in setup/config files; expected pattern for an OpenTelemetry plugin. ai
phantom-deps phantom-dep:@graphql-mesh/cross-helpers AI (phantom-deps): Config-file reference; stable false positive for this package. ai
phantom-deps phantom-dep:@opentelemetry/instrumentation AI (phantom-deps): Config-file reference; expected for an OpenTelemetry plugin. ai
phantom-deps phantom-dep:@opentelemetry/context-async-hooks AI (phantom-deps): Config-file reference; expected for an OpenTelemetry plugin. ai
phantom-deps phantom-dep:@opentelemetry/exporter-trace-otlp-grpc AI (phantom-deps): Config-file reference; expected for an OpenTelemetry plugin. ai
phantom-deps phantom-dep:@opentelemetry/auto-instrumentations-node AI (phantom-deps): Config-file reference; expected for an OpenTelemetry plugin. ai

Versions (showing 51 of 65)

View all versions
Version Deps Published
1.4.40 23 / 9
1.4.39 23 / 9
1.4.38 23 / 9
1.4.37 23 / 9
1.4.36 23 / 9
1.4.35 23 / 9
1.4.34 23 / 9
1.4.33 23 / 9
1.4.32 23 / 9
1.4.31 23 / 9
1.4.30 23 / 9
1.4.29 23 / 9
1.4.28 23 / 9
1.4.27 23 / 9
1.4.26 23 / 9
1.4.25 23 / 9
1.4.24 23 / 9
1.4.22 23 / 9
1.4.9 23 / 9
1.4.8 23 / 9
1.4.7 23 / 9
1.4.6 23 / 9
1.4.5 23 / 9
1.4.4 23 / 9
1.4.3 23 / 9
1.4.2 23 / 9
1.4.1 23 / 9
1.4.0 23 / 9
1.3.11 23 / 7
1.3.10 23 / 7
1.3.9 23 / 7
1.3.8 23 / 7
1.3.7 23 / 7
1.3.6 23 / 7
1.3.5 23 / 7
1.3.4 23 / 7
1.3.3 23 / 7
1.3.2 23 / 7
1.3.1 23 / 7
1.3.0 23 / 7
1.2.5 23 / 7
1.2.4 23 / 7
1.2.3 23 / 7
1.2.2 23 / 7
1.2.1 23 / 7
1.2.0 23 / 7
1.1.2 23 / 7
1.1.1 23 / 7
1.1.0 23 / 7
1.0.15 23 / 7
1.0.14 23 / 7

v1.4.40

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.39

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.38

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.37

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.36

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.35

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.34

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.33

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.32

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.