← Home

@kreuzberg/node

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

nhirschfeld

Keywords

document-intelligencedocument-extractiontext-extractionpdf-extractionocrpdfdocxxlsxpptxoffice-documentstable-extractionmetadata-extractionrustnapinativenodejs

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
typosquat typosquat.levenshtein:zod AI (typosquat): Unrelated package; @kreuzberg/node is a native binding for document intelligence, not a zod typosquat. ai
semgrep semgrep:child-process-execsync AI (semgrep): Used only to detect musl libc via 'ldd --version' for native binary selection — standard napi-rs pattern. ai
semgrep semgrep:child-process-import AI (semgrep): Same musl detection use case; no arbitrary command execution risk. ai
semgrep semgrep:dynamic-require AI (semgrep): Loads user-specified native library via NAPI_RS_NATIVE_LIBRARY_PATH env var — documented napi-rs override mechanism. ai
phantom-deps phantom-dep:@emnapi/runtime AI (phantom-deps): @emnapi/runtime is a runtime dep for napi-rs WASM fallback; referenced in native binding config, not directly imported in JS. ai

Versions (showing 51 of 73)

View all versions
Version Deps Published
4.10.2 2 / 9
4.10.1 2 / 10
4.10.0 2 / 10
4.9.8 2 / 10
4.9.7 2 / 10
4.9.6 2 / 10
4.9.5 2 / 10
4.9.4 2 / 10
4.9.2 2 / 10
4.9.1 2 / 10
4.9.0 2 / 10
4.8.5 2 / 10
4.8.4 2 / 10
4.8.3 2 / 10
4.8.2 2 / 10
4.8.1 2 / 10
4.8.0 2 / 10
4.7.4 2 / 10
4.7.3 2 / 10
4.7.2 2 / 10
4.7.0 2 / 10
4.6.3 2 / 10
4.6.1 2 / 10
4.6.0 2 / 10
4.5.4 2 / 10
4.5.3 2 / 10
4.5.2 2 / 10
4.5.1 2 / 10
4.5.0 2 / 10
4.4.6 2 / 10
4.4.5 2 / 10
4.4.4 2 / 10
4.4.3 2 / 10
4.4.2 2 / 10
4.4.1 2 / 10
4.4.0 2 / 10
4.3.8 2 / 10
4.3.7 2 / 10
4.3.6 2 / 10
4.3.5 2 / 10
4.3.4 2 / 10
4.3.3 2 / 10
4.3.2 2 / 10
4.3.1 2 / 10
4.3.0 2 / 10
4.2.15 2 / 10
4.2.14 2 / 10
4.2.13 2 / 10
4.2.12 2 / 10
4.2.11 2 / 10
4.2.10 2 / 10

v4.10.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.10.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.10.0

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: nhirschfeld → GitHub Actions (on 2026-07-11, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (nhirschfeld) on 2026-07-11, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.