@launchdarkly/session-replay
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/index-6I8VmpDC.js | AI (source-diff): Standard Vite build output with accompanying source map; not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-CKqZvJsH.js | AI (source-diff): Vite build output with accompanying source map; standard minification for this LaunchDarkly SDK package. | ai | |
| provenance | missing-githead | AI (provenance): Side-effect of GitHub Actions publish pipeline; SLSA provenance attestation provides stronger supply chain integrity. | ai | |
| source-diff | obfuscated-file:dist/index-CqhCG1Zf.js | AI (source-diff): Vite build output; minified bundle with accompanying source map is expected for this package. | ai | |
| source-diff | obfuscated-file:dist/index-BdC2Saa4.js | AI (source-diff): Standard Vite minified bundle output; source map included; consistent with package.json build toolchain. | ai | |
| source-diff | obfuscated-file:dist/index-Cxm-TAmp.js | AI (source-diff): Standard Vite minified bundle with accompanying source map; not obfuscation, stable pattern for this package. | ai | |
| source-diff | obfuscated-file:dist/index-DfKXefeq.js | AI (source-diff): Vite-bundled minified output with accompanying source map; standard build artifact for this package. | ai | |
| source-diff | obfuscated-file:dist/index-CTojSwVM.js | AI (source-diff): Standard Vite minified bundle; readable identifiers, no encoding. Expected for this SDK's dist output. | ai | |
| source-diff | obfuscated-file:dist/index-CHfUVEJD.js | AI (source-diff): Standard Vite minified bundle output; consistent with package.json build tooling for this SDK. | ai | |
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions CI/CD publishing with SLSA provenance; expected for LaunchDarkly SDK automation. | ai | |
| source-diff | obfuscated-file:dist/index-DDMbSYLF.js | AI (source-diff): Vite build output with accompanying source map; minification is expected for this browser SDK package. | ai | |
| source-diff | obfuscated-file:dist/index-ggTLMSH6.js | AI (source-diff): Vite-bundled minified output with accompanying source map; standard for this package's build pipeline. | ai | |
| source-diff | obfuscated-file:dist/index-DmBlfkX7.js | AI (source-diff): Standard Vite/Rollup minified bundle output; not obfuscation. Stable pattern for this package. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): SLSA provenance attestation confirms legitimate CI/CD publish; dormancy does not indicate takeover here. | ai | |
| source-diff | encoded-string-file:dist/index.umd.js | AI (source-diff): Long strings are PostCSS/source-map internals in bundled UMD output; stable pattern for this package. | ai | |
| source-diff | obfuscated-file:dist/index-B9zLQZaI.js | AI (source-diff): Vite build output with content-hash filename; minified but not malicious — SLSA provenance confirms CI/CD origin. | ai |
Versions (showing 21 of 21)
| Version | Deps | Published |
|---|---|---|
| 1.1.9 | 1 / 4 | |
| 1.1.8 | 1 / 4 | |
| 1.1.7 | 1 / 4 | |
| 1.1.6 | 1 / 4 | |
| 1.1.5 | 1 / 4 | |
| 1.1.4 | 1 / 4 | |
| 1.1.3 | 1 / 4 | |
| 1.1.2 | 1 / 4 | |
| 1.1.1 | 1 / 4 | |
| 1.1.0 | 1 / 4 | |
| 1.0.3 | 1 / 4 | |
| 1.0.2 | 1 / 4 | |
| 1.0.1 | 1 / 4 | |
| 1.0.0 | 1 / 4 | |
| 0.5.2 | 1 / 4 | |
| 0.5.1 | 1 / 4 | |
| 0.5.0 | 1 / 4 | |
| 0.4.12 | 1 / 4 | |
| 0.4.11 | 1 / 4 | |
| 0.4.9 | 1 / 4 | |
| 0.4.8 | 1 / 4 |
v1.1.9
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.1.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.1.7
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.1.6
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.1.5
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.1.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.1.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.1.2
4 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
This version was published by a different npm account than previous versions on 2026-04-01. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.1.1
3 findingsThis version was published by a different npm account than previous versions on 2026-03-31. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.1.0
3 findingsThis version was published by a different npm account than previous versions on 2026-03-27. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.3
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.2
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.1
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.2
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.1
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.12
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.11
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.