← Home

@launchdarkly/session-replay

21
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

launchdarkly

Keywords

launchdarklysession replaydebuggingobservabilitybrowserlibrary

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/index-6I8VmpDC.js AI (source-diff): Standard Vite build output with accompanying source map; not malicious obfuscation. ai
source-diff obfuscated-file:dist/index-CKqZvJsH.js AI (source-diff): Vite build output with accompanying source map; standard minification for this LaunchDarkly SDK package. ai
provenance missing-githead AI (provenance): Side-effect of GitHub Actions publish pipeline; SLSA provenance attestation provides stronger supply chain integrity. ai
source-diff obfuscated-file:dist/index-CqhCG1Zf.js AI (source-diff): Vite build output; minified bundle with accompanying source map is expected for this package. ai
source-diff obfuscated-file:dist/index-BdC2Saa4.js AI (source-diff): Standard Vite minified bundle output; source map included; consistent with package.json build toolchain. ai
source-diff obfuscated-file:dist/index-Cxm-TAmp.js AI (source-diff): Standard Vite minified bundle with accompanying source map; not obfuscation, stable pattern for this package. ai
source-diff obfuscated-file:dist/index-DfKXefeq.js AI (source-diff): Vite-bundled minified output with accompanying source map; standard build artifact for this package. ai
source-diff obfuscated-file:dist/index-CTojSwVM.js AI (source-diff): Standard Vite minified bundle; readable identifiers, no encoding. Expected for this SDK's dist output. ai
source-diff obfuscated-file:dist/index-CHfUVEJD.js AI (source-diff): Standard Vite minified bundle output; consistent with package.json build tooling for this SDK. ai
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI/CD publishing with SLSA provenance; expected for LaunchDarkly SDK automation. ai
source-diff obfuscated-file:dist/index-DDMbSYLF.js AI (source-diff): Vite build output with accompanying source map; minification is expected for this browser SDK package. ai
source-diff obfuscated-file:dist/index-ggTLMSH6.js AI (source-diff): Vite-bundled minified output with accompanying source map; standard for this package's build pipeline. ai
source-diff obfuscated-file:dist/index-DmBlfkX7.js AI (source-diff): Standard Vite/Rollup minified bundle output; not obfuscation. Stable pattern for this package. ai
publish-pattern dormant-publish AI (publish-pattern): SLSA provenance attestation confirms legitimate CI/CD publish; dormancy does not indicate takeover here. ai
source-diff encoded-string-file:dist/index.umd.js AI (source-diff): Long strings are PostCSS/source-map internals in bundled UMD output; stable pattern for this package. ai
source-diff obfuscated-file:dist/index-B9zLQZaI.js AI (source-diff): Vite build output with content-hash filename; minified but not malicious — SLSA provenance confirms CI/CD origin. ai

Versions (showing 21 of 21)

Version Deps Published
1.1.9 1 / 4
1.1.8 1 / 4
1.1.7 1 / 4
1.1.6 1 / 4
1.1.5 1 / 4
1.1.4 1 / 4
1.1.3 1 / 4
1.1.2 1 / 4
1.1.1 1 / 4
1.1.0 1 / 4
1.0.3 1 / 4
1.0.2 1 / 4
1.0.1 1 / 4
1.0.0 1 / 4
0.5.2 1 / 4
0.5.1 1 / 4
0.5.0 1 / 4
0.4.12 1 / 4
0.4.11 1 / 4
0.4.9 1 / 4
0.4.8 1 / 4

v1.1.9

2 findings
HIGH New obfuscated file: dist/index-CKqZvJsH.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.7

3 findings
HIGH New obfuscated file: dist/index-ggTLMSH6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH Long encoded string in modified file: dist/index.umd.js source-diff

Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.6

3 findings
HIGH New obfuscated file: dist/index-DmBlfkX7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH Long encoded string in modified file: dist/index.umd.js source-diff

Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.5

3 findings
HIGH New obfuscated file: dist/index-B9zLQZaI.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH Long encoded string in modified file: dist/index.umd.js source-diff

Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.2

4 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

HIGH Publisher changed: launchdarkly → GitHub Actions (on 2026-04-01) provenance

This version was published by a different npm account than previous versions on 2026-04-01. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/index-DfKXefeq.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.1

3 findings
HIGH Publisher changed: launchdarkly → GitHub Actions (on 2026-03-31) provenance

This version was published by a different npm account than previous versions on 2026-03-31. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/index-DfKXefeq.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.0

3 findings
HIGH Publisher changed: launchdarkly → GitHub Actions (on 2026-03-27) provenance

This version was published by a different npm account than previous versions on 2026-03-27. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/index-CHfUVEJD.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.3

2 findings
HIGH New obfuscated file: dist/index-BdC2Saa4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.2

2 findings
HIGH New obfuscated file: dist/index-Cxm-TAmp.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.1

2 findings
HIGH New obfuscated file: dist/index-CqhCG1Zf.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.0

2 findings
HIGH New obfuscated file: dist/index-CTojSwVM.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.2

2 findings
HIGH New obfuscated file: dist/index-CTojSwVM.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.1

2 findings
HIGH New obfuscated file: dist/index-6I8VmpDC.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.0

2 findings
HIGH New obfuscated file: dist/index-DDMbSYLF.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.12

2 findings
HIGH New obfuscated file: dist/index-DDMbSYLF.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.11

2 findings
HIGH New obfuscated file: dist/index-DDMbSYLF.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.