@medusajs/analytics-local
Local analytics provider for Medusa
41
Versions
MIT
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
sebrindomoliverjuhlnicolas-gorgasradevskiolijuhl
Keywords
medusa-pluginmedusa-plugin-analytics
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | no-provenance | AI (provenance): Large Medusa monorepo package; provenance attestation not historically enabled for this package family. | ai | |
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions CI publisher with SLSA attestation; consistent with Medusa monorepo CI/CD migration. | ai |
Versions (showing 41 of 41)
| Version | Deps | Published |
|---|---|---|
| 2.18.0 | 0 / 1 | |
| 2.17.0 | 0 / 1 | |
| 2.16.0 | 0 / 1 | |
| 2.15.5 | 0 / 1 | |
| 2.15.3 | 0 / 1 | |
| 2.15.2 | 0 / 1 | |
| 2.15.1 | 0 / 1 | |
| 2.15.0 | 0 / 1 | |
| 2.14.2 | 0 / 1 | |
| 2.14.1 | 0 / 1 | |
| 2.14.0 | 0 / 1 | |
| 2.13.6 | 0 / 1 | |
| 2.13.5 | 0 / 1 | |
| 2.13.4 | 0 / 1 | |
| 2.13.3 | 0 / 1 | |
| 2.13.2 | 0 / 1 | |
| 2.13.1 | 0 / 1 | |
| 2.13.0 | 0 / 1 | |
| 2.12.6 | 0 / 1 | |
| 2.12.5 | 0 / 1 | |
| 2.12.4 | 0 / 1 | |
| 2.12.3 | 0 / 1 | |
| 2.12.2 | 0 / 1 | |
| 2.12.1 | 0 / 1 | |
| 2.12.0 | 0 / 1 | |
| 2.11.3 | 0 / 1 | |
| 2.11.2 | 0 / 6 | |
| 2.11.1 | 0 / 6 | |
| 2.11.0 | 0 / 6 | |
| 2.10.3 | 0 / 6 | |
| 2.10.2 | 0 / 6 | |
| 2.10.1 | 0 / 6 | |
| 2.10.0 | 0 / 6 | |
| 2.9.0 | 0 / 6 | |
| 2.8.8 | 0 / 6 | |
| 2.8.7 | 0 / 6 | |
| 2.8.6 | 0 / 6 | |
| 2.8.5 | 0 / 6 | |
| 2.8.4 | 0 / 6 | |
| 2.8.3 | 0 / 6 | |
| 2.8.2 | 0 / 6 |
v2.18.0
1 finding
HIGH
Provenance attestation missing — previous versions had it
provenance
This version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.