← Home

@n8n/chat

This is an embeddable Chat widget for n8n. It allows the execution of AI-Powered Workflows through a Chat window.

51
Versions
SEE LICENSE IN LICENSE.md
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

n8n-matsuuutomin8njan_n8n_iocornelius.suermann

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/node-icons-DDGCDo-0.mjs AI (source-diff): Long lines are URL-encoded SVG data URIs bundled by Vite; not obfuscated code. ai
source-diff obfuscated-file:dist/node-icons-Dvx0PGtJ.mjs AI (source-diff): Long lines are URL-encoded SVG data URIs from Vite bundling; not obfuscation. Stable pattern for this package. ai
source-diff obfuscated-file:dist/node-icons-5KeulgLA.mjs AI (source-diff): Long lines are URL-encoded SVG data URIs in a bundled icon module; not obfuscation. ai
source-diff obfuscated-file:dist/node-icons-CYbnl_VP.mjs AI (source-diff): Long lines are URL-encoded SVG data URIs in a bundled icon file, not obfuscated executable code. ai
source-diff obfuscated-file:dist/node-icons-ChKUwU1B.mjs AI (source-diff): Long lines are URL-encoded SVG data URIs from Vite bundling, not obfuscation; stable pattern for this package. ai
source-diff obfuscated-file:dist/node-icons-O5Clj8BC.mjs AI (source-diff): File contains only URL-encoded SVG icon data; long lines are expected for data URIs, not obfuscated code. ai
source-diff obfuscated-file:dist/node-icons-CGsST0zi.mjs AI (source-diff): Long lines are URL-encoded SVG data URIs for node icons, not obfuscated executable code. ai
source-diff obfuscated-file:dist/node-icons-BfpANqUU.mjs AI (source-diff): File contains URL-encoded SVG icon data from n8n's design-system; long lines are a build artifact, not obfuscation. ai
source-diff obfuscated-file:dist/node-icons-CKgMxpAY.mjs AI (source-diff): File contains URL-encoded SVG icon data URIs; long lines are expected minified build output, not obfuscation. ai
source-diff obfuscated-file:dist/node-icons-Ca5tmG4k.mjs AI (source-diff): File contains URL-encoded SVG data URIs for node icons — standard build output, not obfuscation. ai
source-diff obfuscated-file:dist/node-icons-B8yj9hZx.mjs AI (source-diff): Long lines are URL-encoded SVG data URIs for node icons, not obfuscated malicious code; pattern is stable for this package. ai
maintainer-change maintainer-added AI (maintainer-change): New maintainers are n8n org members; consistent with internal team expansion, not a hostile takeover. ai
provenance publisher-changed AI (provenance): tomin8n is an n8n org account with 10 approved packages; SLSA provenance confirms CI/CD publish from official repo. ai
phantom-deps phantom-dep:@n8n/design-system AI (phantom-deps): Same-org scoped package; consumed at build time in bundled output. ai
phantom-deps phantom-dep:highlight.js AI (phantom-deps): Bundled Vue component; deps consumed at build time, not via direct imports in analyzed source. ai
phantom-deps phantom-dep:@vueuse/core AI (phantom-deps): Bundled Vue component; deps consumed at build time, not via direct imports in analyzed source. ai
typosquat typosquat.levenshtein:chalk AI (typosquat): @n8n/chat is the official n8n chat widget; no relation to chalk; scoped package name makes typosquatting implausible. ai
phantom-deps phantom-dep:uuid AI (phantom-deps): Bundled Vue component; deps consumed at build time, not via direct imports in analyzed source. ai
phantom-deps phantom-dep:markdown-it-link-attributes AI (phantom-deps): Bundled Vue component; deps consumed at build time, not via direct imports in analyzed source. ai
phantom-deps phantom-dep:vue-markdown-render AI (phantom-deps): Bundled Vue component; deps consumed at build time, not via direct imports in analyzed source. ai

Versions (showing 51 of 51)

Version Deps Published
1.23.0 7 / 0
1.21.0 7 / 0
1.20.1 7 / 0
1.20.0 7 / 0
1.19.0 7 / 0
1.18.3 7 / 0
1.18.2 7 / 0
1.18.1 7 / 0
1.18.0 7 / 0
1.17.2 7 / 0
1.17.1 7 / 0
1.17.0 7 / 0
1.16.0 7 / 0
1.15.0 7 / 0
1.14.0 7 / 0
1.13.2 7 / 0
1.13.1 7 / 0
1.13.0 7 / 0
1.12.0 7 / 0
1.11.2 7 / 0
1.11.1 7 / 0
1.11.0 7 / 0
1.10.1 7 / 0
1.10.0 7 / 0
1.9.3 7 / 0
1.9.2 7 / 0
1.9.1 7 / 0
1.9.0 7 / 0
1.8.0 7 / 0
1.7.1 7 / 0
1.7.0 7 / 0
1.6.1 7 / 0
1.6.0 7 / 0
1.5.1 7 / 0
1.5.0 7 / 0
1.4.0 7 / 0
1.3.0 7 / 0
1.2.1 7 / 0
1.2.0 7 / 0
1.1.1 7 / 0
1.1.0 7 / 0
1.0.0 7 / 0
0.68.3 7 / 0
0.68.2 7 / 0
0.68.1 7 / 0
0.68.0 7 / 0
0.67.0 7 / 0
0.66.1 7 / 0
0.66.0 7 / 0
0.65.0 7 / 0
0.64.0 7 / 0

v1.23.0

2 findings
HIGH New obfuscated file: dist/node-icons-DDGCDo-0.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.21.0

2 findings
HIGH New obfuscated file: dist/node-icons-ChKUwU1B.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.20.1

2 findings
HIGH New obfuscated file: dist/node-icons-Dvx0PGtJ.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.20.0

2 findings
HIGH New obfuscated file: dist/node-icons-5KeulgLA.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.19.0

2 findings
HIGH New obfuscated file: dist/node-icons-CYbnl_VP.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.18.2

2 findings
HIGH New obfuscated file: dist/node-icons-O5Clj8BC.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.18.1

2 findings
HIGH New obfuscated file: dist/node-icons-Ca5tmG4k.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.18.0

2 findings
HIGH New obfuscated file: dist/node-icons-BfpANqUU.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.17.2

2 findings
HIGH New obfuscated file: dist/node-icons-CKgMxpAY.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.17.1

2 findings
HIGH New obfuscated file: dist/node-icons-CGsST0zi.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.17.0

2 findings
HIGH New obfuscated file: dist/node-icons-B8yj9hZx.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.16.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.15.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.14.0

2 findings
HIGH Publisher changed: jan_n8n_io → GitHub Actions (on 2026-03-24) provenance

This version was published by a different npm account than previous versions on 2026-03-24. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.13.2

2 findings
HIGH Publisher changed: jan_n8n_io → GitHub Actions (on 2026-03-20) provenance

This version was published by a different npm account than previous versions on 2026-03-20. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.13.1

2 findings
HIGH Publisher changed: jan_n8n_io → GitHub Actions (on 2026-03-18) provenance

This version was published by a different npm account than previous versions on 2026-03-18. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.13.0

2 findings
HIGH Publisher changed: jan_n8n_io → GitHub Actions (on 2026-03-16) provenance

This version was published by a different npm account than previous versions on 2026-03-16. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.12.0

2 findings
HIGH Publisher changed: jan_n8n_io → GitHub Actions (on 2026-03-09) provenance

This version was published by a different npm account than previous versions on 2026-03-09. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.11.2

2 findings
HIGH Publisher changed: jan_n8n_io → GitHub Actions (on 2026-03-11) provenance

This version was published by a different npm account than previous versions on 2026-03-11. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.11.1

2 findings
HIGH Publisher changed: jan_n8n_io → GitHub Actions (on 2026-03-09) provenance

This version was published by a different npm account than previous versions on 2026-03-09. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.11.0

2 findings
HIGH Publisher changed: jan_n8n_io → GitHub Actions (on 2026-03-02) provenance

This version was published by a different npm account than previous versions on 2026-03-02. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.10.1

2 findings
HIGH Publisher changed: jan_n8n_io → GitHub Actions (on 2026-02-27) provenance

This version was published by a different npm account than previous versions on 2026-02-27. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.10.0

2 findings
HIGH Publisher changed: jan_n8n_io → GitHub Actions (on 2026-02-23) provenance

This version was published by a different npm account than previous versions on 2026-02-23. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.9.3

2 findings
HIGH Publisher changed: jan_n8n_io → GitHub Actions (on 2026-02-25) provenance

This version was published by a different npm account than previous versions on 2026-02-25. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.9.2

2 findings
HIGH Publisher changed: jan_n8n_io → GitHub Actions (on 2026-02-23) provenance

This version was published by a different npm account than previous versions on 2026-02-23. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.9.1

2 findings
HIGH Publisher changed: jan_n8n_io → GitHub Actions (on 2026-02-18) provenance

This version was published by a different npm account than previous versions on 2026-02-18. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.9.0

2 findings
HIGH Publisher changed: jan_n8n_io → GitHub Actions (on 2026-02-16) provenance

This version was published by a different npm account than previous versions on 2026-02-16. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.8.0

2 findings
HIGH Publisher changed: jan_n8n_io → GitHub Actions (on 2026-02-10) provenance

This version was published by a different npm account than previous versions on 2026-02-10. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.7.1

2 findings
HIGH Publisher changed: jan_n8n_io → tomin8n (on 2026-02-09) provenance

This version was published by a different npm account than previous versions on 2026-02-09. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.68.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.68.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.68.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.68.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.67.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.66.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.66.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.65.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.64.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.