← Home

@n8n/chat

This is an embeddable Chat widget for n8n. It allows the execution of AI-Powered Workflows through a Chat window.

71
Versions
SEE LICENSE IN LICENSE.md
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

cornelius_n8n_ion8n-matsuuutomin8njan_n8n_ion8n-charliekolb

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/node-icons-jTe9UIcY.mjs AI (source-diff): Long lines are packed SVG icon data URIs from the bundler, not obfuscated logic. ai
source-diff obfuscated-file:dist/node-icons-BQn2QBdU.mjs AI (source-diff): Bundled SVG icon data-URIs, not obfuscation; part of design-system asset bundle. ai
source-diff obfuscated-file:dist/node-icons-DvZup5iL.mjs AI (source-diff): Bundled SVG icon data-URLs cause long lines; no true obfuscation signature. ai
source-diff obfuscated-file:dist/node-icons-B9nJxSvI.mjs AI (source-diff): Long lines are inlined SVG data-URIs for icons, not obfuscated code. ai
source-diff obfuscated-file:dist/node-icons-D2vOg0kY.mjs AI (source-diff): Bundled SVG icon data URIs, long lines are asset data not obfuscation. ai
source-diff obfuscated-file:dist/node-icons-BHcibv9B.mjs AI (source-diff): Bundled SVG icon data URIs, single long line from minification not obfuscation. ai
source-diff obfuscated-file:dist/node-icons-VdkeXtY6.mjs AI (source-diff): Bundled SVG data-URI icon asset, not obfuscated logic; long lines are inline SVGs. ai
source-diff obfuscated-file:dist/node-icons-C4jja2Zy.mjs AI (source-diff): Bundled SVG icon data-URIs, long lines not obfuscation. ai
publish-pattern new-deps-added AI (publish-pattern): markdown-it is a well-known, widely used markdown parser matching stated chat rendering feature. ai
source-diff obfuscated-file:dist/node-icons-Bqaz83-4.mjs AI (source-diff): File contains URL-encoded SVG icon data, not obfuscated executable code; long lines are expected for data URIs. ai
source-diff obfuscated-file:dist/node-icons-BVPh4HTC.mjs AI (source-diff): Long lines are URL-encoded SVG data URIs in a bundled icon file; not obfuscation or malicious code. ai
source-diff obfuscated-file:dist/node-icons-Y_bSQrsa.mjs AI (source-diff): Long lines are URL-encoded SVG data URIs for node icons — standard build output, not obfuscation. ai
source-diff obfuscated-file:dist/node-icons-DcZQleXB.mjs AI (source-diff): File contains URL-encoded SVG icon data bundled as JS data URIs — standard build output for this UI component package. ai
source-diff obfuscated-file:dist/node-icons-C8sh8mtt.mjs AI (source-diff): Long lines are URL-encoded SVG data URIs for node icons, not obfuscated code. ai
source-diff obfuscated-file:dist/node-icons-ChnytiKZ.mjs AI (source-diff): File contains URL-encoded SVG data URIs for node icons — standard build output, not obfuscation. ai
source-diff obfuscated-file:dist/node-icons-D_gsYPkJ.mjs AI (source-diff): Long lines are URL-encoded SVG data URIs from bundled icon assets, not obfuscated malicious code. ai
source-diff obfuscated-file:dist/node-icons-BplsIZ5d.mjs AI (source-diff): Long lines are URL-encoded SVG data URIs in a Vite build artifact, not obfuscation or malicious code. ai
phantom-deps phantom-dep:markdown-it AI (phantom-deps): markdown-it is bundled into dist; phantom-dep is a false positive for this build pattern. ai
source-diff obfuscated-file:dist/node-icons-DvxN7FBJ.mjs AI (source-diff): Long lines are URL-encoded SVG data URIs for node icons, not obfuscated code. ai
source-diff encoded-string-file:dist/chat.bundle.es.js AI (source-diff): Base64 string is the entities/htmlDecodeTree lookup table from markdown-it's dependency chain, not a payload. ai
source-diff encoded-string-file:dist/chat.es.js AI (source-diff): Same htmlDecodeTree base64 table as chat.bundle.es.js; benign markdown-it dependency artifact. ai
source-diff obfuscated-file:dist/node-icons-DDGCDo-0.mjs AI (source-diff): Long lines are URL-encoded SVG data URIs bundled by Vite; not obfuscated code. ai
source-diff obfuscated-file:dist/node-icons-Dvx0PGtJ.mjs AI (source-diff): Long lines are URL-encoded SVG data URIs from Vite bundling; not obfuscation. Stable pattern for this package. ai
source-diff obfuscated-file:dist/node-icons-5KeulgLA.mjs AI (source-diff): Long lines are URL-encoded SVG data URIs in a bundled icon module; not obfuscation. ai
source-diff obfuscated-file:dist/node-icons-CYbnl_VP.mjs AI (source-diff): Long lines are URL-encoded SVG data URIs in a bundled icon file, not obfuscated executable code. ai
source-diff obfuscated-file:dist/node-icons-ChKUwU1B.mjs AI (source-diff): Long lines are URL-encoded SVG data URIs from Vite bundling, not obfuscation; stable pattern for this package. ai
source-diff obfuscated-file:dist/node-icons-O5Clj8BC.mjs AI (source-diff): File contains only URL-encoded SVG icon data; long lines are expected for data URIs, not obfuscated code. ai
source-diff obfuscated-file:dist/node-icons-CGsST0zi.mjs AI (source-diff): Long lines are URL-encoded SVG data URIs for node icons, not obfuscated executable code. ai
source-diff obfuscated-file:dist/node-icons-BfpANqUU.mjs AI (source-diff): File contains URL-encoded SVG icon data from n8n's design-system; long lines are a build artifact, not obfuscation. ai
source-diff obfuscated-file:dist/node-icons-CKgMxpAY.mjs AI (source-diff): File contains URL-encoded SVG icon data URIs; long lines are expected minified build output, not obfuscation. ai
source-diff obfuscated-file:dist/node-icons-Ca5tmG4k.mjs AI (source-diff): File contains URL-encoded SVG data URIs for node icons — standard build output, not obfuscation. ai
source-diff obfuscated-file:dist/node-icons-B8yj9hZx.mjs AI (source-diff): Long lines are URL-encoded SVG data URIs for node icons, not obfuscated malicious code; pattern is stable for this package. ai
maintainer-change maintainer-added AI (maintainer-change): New maintainers are n8n org members; consistent with internal team expansion, not a hostile takeover. ai
provenance publisher-changed AI (provenance): tomin8n is an n8n org account with 10 approved packages; SLSA provenance confirms CI/CD publish from official repo. ai
phantom-deps phantom-dep:highlight.js AI (phantom-deps): Bundled Vue component; deps consumed at build time, not via direct imports in analyzed source. ai
phantom-deps phantom-dep:markdown-it-link-attributes AI (phantom-deps): Bundled Vue component; deps consumed at build time, not via direct imports in analyzed source. ai
phantom-deps phantom-dep:vue-markdown-render AI (phantom-deps): Bundled Vue component; deps consumed at build time, not via direct imports in analyzed source. ai
phantom-deps phantom-dep:@n8n/design-system AI (phantom-deps): Same-org scoped package; consumed at build time in bundled output. ai
phantom-deps phantom-dep:uuid AI (phantom-deps): Bundled Vue component; deps consumed at build time, not via direct imports in analyzed source. ai
phantom-deps phantom-dep:@vueuse/core AI (phantom-deps): Bundled Vue component; deps consumed at build time, not via direct imports in analyzed source. ai
typosquat typosquat.levenshtein:chalk AI (typosquat): @n8n/chat is the official n8n chat widget; no relation to chalk; scoped package name makes typosquatting implausible. ai

Versions (showing 71 of 71)

Version Deps Published
1.30.1 8 / 0
1.30.0 8 / 0
1.29.1 8 / 0
1.29.0 8 / 0
1.28.3 8 / 0
1.28.2 8 / 0
1.28.1 8 / 0
1.28.0 8 / 0
1.27.2 7 / 0
1.27.1 7 / 0
1.27.0 7 / 0
1.26.0 7 / 0
1.25.0 7 / 0
1.24.2 7 / 0
1.24.1 7 / 0
1.24.0 7 / 0
1.23.0 7 / 0
1.22.0 7 / 0
1.21.0 7 / 0
1.20.1 7 / 0
1.20.0 7 / 0
1.19.0 7 / 0
1.18.3 7 / 0
1.18.2 7 / 0
1.18.1 7 / 0
1.18.0 7 / 0
1.17.2 7 / 0
1.17.1 7 / 0
1.17.0 7 / 0
1.16.0 7 / 0
1.15.0 7 / 0
1.14.0 7 / 0
1.13.2 7 / 0
1.13.1 7 / 0
1.13.0 7 / 0
1.12.0 7 / 0
1.11.2 7 / 0
1.11.1 7 / 0
1.11.0 7 / 0
1.10.1 7 / 0
1.10.0 7 / 0
1.9.3 7 / 0
1.9.2 7 / 0
1.9.1 7 / 0
1.9.0 7 / 0
1.8.0 7 / 0
1.7.1 7 / 0
1.7.0 7 / 0
1.6.1 7 / 0
1.6.0 7 / 0
1.5.1 7 / 0
1.5.0 7 / 0
1.4.0 7 / 0
1.3.0 7 / 0
1.2.1 7 / 0
1.2.0 7 / 0
1.1.1 7 / 0
1.1.0 7 / 0
1.0.0 7 / 0
0.68.6 7 / 0
0.68.5 7 / 0
0.68.4 7 / 0
0.68.3 7 / 0
0.68.2 7 / 0
0.68.1 7 / 0
0.68.0 7 / 0
0.67.0 7 / 0
0.66.1 7 / 0
0.66.0 7 / 0
0.65.0 7 / 0
0.64.0 7 / 0

v1.30.1

2 findings
HIGH New obfuscated file: dist/node-icons-BQn2QBdU.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.30.0

2 findings
HIGH New obfuscated file: dist/node-icons-jTe9UIcY.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.29.1

2 findings
HIGH New obfuscated file: dist/node-icons-C4jja2Zy.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.29.0

2 findings
HIGH New obfuscated file: dist/node-icons-B9nJxSvI.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.28.3

2 findings
HIGH New obfuscated file: dist/node-icons-DvZup5iL.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.28.2

2 findings
HIGH New obfuscated file: dist/node-icons-BHcibv9B.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.28.1

2 findings
HIGH New obfuscated file: dist/node-icons-VdkeXtY6.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.28.0

4 findings
HIGH New obfuscated file: dist/node-icons-DvxN7FBJ.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH Long encoded string in modified file: dist/chat.bundle.es.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: dist/chat.es.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.27.2

2 findings
HIGH New obfuscated file: dist/node-icons-D2vOg0kY.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.22.0

2 findings
HIGH New obfuscated file: dist/node-icons-DcZQleXB.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.68.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.68.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.