← Home

@n8n/db

88
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

cornelius_n8n_ion8n-matsuuutomin8njan_n8n_ion8n-charliekolb

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition from manual publish (tomin8n) to GitHub Actions CI/CD with SLSA attestation is a provenance improvement, not a risk. ai
publish-pattern new-deps-added AI (publish-pattern): @n8n/utils is a first-party n8n monorepo package; not a suspicious third-party dep. ai
maintainer-change maintainer-removed AI (maintainer-change): Same as above — removal paired with addition consistent with username change, not takeover. ai
maintainer-change maintainer-added AI (maintainer-change): Appears to be an n8n org username rename; SLSA provenance and official repo confirm legitimate CI/CD publish. ai
publish-pattern rapid-publish AI (publish-pattern): n8n monorepo uses automated CI/CD with SLSA provenance; rapid publishes are expected across coordinated package releases. ai
license uncommon-license:SEE LICENSE IN LICENSE.md AI (license): Dual-license pattern (OSS + EE); stable for n8n packages. ai
source-diff large-new-source-files AI (source-diff): Active n8n monorepo package; new source files are expected across frequent releases. ai
npm-metadata no-description AI (npm-metadata): Internal monorepo package; missing description is a known pattern, not a malware signal here. ai
dependencies unvetted-dep:@n8n/typeorm AI (dependencies): Internal n8n fork of TypeORM; stable dependency for this package. ai
dependencies unvetted-dep:p-lazy AI (dependencies): p-lazy is a well-known sindresorhus utility; stable dependency for this package. ai
typosquat typosquat.levenshtein:pg AI (typosquat): Scoped @n8n/db is an internal n8n package, not a typosquat of pg. ai
phantom-deps phantom-dep:reflect-metadata AI (phantom-deps): reflect-metadata is a known implicit runtime dep for TypeORM/decorator-based packages. ai
typosquat typosquat.levenshtein:qs AI (typosquat): Scoped @n8n/db is an internal n8n package, not a typosquat of qs. ai

Versions (showing 88 of 188)

Version Deps Published
1.7.0 20 / 3
1.6.2 19 / 3
1.6.1 19 / 3
1.6.0 19 / 3
1.5.1 19 / 3
1.5.0 19 / 3
1.4.4 19 / 3
1.4.3 19 / 3
1.4.2 19 / 3
1.4.1 19 / 3
1.4.0 19 / 3
1.3.4 19 / 3
1.3.3 19 / 3
1.3.2 19 / 3
1.3.1 19 / 3
1.3.0 19 / 3
1.2.4 19 / 3
1.2.3 19 / 3
1.2.2 19 / 3
1.2.1 19 / 3
1.2.0 19 / 3
1.1.4 19 / 3
1.1.3 19 / 3
1.1.2 19 / 3
1.1.1 19 / 3
1.1.0 19 / 3
1.0.3 19 / 3
1.0.2 19 / 3
1.0.1 19 / 3
1.0.0 19 / 3
0.34.42 19 / 3
0.34.41 19 / 3
0.34.40 19 / 3
0.34.39 19 / 3
0.34.38 19 / 3
0.34.37 19 / 3
0.34.36 19 / 3
0.34.35 19 / 3
0.34.34 19 / 3
0.34.33 19 / 3
0.34.32 19 / 3
0.34.31 19 / 3
0.34.30 19 / 3
0.34.29 19 / 3
0.34.28 19 / 3
0.34.27 19 / 3
0.34.26 19 / 3
0.34.25 19 / 3
0.34.24 19 / 3
0.34.23 19 / 3
0.34.22 19 / 3
0.34.21 19 / 3
0.34.20 19 / 3
0.34.19 19 / 3
0.34.18 19 / 3
0.34.17 19 / 3
0.34.16 19 / 3
0.34.15 19 / 3
0.34.14 19 / 3
0.34.13 19 / 3
0.34.12 19 / 3
0.34.11 19 / 3
0.34.10 19 / 3
0.34.9 19 / 3
0.34.8 19 / 3
0.34.7 19 / 3
0.34.6 19 / 3
0.34.5 19 / 3
0.34.4 19 / 3
0.34.3 19 / 3
0.34.2 19 / 3
0.34.1 19 / 3
0.34.0 19 / 3
0.33.3 19 / 3
0.33.2 19 / 3
0.33.1 19 / 3
0.33.0 19 / 3
0.32.3 19 / 3
0.32.2 19 / 3
0.32.1 19 / 3
0.32.0 19 / 3
0.31.3 19 / 3
0.31.2 19 / 3
0.31.1 19 / 3
0.31.0 19 / 3
0.30.1 19 / 3
0.30.0 19 / 3
0.29.1 19 / 3

v1.7.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.6.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.6.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.5.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.34.42

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.34.41

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.34.40

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.34.39

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.34.38

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.34.36

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.34.35

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.34.34

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.34.33

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.34.32

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.34.31

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.34.29

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.34.28

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.34.27

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.34.26

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.34.25

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.34.24

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.34.23

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.34.21

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.34.18

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.34.15

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.34.13

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.34.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.34.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.34.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.34.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.34.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.33.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.32.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.