@n8n/decorators
32
Versions
SEE LICENSE IN LICENSE.md
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
cornelius_n8n_ion8n-matsuuutomin8njan_n8n_ion8n-charliekolb
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): tomin8n is an established n8n org publisher with strong approval record; SLSA attestation confirms CI/CD provenance. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): New maintainers are known n8n org accounts; consistent with internal team transition. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): @n8n/api-types is a sibling n8n monorepo package, not a suspicious third-party dependency. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Dormancy reflects monorepo versioning cadence; SLSA provenance and official n8n-io org confirm legitimate publish. | ai | |
| dependencies | unvetted-dep:@n8n/api-types | AI (dependencies): Sibling n8n monorepo package at matching version; expected dependency for this org. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Major version bump in a monorepo; large file count increase is expected, not indicative of injected code. | ai | |
| dependencies | unvetted-dep:n8n-workflow | AI (dependencies): Core n8n-io monorepo package; expected dependency for this org's packages. | ai | |
| dependencies | unvetted-dep:@n8n/di | AI (dependencies): Internal n8n org dependency; expected sibling package from the same monorepo. | ai | |
| dependencies | unvetted-dep:@n8n/permissions | AI (dependencies): Internal n8n org dependency; expected sibling package from the same monorepo. | ai |
Versions (showing 32 of 132)
| Version | Deps | Published |
|---|---|---|
| 0.33.22 | 5 / 3 | |
| 0.33.21 | 5 / 3 | |
| 0.33.20 | 5 / 3 | |
| 0.33.19 | 5 / 3 | |
| 0.33.18 | 5 / 3 | |
| 0.33.17 | 5 / 3 | |
| 0.33.16 | 5 / 3 | |
| 0.33.15 | 5 / 3 | |
| 0.33.14 | 5 / 3 | |
| 0.33.13 | 5 / 3 | |
| 0.33.12 | 5 / 3 | |
| 0.33.11 | 5 / 3 | |
| 0.33.10 | 5 / 3 | |
| 0.33.9 | 5 / 3 | |
| 0.33.8 | 5 / 3 | |
| 0.33.7 | 5 / 3 | |
| 0.33.6 | 5 / 3 | |
| 0.33.5 | 5 / 3 | |
| 0.33.4 | 5 / 3 | |
| 0.33.3 | 5 / 3 | |
| 0.33.2 | 5 / 3 | |
| 0.33.1 | 5 / 3 | |
| 0.33.0 | 5 / 3 | |
| 0.32.1 | 5 / 3 | |
| 0.32.0 | 5 / 3 | |
| 0.31.2 | 5 / 3 | |
| 0.31.1 | 5 / 3 | |
| 0.31.0 | 5 / 3 | |
| 0.30.2 | 5 / 3 | |
| 0.30.1 | 5 / 3 | |
| 0.30.0 | 5 / 3 | |
| 0.29.0 | 5 / 3 |
v0.33.22
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.