← Home

@n8n/instance-ai

59
Versions
SEE LICENSE IN LICENSE.md
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

cornelius_n8n_ion8n-matsuuutomin8njan_n8n_ion8n-charliekolb

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:undici AI (phantom-deps): Implicit runtime dependency; stable pattern for this package. ai
phantom-deps phantom-dep:@langchain/anthropic AI (phantom-deps): Config-file reference; stable pattern for this package's AI integration. ai
maintainer-change maintainer-added AI (maintainer-change): n8n org username rename; CI/CD publishing with SLSA provenance confirms legitimate org control. ai
maintainer-change maintainer-removed AI (maintainer-change): Same individual, username change within n8n org; not a package takeover. ai
publish-pattern new-deps-added AI (publish-pattern): n8n monorepo with SLSA provenance; new dep @thednp/dommatrix is a benign DOM utility. ai
source-diff obfuscated-file:dist/tools/orchestration/data-table-agent.prompt.d.ts AI (source-diff): Long lines are AI prompt strings in a .d.ts declaration file, not obfuscated code. Stable false positive for this package. ai
source-diff obfuscated-file:dist/tools/orchestration/eval-setup-agent.prompt.d.ts AI (source-diff): Long line is a TypeScript string literal containing an LLM prompt — fully readable, not obfuscated code. ai
phantom-deps phantom-dep:fast-glob AI (phantom-deps): Referenced in config/build files; stable false positive for this monorepo package. ai
source-diff large-new-source-files AI (source-diff): Active n8n monorepo package; large file additions reflect legitimate feature growth, not injection. ai
npm-metadata url-dep:xlsx AI (npm-metadata): SheetJS CDN distribution is the official install method since npm removal; known pattern. ai
dependencies unvetted-dep:xlsx AI (dependencies): SheetJS distributes via CDN tarball as documented; stable pattern for this library. ai
publish-pattern rapid-publish AI (publish-pattern): Automated CI/CD publishing from n8n monorepo; rapid successive publishes are expected behavior. ai
provenance slsa-provenance AI (provenance): SLSA provenance via Sigstore confirms CI/CD publish from official n8n-io/n8n repo. ai
dependencies unvetted-dep:zod-from-json-schema-v3 AI (dependencies): Alias for zod-from-json-schema; standard npm alias pattern for version pinning. ai
dependencies unvetted-dep:@ai-sdk/provider-v5 AI (dependencies): Alias for @ai-sdk/[email protected] from Vercel AI SDK; legitimate aliasing pattern. ai
dependencies unvetted-dep:@daytonaio/sdk AI (dependencies): Legitimate Daytona SDK dependency used in n8n's AI/agent tooling; stable for this package. ai
npm-metadata no-description AI (npm-metadata): Official n8n scoped package published via CI; missing description is a packaging choice, not a malware signal. ai
phantom-deps phantom-dep:linkedom AI (phantom-deps): Config-referenced optional dep in n8n monorepo package; stable false positive. ai
phantom-deps phantom-dep:flatted AI (phantom-deps): Config-referenced optional dep in n8n monorepo package; stable false positive. ai
phantom-deps phantom-dep:p-limit AI (phantom-deps): Config-referenced optional dep in n8n monorepo package; stable false positive. ai
phantom-deps phantom-dep:@joplin/turndown-plugin-gfm AI (phantom-deps): Config-referenced optional dep in n8n monorepo package; stable false positive. ai
phantom-deps phantom-dep:@mozilla/readability AI (phantom-deps): Config-referenced optional dep in n8n monorepo package; stable false positive. ai
phantom-deps phantom-dep:pdf-parse AI (phantom-deps): Config-referenced optional dep in n8n monorepo package; stable false positive. ai
phantom-deps phantom-dep:turndown AI (phantom-deps): Config-referenced optional dep in n8n monorepo package; stable false positive. ai

Versions (showing 59 of 59)

Version Deps Published
1.18.0 31 / 13
1.17.3 31 / 13
1.17.2 31 / 13
1.17.0 31 / 13
1.16.3 31 / 13
1.16.0 31 / 13
1.15.3 31 / 12
1.15.0 31 / 12
1.14.9 29 / 12
1.14.2 29 / 12
1.14.1 29 / 12
1.14.0 29 / 12
1.13.4 28 / 12
1.13.2 28 / 12
1.12.3 26 / 13
1.12.2 26 / 13
1.12.1 26 / 13
1.12.0 26 / 13
1.11.5 26 / 13
1.11.4 26 / 13
1.11.3 26 / 13
1.11.2 26 / 13
1.11.1 26 / 13
1.11.0 26 / 13
1.10.2 26 / 9
1.10.1 26 / 9
1.10.0 26 / 9
1.9.0 26 / 9
1.8.3 27 / 9
1.8.2 26 / 9
1.8.1 26 / 9
1.8.0 26 / 9
1.7.3 30 / 9
1.7.2 30 / 9
1.7.1 30 / 9
1.7.0 30 / 9
1.6.3 28 / 9
1.6.2 28 / 9
1.6.1 28 / 9
1.6.0 28 / 9
1.5.4 24 / 8
1.5.3 24 / 8
1.5.2 24 / 8
1.5.1 24 / 8
1.5.0 24 / 8
1.4.1 24 / 5
1.4.0 24 / 5
1.3.5 24 / 5
1.3.4 24 / 5
1.3.3 24 / 5
1.3.2 24 / 5
1.3.1 24 / 5
1.3.0 24 / 5
1.2.3 23 / 5
1.2.2 23 / 5
1.2.1 23 / 5
1.2.0 23 / 5
1.1.0 19 / 4
1.0.0 19 / 4

v1.18.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.17.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.17.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.17.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.16.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.16.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.15.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.15.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.14.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.14.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.14.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.14.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.13.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.