← Home

@n8n/n8n-nodes-langchain

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

cornelius_n8n_ion8n-matsuuutomin8njan_n8n_ion8n-charliekolb

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:oracledb AI (phantom-deps): Optional database integration; phantom dep pattern is stable for this plugin package. ai
phantom-deps phantom-dep:@langchain/google-common AI (phantom-deps): Optional LangChain integration; phantom dep pattern is stable for this plugin package. ai
phantom-deps phantom-dep:@langchain/langgraph-checkpoint AI (phantom-deps): Config-referenced LangChain integration dependency; stable pattern for this package. ai
phantom-deps phantom-dep:@langchain/langgraph AI (phantom-deps): Config-referenced LangChain integration dependency; stable pattern for this package. ai
phantom-deps phantom-dep:@n8n/errors AI (phantom-deps): Same-org scoped package; stable pattern for n8n internal dependencies. ai
maintainer-change maintainer-removed AI (maintainer-change): Old username removed as part of org rename; not a takeover. ai
phantom-deps phantom-dep:axios AI (phantom-deps): axios is now a declared runtime dep; phantom-dep is a false positive for this package. ai
maintainer-change maintainer-added AI (maintainer-change): Internal n8n org rename; same person, different username format. ai
source-diff source-size-tripled AI (source-diff): Size growth matches 14 new runtime deps and 2491 new source files for new AI provider integrations; SLSA provenance confirms CI build. ai
publish-pattern rapid-publish AI (publish-pattern): n8n uses automated CI/CD releases; rapid successive publishes are normal for this package. ai
phantom-deps phantom-dep:mysql2 AI (phantom-deps): mysql2 is a declared optional/peer dep for MySQL vector store support; phantom-dep heuristic is a false positive here. ai
publish-pattern new-deps-added AI (publish-pattern): New deps are feature-driven integrations for a large LangChain node package; consistent with its expansion pattern across 351 versions. ai
source-diff large-new-source-files AI (source-diff): New files are tokenizer JSON data and node implementations consistent with package scope. ai
dependencies unvetted-dep:@getzep/zep-cloud AI (dependencies): Zep Cloud memory integration; expected dep. ai
dependencies unvetted-dep:@n8n/typescript-config AI (dependencies): n8n-scoped TS config; same org, expected dev dep. ai
dependencies unvetted-dep:@microsoft/agents-a365-notifications AI (dependencies): Microsoft Agents SDK integration; expected dep for MicrosoftAgent365 node. ai
dependencies unvetted-dep:@microsoft/agents-a365-observability AI (dependencies): Microsoft Agents SDK integration; expected dep for MicrosoftAgent365 node. ai
dependencies unvetted-dep:@n8n/typeorm AI (dependencies): n8n-scoped TypeORM fork; expected stable dep for this package. ai
dependencies unvetted-dep:@getzep/zep-js AI (dependencies): Zep memory integration; legitimate dep for LangChain nodes package. ai
dependencies unvetted-dep:@langchain/groq AI (dependencies): Official LangChain Groq integration; expected dep. ai
dependencies unvetted-dep:@xata.io/client AI (dependencies): Xata vector store integration; expected dep for this package. ai
dependencies unvetted-dep:generate-schema AI (dependencies): Utility dep for schema generation; stable for this package. ai
phantom-deps phantom-dep:tmp-promise AI (phantom-deps): Utility dep; stable false positive. ai
phantom-deps phantom-dep:@microsoft/agents-a365-runtime AI (phantom-deps): New Microsoft Agent365 integration dep; stable false positive. ai
phantom-deps phantom-dep:@microsoft/agents-a365-notifications AI (phantom-deps): New Microsoft Agent365 integration dep; stable false positive. ai
phantom-deps phantom-dep:@microsoft/agents-a365-tooling-extensions-langchain AI (phantom-deps): New Microsoft Agent365 integration dep; stable false positive. ai
bogus-package bogus-package AI (bogus-package): Official n8n package; short README and no keywords are expected for a monorepo sub-package. ai
phantom-deps phantom-dep:@aws-sdk/client-sso-oidc AI (phantom-deps): AWS SDK transitive dep loaded by convention; stable false positive. ai
phantom-deps phantom-dep:@n8n/typescript-config AI (phantom-deps): Same-org build config package; phantom-dep is expected and benign. ai
phantom-deps phantom-dep:@google/generative-ai AI (phantom-deps): Google AI integration dep; declared correctly. ai
phantom-deps phantom-dep:@getzep/zep-cloud AI (phantom-deps): Zep cloud integration; declared correctly. ai
phantom-deps phantom-dep:@getzep/zep-js AI (phantom-deps): Zep memory integration; declared correctly. ai
phantom-deps phantom-dep:mime-types AI (phantom-deps): Stable false positive; used in document loaders. ai
phantom-deps phantom-dep:langchain AI (phantom-deps): Core langchain dep; declared correctly, phantom-dep heuristic is a false positive. ai
phantom-deps phantom-dep:cohere-ai AI (phantom-deps): Cohere integration dep; declared correctly, phantom-dep heuristic is a false positive. ai
phantom-deps phantom-dep:ignore AI (phantom-deps): Stable false positive for this package; used in config/build tooling. ai
phantom-deps phantom-dep:d3-dsv AI (phantom-deps): Used by document loaders; declared correctly, phantom-dep is a false positive for this package. ai
phantom-deps phantom-dep:pg AI (phantom-deps): pg is a transitive/optional dep used by MemoryPostgresChat; phantom-dep heuristic fires but it's legitimately declared. ai

Versions (showing 51 of 115)

View all versions
Version Deps Published
2.32.1 95 / 22
2.32.0 95 / 22
2.31.2 95 / 21
2.31.1 95 / 21
2.31.0 95 / 21
2.30.6 95 / 20
2.30.5 95 / 20
2.30.4 95 / 20
2.30.3 95 / 20
2.30.2 95 / 20
2.30.1 95 / 20
2.30.0 95 / 20
2.29.9 95 / 20
2.29.8 95 / 20
2.29.7 95 / 20
2.29.6 95 / 20
2.29.5 95 / 20
2.29.3 93 / 20
2.29.2 93 / 20
2.29.1 93 / 20
2.29.0 93 / 20
2.28.6 90 / 13
2.28.3 88 / 13
2.28.2 88 / 13
2.27.0 84 / 15
2.26.4 84 / 15
2.26.3 84 / 15
2.26.2 84 / 15
2.26.0 84 / 15
2.25.1 81 / 15
2.25.0 81 / 15
2.24.0 81 / 15
2.23.1 81 / 15
2.23.0 81 / 15
2.22.4 81 / 15
2.22.3 81 / 15
2.22.2 81 / 15
2.22.1 81 / 15
2.22.0 81 / 15
2.21.5 80 / 15
2.21.4 80 / 15
2.21.3 80 / 15
2.21.0 80 / 15
2.20.7 80 / 12
2.20.6 80 / 12
2.20.3 80 / 12
2.20.1 80 / 12
2.20.0 80 / 12
2.19.1 80 / 12
2.19.0 80 / 12
2.18.4 80 / 12

v2.32.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.32.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.31.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.31.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.31.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.30.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.30.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.30.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.30.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.30.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.30.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.30.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.29.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.29.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.29.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.29.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.29.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.29.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.29.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.29.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.29.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.28.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.28.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.28.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.26.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.26.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.26.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.25.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.25.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.24.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.22.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.22.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.21.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.21.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.20.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.20.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.18.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.