@n8n/n8n-nodes-langchain
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:oracledb | AI (phantom-deps): Optional database integration; phantom dep pattern is stable for this plugin package. | ai | |
| phantom-deps | phantom-dep:@langchain/google-common | AI (phantom-deps): Optional LangChain integration; phantom dep pattern is stable for this plugin package. | ai | |
| phantom-deps | phantom-dep:@langchain/langgraph-checkpoint | AI (phantom-deps): Config-referenced LangChain integration dependency; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@langchain/langgraph | AI (phantom-deps): Config-referenced LangChain integration dependency; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@n8n/errors | AI (phantom-deps): Same-org scoped package; stable pattern for n8n internal dependencies. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Old username removed as part of org rename; not a takeover. | ai | |
| phantom-deps | phantom-dep:axios | AI (phantom-deps): axios is now a declared runtime dep; phantom-dep is a false positive for this package. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Internal n8n org rename; same person, different username format. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size growth matches 14 new runtime deps and 2491 new source files for new AI provider integrations; SLSA provenance confirms CI build. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): n8n uses automated CI/CD releases; rapid successive publishes are normal for this package. | ai | |
| phantom-deps | phantom-dep:mysql2 | AI (phantom-deps): mysql2 is a declared optional/peer dep for MySQL vector store support; phantom-dep heuristic is a false positive here. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New deps are feature-driven integrations for a large LangChain node package; consistent with its expansion pattern across 351 versions. | ai | |
| source-diff | large-new-source-files | AI (source-diff): New files are tokenizer JSON data and node implementations consistent with package scope. | ai | |
| dependencies | unvetted-dep:@getzep/zep-cloud | AI (dependencies): Zep Cloud memory integration; expected dep. | ai | |
| dependencies | unvetted-dep:@n8n/typescript-config | AI (dependencies): n8n-scoped TS config; same org, expected dev dep. | ai | |
| dependencies | unvetted-dep:@microsoft/agents-a365-notifications | AI (dependencies): Microsoft Agents SDK integration; expected dep for MicrosoftAgent365 node. | ai | |
| dependencies | unvetted-dep:@microsoft/agents-a365-observability | AI (dependencies): Microsoft Agents SDK integration; expected dep for MicrosoftAgent365 node. | ai | |
| dependencies | unvetted-dep:@n8n/typeorm | AI (dependencies): n8n-scoped TypeORM fork; expected stable dep for this package. | ai | |
| dependencies | unvetted-dep:@getzep/zep-js | AI (dependencies): Zep memory integration; legitimate dep for LangChain nodes package. | ai | |
| dependencies | unvetted-dep:@langchain/groq | AI (dependencies): Official LangChain Groq integration; expected dep. | ai | |
| dependencies | unvetted-dep:@xata.io/client | AI (dependencies): Xata vector store integration; expected dep for this package. | ai | |
| dependencies | unvetted-dep:generate-schema | AI (dependencies): Utility dep for schema generation; stable for this package. | ai | |
| phantom-deps | phantom-dep:tmp-promise | AI (phantom-deps): Utility dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:@microsoft/agents-a365-runtime | AI (phantom-deps): New Microsoft Agent365 integration dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:@microsoft/agents-a365-notifications | AI (phantom-deps): New Microsoft Agent365 integration dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:@microsoft/agents-a365-tooling-extensions-langchain | AI (phantom-deps): New Microsoft Agent365 integration dep; stable false positive. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Official n8n package; short README and no keywords are expected for a monorepo sub-package. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/client-sso-oidc | AI (phantom-deps): AWS SDK transitive dep loaded by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:@n8n/typescript-config | AI (phantom-deps): Same-org build config package; phantom-dep is expected and benign. | ai | |
| phantom-deps | phantom-dep:@google/generative-ai | AI (phantom-deps): Google AI integration dep; declared correctly. | ai | |
| phantom-deps | phantom-dep:@getzep/zep-cloud | AI (phantom-deps): Zep cloud integration; declared correctly. | ai | |
| phantom-deps | phantom-dep:@getzep/zep-js | AI (phantom-deps): Zep memory integration; declared correctly. | ai | |
| phantom-deps | phantom-dep:mime-types | AI (phantom-deps): Stable false positive; used in document loaders. | ai | |
| phantom-deps | phantom-dep:langchain | AI (phantom-deps): Core langchain dep; declared correctly, phantom-dep heuristic is a false positive. | ai | |
| phantom-deps | phantom-dep:cohere-ai | AI (phantom-deps): Cohere integration dep; declared correctly, phantom-dep heuristic is a false positive. | ai | |
| phantom-deps | phantom-dep:ignore | AI (phantom-deps): Stable false positive for this package; used in config/build tooling. | ai | |
| phantom-deps | phantom-dep:d3-dsv | AI (phantom-deps): Used by document loaders; declared correctly, phantom-dep is a false positive for this package. | ai | |
| phantom-deps | phantom-dep:pg | AI (phantom-deps): pg is a transitive/optional dep used by MemoryPostgresChat; phantom-dep heuristic fires but it's legitimately declared. | ai |
Versions (showing 100 of 115)
| Version | Deps | Published |
|---|---|---|
| 2.32.1 | 95 / 22 | |
| 2.32.0 | 95 / 22 | |
| 2.31.2 | 95 / 21 | |
| 2.31.1 | 95 / 21 | |
| 2.31.0 | 95 / 21 | |
| 2.30.6 | 95 / 20 | |
| 2.30.5 | 95 / 20 | |
| 2.30.4 | 95 / 20 | |
| 2.30.3 | 95 / 20 | |
| 2.30.2 | 95 / 20 | |
| 2.30.1 | 95 / 20 | |
| 2.30.0 | 95 / 20 | |
| 2.29.9 | 95 / 20 | |
| 2.29.8 | 95 / 20 | |
| 2.29.7 | 95 / 20 | |
| 2.29.6 | 95 / 20 | |
| 2.29.5 | 95 / 20 | |
| 2.29.3 | 93 / 20 | |
| 2.29.2 | 93 / 20 | |
| 2.29.1 | 93 / 20 | |
| 2.29.0 | 93 / 20 | |
| 2.28.6 | 90 / 13 | |
| 2.28.3 | 88 / 13 | |
| 2.28.2 | 88 / 13 | |
| 2.27.0 | 84 / 15 | |
| 2.26.4 | 84 / 15 | |
| 2.26.3 | 84 / 15 | |
| 2.26.2 | 84 / 15 | |
| 2.26.0 | 84 / 15 | |
| 2.25.1 | 81 / 15 | |
| 2.25.0 | 81 / 15 | |
| 2.24.0 | 81 / 15 | |
| 2.23.1 | 81 / 15 | |
| 2.23.0 | 81 / 15 | |
| 2.22.4 | 81 / 15 | |
| 2.22.3 | 81 / 15 | |
| 2.22.2 | 81 / 15 | |
| 2.22.1 | 81 / 15 | |
| 2.22.0 | 81 / 15 | |
| 2.21.5 | 80 / 15 | |
| 2.21.4 | 80 / 15 | |
| 2.21.3 | 80 / 15 | |
| 2.21.0 | 80 / 15 | |
| 2.20.7 | 80 / 12 | |
| 2.20.6 | 80 / 12 | |
| 2.20.3 | 80 / 12 | |
| 2.20.1 | 80 / 12 | |
| 2.20.0 | 80 / 12 | |
| 2.19.1 | 80 / 12 | |
| 2.19.0 | 80 / 12 | |
| 2.18.4 | 80 / 12 | |
| 2.18.1 | 80 / 12 | |
| 2.18.0 | 80 / 12 | |
| 2.16.0 | 80 / 12 | |
| 2.15.1 | 80 / 12 | |
| 2.14.1 | 80 / 12 | |
| 2.14.0 | 80 / 12 | |
| 2.13.1 | 80 / 12 | |
| 2.13.0 | 80 / 12 | |
| 2.12.0 | 80 / 12 | |
| 2.11.2 | 80 / 12 | |
| 2.11.1 | 80 / 12 | |
| 2.11.0 | 80 / 12 | |
| 2.10.2 | 80 / 12 | |
| 2.10.1 | 80 / 12 | |
| 2.10.0 | 80 / 12 | |
| 2.9.1 | 80 / 12 | |
| 2.9.0 | 80 / 12 | |
| 2.8.1 | 80 / 12 | |
| 2.8.0 | 80 / 12 | |
| 2.7.2 | 82 / 12 | |
| 2.7.1 | 82 / 12 | |
| 2.7.0 | 82 / 12 | |
| 2.6.3 | 75 / 12 | |
| 2.6.2 | 75 / 12 | |
| 2.6.1 | 75 / 12 | |
| 2.6.0 | 75 / 12 | |
| 2.5.2 | 75 / 13 | |
| 2.5.1 | 75 / 13 | |
| 2.5.0 | 75 / 13 | |
| 1.122.46 | 74 / 13 | |
| 1.122.45 | 74 / 13 | |
| 1.122.44 | 74 / 13 | |
| 1.122.43 | 74 / 13 | |
| 1.122.42 | 74 / 13 | |
| 1.122.41 | 74 / 13 | |
| 1.122.40 | 74 / 13 | |
| 1.122.39 | 74 / 13 | |
| 1.122.38 | 74 / 13 | |
| 1.122.37 | 74 / 13 | |
| 1.122.36 | 74 / 13 | |
| 1.122.35 | 74 / 13 | |
| 1.122.34 | 74 / 13 | |
| 1.122.33 | 74 / 13 | |
| 1.122.32 | 74 / 13 | |
| 1.122.31 | 74 / 13 | |
| 1.122.30 | 74 / 13 | |
| 1.122.29 | 74 / 13 | |
| 1.122.28 | 74 / 13 | |
| 1.122.27 | 74 / 13 |
v2.32.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.32.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.31.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.31.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.31.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.30.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.30.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.30.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.30.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.30.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.30.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.30.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.29.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.29.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.29.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.29.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.29.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.29.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.29.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.29.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.29.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.28.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.28.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.28.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.26.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.26.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.26.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.25.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.25.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.24.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.22.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.22.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.21.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.21.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.20.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.20.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.18.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.16.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.14.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.14.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.13.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.13.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.12.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.11.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.11.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.11.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.10.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.10.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.10.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.9.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.9.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.8.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.8.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.7.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.7.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.7.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.6.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.6.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.6.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.6.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.5.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.5.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.5.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.122.46
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.122.45
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.122.44
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.122.43
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.122.42
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.122.41
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.122.40
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.122.38
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.122.33
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.