← Home

@n8n/utils

43
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

cornelius_n8n_ion8n-matsuuutomin8njan_n8n_ion8n-charliekolb

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): n8n-io org publishes via GitHub Actions CI with SLSA attestation; this is their documented release pipeline. ai
maintainer-change maintainer-added AI (maintainer-change): New maintainers are n8n org members; consistent with org-level CI publishing transition. ai

Versions (showing 43 of 43)

Version Deps Published
1.40.0 2 / 9
1.39.0 2 / 9
1.38.1 2 / 9
1.38.0 2 / 9
1.37.2 2 / 9
1.37.1 2 / 9
1.37.0 2 / 9
1.36.0 2 / 9
1.35.0 2 / 9
1.34.0 2 / 9
1.33.0 2 / 9
1.32.0 2 / 9
1.31.0 2 / 9
1.30.0 2 / 9
1.29.0 2 / 9
1.28.1 2 / 9
1.28.0 2 / 9
1.27.0 2 / 9
1.26.0 2 / 9
1.25.0 2 / 9
1.24.0 2 / 9
1.23.0 2 / 9
1.22.0 0 / 9
1.21.0 0 / 9
1.20.1 0 / 9
1.20.0 0 / 9
1.19.0 0 / 9
1.18.0 0 / 9
1.17.0 0 / 9
1.16.0 0 / 9
1.15.0 0 / 9
1.14.0 0 / 9
1.13.0 0 / 9
1.12.0 0 / 9
1.11.0 0 / 9
1.10.0 0 / 9
1.9.0 0 / 9
1.8.0 0 / 9
1.7.0 0 / 9
1.6.0 0 / 9
1.5.0 0 / 9
1.4.0 0 / 9
1.3.0 0 / 10

v1.40.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.39.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.38.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.38.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.37.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.37.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.37.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.20.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.8.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.7.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.6.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.5.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.