@newrelic/browser-agent
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:rrweb | AI (phantom-deps): Session-replay dep used in build output, not detected by static import scan. | ai | |
| phantom-deps | phantom-dep:fflate | AI (phantom-deps): Compression lib used in bundled build, false positive from heuristic. | ai | |
| npm-metadata | url-dep:@newrelic/nr-querypack | AI (npm-metadata): Dev-only dependency pinned to official newrelic org repo, not shipped in package. | ai | |
| provenance | publisher-changed | AI (provenance): New Relic migrated to GitHub Actions CI/CD publishing with SLSA attestation; this is the expected publisher going forward. | ai | |
| dependencies | unvetted-dep:@newrelic/rrweb | AI (dependencies): @newrelic/rrweb is New Relic's own fork of rrweb, maintained by the same org as this package. It is a first-party dependency for session replay functionality, stable across versions. | ai |
Versions (showing 51 of 122)
| Version | Deps | Published |
|---|---|---|
| 1.318.0 | 3 / 57 | |
| 1.317.0 | 3 / 57 | |
| 1.316.0 | 3 / 57 | |
| 1.315.0 | 3 / 57 | |
| 1.314.0 | 3 / 57 | |
| 1.313.1 | 3 / 57 | |
| 1.313.0 | 3 / 57 | |
| 1.312.1 | 3 / 57 | |
| 1.312.0 | 3 / 57 | |
| 1.311.0 | 3 / 57 | |
| 1.310.1 | 3 / 57 | |
| 1.310.0 | 3 / 57 | |
| 1.309.0 | 3 / 57 | |
| 1.308.0 | 3 / 57 | |
| 1.307.0 | 3 / 57 | |
| 1.306.0 | 3 / 57 | |
| 1.305.0 | 3 / 57 | |
| 1.304.0 | 3 / 57 | |
| 1.303.0 | 3 / 57 | |
| 1.302.0 | 3 / 57 | |
| 1.301.0 | 3 / 57 | |
| 1.300.0 | 3 / 57 | |
| 1.299.0 | 3 / 57 | |
| 1.298.0 | 3 / 57 | |
| 1.297.1 | 3 / 57 | |
| 1.297.0 | 3 / 61 | |
| 1.296.0 | 3 / 61 | |
| 1.295.0 | 3 / 61 | |
| 1.294.0 | 3 / 61 | |
| 1.293.0 | 3 / 61 | |
| 1.292.1 | 3 / 61 | |
| 1.292.0 | 3 / 61 | |
| 1.291.1 | 3 / 61 | |
| 1.291.0 | 3 / 61 | |
| 1.290.1 | 3 / 61 | |
| 1.290.0 | 3 / 61 | |
| 1.289.0 | 3 / 61 | |
| 1.288.1 | 3 / 61 | |
| 1.288.0 | 3 / 61 | |
| 1.287.0 | 3 / 61 | |
| 1.286.0 | 3 / 61 | |
| 1.285.0 | 3 / 61 | |
| 1.284.1 | 3 / 61 | |
| 1.284.0 | 3 / 61 | |
| 1.283.2 | 3 / 61 | |
| 1.283.1 | 3 / 61 | |
| 1.283.0 | 3 / 61 | |
| 1.282.0 | 3 / 61 | |
| 1.281.0 | 3 / 61 | |
| 1.280.0 | 3 / 61 | |
| 1.279.1 | 3 / 61 |
v1.318.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.317.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.288.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.288.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.287.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.286.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.285.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.284.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.284.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.283.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.283.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.283.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.282.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.281.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.280.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.279.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.