← Home

@opentelemetry/contrib-test-utils

Test utilities for opentelemetry components

30
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

dyladanpichlermarcoverbalancenpmjs-accounttrentmmartinkuba

Keywords

opentelemetrycontrib-test-utils

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): OpenTelemetry JS contrib migrated publishing to GitHub Actions CI/CD with SLSA provenance; this is expected for all future versions. ai

Versions (showing 30 of 30)

Version Deps Published
0.67.0 9 / 1
0.66.0 9 / 1
0.65.0 9 / 1
0.64.0 9 / 1
0.63.0 9 / 1
0.62.0 9 / 1
0.61.0 9 / 1
0.60.0 9 / 1
0.59.0 9 / 1
0.58.0 9 / 1
0.57.0 9 / 1
0.56.0 9 / 1
0.55.0 9 / 3
0.54.0 9 / 3
0.53.0 9 / 3
0.52.2 9 / 3
0.52.1 9 / 3
0.51.0 9 / 3
0.50.0 9 / 3
0.49.0 9 / 3
0.48.0 9 / 3
0.47.0 9 / 3
0.46.0 9 / 3
0.45.1 9 / 3
0.45.0 10 / 3
0.44.0 10 / 3
0.43.0 10 / 3
0.42.0 10 / 3
0.41.0 8 / 3
0.40.0 8 / 3

v0.67.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.46.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v0.45.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v0.45.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v0.44.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v0.43.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v0.42.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v0.41.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v0.40.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.