← Home

@opentelemetry/exporter-trace-otlp-proto

OpenTelemetry Collector Exporter allows user to send collected traces to the OpenTelemetry Collector using protobuf over HTTP

51
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

dyladanpichlermarcoverbalancenpmjs-accounttrentmmartinkuba

Keywords

opentelemetrynodejsprotobuftracingprofilingmetricsstats

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern new-deps-added AI (publish-pattern): New dep is an intra-org rename, not a third-party addition; stable pattern for this package. ai
dependencies unvetted-dep:@opentelemetry/sdk-trace AI (dependencies): Same org (@opentelemetry) as this package; routine internal dep rename from sdk-trace-base. ai
provenance no-provenance AI (provenance): This package predates widespread Sigstore provenance adoption on npm; no provenance is expected for this version range. ai
source-diff large-new-source-files AI (source-diff): Package ships multiple build targets (CJS, ESM, ESNext), which naturally multiplies file count. Size growth is consistent with adding module formats, not injected code. ai
source-diff source-size-tripled AI (source-diff): Size increase reflects addition of ESM/ESNext build outputs for a multi-format package, not bundled payloads. Consistent with the package.json module fields. ai
phantom-deps phantom-dep:@grpc/proto-loader AI (phantom-deps): Dependency is used indirectly via OTel sub-packages; phantom detection is a false positive for this modular monorepo package. ai
dependencies unvetted-dep:protobufjs AI (dependencies): protobufjs is a legitimate, widely-used protobuf library; its use is expected and appropriate for an OTLP protobuf exporter package. ai
phantom-deps phantom-dep:protobufjs AI (phantom-deps): protobufjs is used at runtime for .proto file loading, likely via dynamic require or delegated to sub-packages in the OTel monorepo architecture. ai
provenance publisher-changed AI (provenance): Transition from individual maintainer (dyladan) to GitHub Actions CI/CD publishing with SLSA provenance; standard practice for OpenTelemetry project. ai
phantom-deps phantom-dep:@opentelemetry/resources AI (phantom-deps): Same-org dependency likely used transitively or re-exported; standard for OpenTelemetry monorepo packages. ai
phantom-deps phantom-dep:@opentelemetry/core AI (phantom-deps): Same-org dependency likely used transitively or re-exported; standard for OpenTelemetry monorepo packages. ai

Versions (showing 51 of 69)

View all versions
Version Deps Published
0.221.0 3 / 20
0.220.0 5 / 20
0.219.0 5 / 20
0.218.0 5 / 20
0.217.0 5 / 20
0.216.0 5 / 20
0.215.0 5 / 20
0.214.0 5 / 20
0.213.0 5 / 20
0.212.0 5 / 20
0.211.0 5 / 20
0.210.0 5 / 20
0.209.0 5 / 20
0.208.0 5 / 20
0.207.0 5 / 20
0.206.0 5 / 20
0.205.0 5 / 21
0.204.0 5 / 21
0.203.0 5 / 22
0.202.0 5 / 22
0.201.1 5 / 22
0.201.0 5 / 22
0.200.0 5 / 22
0.57.2 5 / 23
0.57.1 5 / 23
0.57.0 5 / 23
0.56.0 5 / 23
0.55.0 5 / 23
0.54.2 5 / 23
0.54.1 5 / 23
0.54.0 5 / 23
0.53.0 5 / 24
0.52.1 5 / 25
0.52.0 5 / 25
0.51.1 6 / 26
0.51.0 6 / 26
0.50.0 6 / 26
0.49.1 6 / 26
0.49.0 6 / 26
0.48.0 6 / 26
0.47.0 6 / 25
0.46.0 6 / 25
0.45.1 6 / 25
0.45.0 6 / 25
0.44.0 6 / 25
0.43.0 6 / 25
0.42.0 6 / 25
0.41.2 6 / 25
0.41.1 6 / 25
0.41.0 7 / 15
0.40.0 6 / 13

v0.221.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.220.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.