← Home

@opentelemetry/instrumentation-grpc

OpenTelemetry instrumentation for `@grpc/grpc-js` rpc client and server for gRPC framework

51
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

dyladanpichlermarcoverbalancenpmjs-accounttrentmmartinkuba

Keywords

opentelemetrygrpcnodejstracingprofilinginstrumentation

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
maintainer-change maintainer-added AI (maintainer-change): Known OpenTelemetry org maintainer rotation, long-stable. ai
provenance publisher-changed-stale AI (provenance): Publisher change stable 1109d, consistent with legitimate org transfer. ai
publish-pattern new-deps-added AI (publish-pattern): tslib is a trivial, universally trusted TS helper lib. ai
install-scripts install-script:postinstall AI (install-scripts): Postinstall only prints a deprecation warning via node -e console.log; no network or exec. ai
provenance publisher-changed AI (provenance): Legitimate migration to GitHub Actions CI/CD publishing with SLSA provenance for this well-established org. ai
publish-pattern dormant-publish AI (publish-pattern): Monorepo package; dormancy reflects release cadence, not abandonment. ai

Versions (showing 51 of 83)

View all versions
Version Deps Published
0.221.0 2 / 19
0.220.0 2 / 19
0.219.0 2 / 20
0.218.0 2 / 20
0.217.0 2 / 20
0.216.0 2 / 20
0.215.0 2 / 20
0.214.0 2 / 20
0.213.0 2 / 20
0.212.0 2 / 20
0.211.0 2 / 20
0.210.0 2 / 20
0.209.0 2 / 20
0.208.0 2 / 18
0.207.0 2 / 18
0.206.0 2 / 18
0.205.0 2 / 19
0.204.0 2 / 19
0.203.0 2 / 20
0.202.0 2 / 20
0.201.1 2 / 20
0.201.0 2 / 20
0.200.0 2 / 20
0.57.2 2 / 22
0.57.1 2 / 22
0.57.0 2 / 22
0.56.0 2 / 22
0.55.0 2 / 22
0.54.2 2 / 22
0.54.1 2 / 22
0.54.0 2 / 22
0.53.0 2 / 23
0.52.1 2 / 24
0.52.0 2 / 24
0.51.1 2 / 24
0.51.0 2 / 24
0.50.0 2 / 24
0.49.1 2 / 24
0.49.0 2 / 24
0.48.0 2 / 24
0.47.0 2 / 24
0.46.0 2 / 24
0.45.1 2 / 24
0.45.0 2 / 24
0.44.0 2 / 24
0.43.0 2 / 24
0.42.0 2 / 24
0.41.2 2 / 24
0.41.1 2 / 20
0.41.0 3 / 20
0.40.0 2 / 20

v0.221.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.220.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.50.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.49.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.49.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.48.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.47.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.46.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.45.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.45.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.44.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.43.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.42.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: dyladan → pichlermarc (on 2023-09-11, known maintainer) provenance

This version was published by a different npm account (pichlermarc) than the most recent previously approved version (dyladan) on 2023-09-11, but pichlermarc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.41.2

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: dyladan → pichlermarc (on 2023-08-08, known maintainer) provenance

This version was published by a different npm account (pichlermarc) than the most recent previously approved version (dyladan) on 2023-08-08, but pichlermarc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.41.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.41.0

2 findings
MEDIUM Publisher changed: dyladan → pichlermarc (on 2023-07-06, unremoved on npm for 1109d) provenance

This version was published by a different npm account (pichlermarc) than the most recent previously approved version (dyladan) on 2023-07-06. It has since remained available on npm for 1109 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.40.0

3 findings
HIGH Package has 'postinstall' script install-scripts

Script: node -e "console.log(\"\x1b[95m%s\x1b[0m\", \"@opentelemetry/instrumentation-grpc - warning: The package 'grpc' (https://www.npmjs.com/package/grpc) is deprecated. It will no longer be instrumented in the next release of '@opentelemetry/instrumentation-grpc'. Please migrate to '@grpc/grpc-js' (https://www.npmjs.com/package/@grpc/grpc-js) to continue receiving telemetry.\");"

MEDIUM Publisher changed: dyladan → pichlermarc (on 2023-06-06, unremoved on npm for 1139d) provenance

This version was published by a different npm account (pichlermarc) than the most recent previously approved version (dyladan) on 2023-06-06. It has since remained available on npm for 1139 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.