← Home

@opentelemetry/instrumentation-koa

23
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

dyladanpichlermarcoverbalancenpmjs-accounttrentmmartinkuba

Keywords

instrumentationkoanodejsopentelemetrypluginprofilingtracing

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Legitimate migration to GitHub Actions CI publishing for the official OpenTelemetry JS contrib monorepo; backed by SLSA provenance. ai
publish-pattern dormant-publish AI (publish-pattern): Dormancy explained by CI/CD pipeline transition; official OTel contrib package with verified provenance. ai

Versions (showing 23 of 23)

Version Deps Published
0.67.0 3 / 10
0.66.0 3 / 10
0.65.0 3 / 10
0.64.0 3 / 10
0.63.0 3 / 10
0.62.0 3 / 10
0.61.0 3 / 10
0.60.0 3 / 10
0.59.0 3 / 10
0.58.0 3 / 10
0.57.1 3 / 10
0.57.0 3 / 19
0.56.0 3 / 19
0.55.0 3 / 19
0.54.2 3 / 19
0.54.1 3 / 19
0.53.0 3 / 19
0.52.0 3 / 19
0.51.0 3 / 19
0.50.2 3 / 19
0.50.1 3 / 19
0.50.0 3 / 19
0.49.0 3 / 19

v0.67.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.66.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.65.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.63.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.62.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.