← Home

@opentelemetry/web-common

31
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

dyladanpichlermarcoverbalancenpmjs-accounttrentmmartinkuba

Keywords

opentelemetrywebtracingprofilingstatsmonitoring

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI publishing with SLSA attestation is the expected pattern for the official OTel JS monorepo. ai
phantom-deps phantom-dep:@opentelemetry/semantic-conventions AI (phantom-deps): Same-org scoped dep; phantom-dep heuristic is unreliable for transitive/type-only imports in this package. ai

Versions (showing 31 of 31)

Version Deps Published
0.221.0 3 / 22
0.220.0 3 / 22
0.219.0 3 / 22
0.218.0 3 / 22
0.217.0 3 / 22
0.216.0 3 / 22
0.215.0 3 / 22
0.214.0 3 / 22
0.213.0 3 / 22
0.212.0 3 / 22
0.211.0 3 / 22
0.210.0 3 / 22
0.209.0 3 / 22
0.208.0 3 / 22
0.207.0 3 / 22
0.206.0 3 / 22
0.205.0 3 / 23
0.204.0 3 / 23
0.203.0 3 / 24
0.202.0 3 / 25
0.201.1 3 / 25
0.201.0 3 / 25
0.200.0 3 / 25
0.57.2 3 / 26
0.57.1 3 / 26
0.57.0 3 / 26
0.56.0 3 / 26
0.55.0 3 / 26
0.54.2 3 / 26
0.54.1 3 / 26
0.54.0 3 / 26

v0.221.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.220.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.200.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v0.57.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v0.57.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v0.57.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v0.56.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v0.55.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v0.54.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v0.54.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v0.54.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.