← Home

@posthog/webpack-plugin

Webpack plugin for Posthog 🦔

95
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

watilotwixesfuziontechmariusandraben-posthogtimglrafael_posthogfraserhoppermanoelposthogrobbie-cdustinbyrnefeliperalmeidalucasheriquesfrankposthogtom-posthogadamleithpcat-phsarahxsanderspeterkirkhamposthogioannisjjoshuasnyderhuguespouillot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:env-spread AI (semgrep): Spreading env into child process spawn is standard; not exfiltration. ai
phantom-deps phantom-dep:@posthog/cli AI (phantom-deps): @posthog/cli is a same-org dep declared in package.json; phantom-dep false positive for this package. ai

Versions (showing 95 of 95)

Version Deps Published
1.5.8 3 / 4
1.5.7 3 / 4
1.5.6 3 / 4
1.5.5 3 / 4
1.5.4 3 / 4
1.5.3 3 / 4
1.5.2 3 / 4
1.5.1 3 / 4
1.5.0 3 / 4
1.4.43 3 / 4
1.4.42 3 / 4
1.4.41 3 / 4
1.4.40 3 / 4
1.4.39 3 / 4
1.4.38 3 / 4
1.4.37 3 / 4
1.4.36 3 / 4
1.4.35 3 / 4
1.4.34 3 / 4
1.4.33 3 / 4
1.4.32 3 / 4
1.4.31 3 / 4
1.4.30 3 / 4
1.4.29 3 / 4
1.4.28 3 / 4
1.4.27 3 / 4
1.4.26 3 / 4
1.4.25 3 / 4
1.4.24 3 / 4
1.4.23 3 / 4
1.4.22 3 / 4
1.4.21 3 / 4
1.4.20 3 / 4
1.4.19 3 / 4
1.4.18 3 / 4
1.4.17 3 / 4
1.4.16 3 / 4
1.4.15 3 / 4
1.4.14 3 / 4
1.4.13 3 / 4
1.4.12 3 / 4
1.4.11 3 / 4
1.4.10 3 / 4
1.4.9 3 / 4
1.4.8 3 / 4
1.4.7 3 / 4
1.4.6 3 / 4
1.4.5 3 / 4
1.4.4 3 / 4
1.4.3 3 / 4
1.4.2 3 / 4
1.4.1 3 / 4
1.4.0 3 / 4
1.3.6 3 / 4
1.3.5 3 / 4
1.3.4 2 / 4
1.3.3 2 / 4
1.3.2 2 / 4
1.3.1 2 / 4
1.3.0 2 / 4
1.2.27 2 / 4
1.2.26 2 / 4
1.2.25 2 / 4
1.2.24 2 / 4
1.2.23 2 / 4
1.2.22 2 / 4
1.2.21 2 / 4
1.2.20 2 / 4
1.2.19 2 / 4
1.2.18 2 / 4
1.2.17 2 / 4
1.2.16 2 / 4
1.2.15 2 / 4
1.2.14 2 / 4
1.2.13 2 / 4
1.2.12 2 / 4
1.2.11 2 / 4
1.2.10 2 / 4
1.2.9 2 / 4
1.2.8 2 / 4
1.2.7 2 / 4
1.2.6 2 / 4
1.2.5 2 / 4
1.2.4 2 / 4
1.2.3 2 / 4
1.2.2 2 / 4
1.2.1 2 / 4
1.2.0 2 / 4
1.1.4 2 / 4
1.1.3 2 / 4
1.1.2 2 / 4
1.1.1 2 / 4
1.1.0 2 / 4
1.0.2 2 / 4
1.0.0 2 / 4

v1.5.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.5.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.5.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.5.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.5.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.5.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.5.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.5.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.5.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.43

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.42

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.41

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.40

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.39

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.38

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.37

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.36

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.35

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.34

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.33

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.32

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.31

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.30

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.29

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.28

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.27

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.26

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.25

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.24

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.23

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.22

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.21

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.20

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.19

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.18

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.17

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.16

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.15

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.14

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.13

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.0

2 findings
HIGH env-spread: src/index.ts:89 semgrep

Spreading entire process.env into an object — may capture all secrets 87 | await spawnLocal(config.cliBinaryPath, args, { 88 | cwd: process.cwd(), > 89 | env: { 90 | RUST_LOG: `posthog_cli=${config.logLevel}`, 91 | ...process.env,

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.27

2 findings
HIGH env-spread: src/index.ts:91 semgrep

Spreading entire process.env into an object — may capture all secrets 89 | await spawnLocal(config.cliBinaryPath, args, { 90 | cwd: process.cwd(), > 91 | env: { 92 | RUST_LOG: `posthog_cli=${config.logLevel}`, 93 | ...process.env,

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.26

2 findings
HIGH env-spread: src/index.ts:91 semgrep

Spreading entire process.env into an object — may capture all secrets 89 | await spawnLocal(config.cliBinaryPath, args, { 90 | cwd: process.cwd(), > 91 | env: { 92 | RUST_LOG: `posthog_cli=${config.logLevel}`, 93 | ...process.env,

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.25

2 findings
HIGH env-spread: src/index.ts:91 semgrep

Spreading entire process.env into an object — may capture all secrets 89 | await spawnLocal(config.cliBinaryPath, args, { 90 | cwd: process.cwd(), > 91 | env: { 92 | RUST_LOG: `posthog_cli=${config.logLevel}`, 93 | ...process.env,

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.24

2 findings
HIGH env-spread: src/index.ts:91 semgrep

Spreading entire process.env into an object — may capture all secrets 89 | await spawnLocal(config.cliBinaryPath, args, { 90 | cwd: process.cwd(), > 91 | env: { 92 | RUST_LOG: `posthog_cli=${config.logLevel}`, 93 | ...process.env,

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.23

2 findings
HIGH env-spread: src/index.ts:91 semgrep

Spreading entire process.env into an object — may capture all secrets 89 | await spawnLocal(config.cliBinaryPath, args, { 90 | cwd: process.cwd(), > 91 | env: { 92 | RUST_LOG: `posthog_cli=${config.logLevel}`, 93 | ...process.env,

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.22

2 findings
HIGH env-spread: src/index.ts:91 semgrep

Spreading entire process.env into an object — may capture all secrets 89 | await spawnLocal(config.cliBinaryPath, args, { 90 | cwd: process.cwd(), > 91 | env: { 92 | RUST_LOG: `posthog_cli=${config.logLevel}`, 93 | ...process.env,

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.21

2 findings
HIGH env-spread: src/index.ts:91 semgrep

Spreading entire process.env into an object — may capture all secrets 89 | await spawnLocal(config.cliBinaryPath, args, { 90 | cwd: process.cwd(), > 91 | env: { 92 | RUST_LOG: `posthog_cli=${config.logLevel}`, 93 | ...process.env,

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.20

2 findings
HIGH env-spread: src/index.ts:91 semgrep

Spreading entire process.env into an object — may capture all secrets 89 | await spawnLocal(config.cliBinaryPath, args, { 90 | cwd: process.cwd(), > 91 | env: { 92 | RUST_LOG: `posthog_cli=${config.logLevel}`, 93 | ...process.env,

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.19

2 findings
HIGH env-spread: src/index.ts:91 semgrep

Spreading entire process.env into an object — may capture all secrets 89 | await spawnLocal(config.cliBinaryPath, args, { 90 | cwd: process.cwd(), > 91 | env: { 92 | RUST_LOG: `posthog_cli=${config.logLevel}`, 93 | ...process.env,

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.18

2 findings
HIGH env-spread: src/index.ts:91 semgrep

Spreading entire process.env into an object — may capture all secrets 89 | await spawnLocal(config.cliBinaryPath, args, { 90 | cwd: process.cwd(), > 91 | env: { 92 | RUST_LOG: `posthog_cli=${config.logLevel}`, 93 | ...process.env,

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.17

2 findings
HIGH env-spread: src/index.ts:91 semgrep

Spreading entire process.env into an object — may capture all secrets 89 | await spawnLocal(config.cliBinaryPath, args, { 90 | cwd: process.cwd(), > 91 | env: { 92 | RUST_LOG: `posthog_cli=${config.logLevel}`, 93 | ...process.env,

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.16

2 findings
HIGH env-spread: src/index.ts:91 semgrep

Spreading entire process.env into an object — may capture all secrets 89 | await spawnLocal(config.cliBinaryPath, args, { 90 | cwd: process.cwd(), > 91 | env: { 92 | RUST_LOG: `posthog_cli=${config.logLevel}`, 93 | ...process.env,

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.15

2 findings
HIGH env-spread: src/index.ts:91 semgrep

Spreading entire process.env into an object — may capture all secrets 89 | await spawnLocal(config.cliBinaryPath, args, { 90 | cwd: process.cwd(), > 91 | env: { 92 | RUST_LOG: `posthog_cli=${config.logLevel}`, 93 | ...process.env,

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.14

2 findings
HIGH env-spread: src/index.ts:91 semgrep

Spreading entire process.env into an object — may capture all secrets 89 | await spawnLocal(config.cliBinaryPath, args, { 90 | cwd: process.cwd(), > 91 | env: { 92 | RUST_LOG: `posthog_cli=${config.logLevel}`, 93 | ...process.env,

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.13

2 findings
HIGH env-spread: src/index.ts:91 semgrep

Spreading entire process.env into an object — may capture all secrets 89 | await spawnLocal(config.cliBinaryPath, args, { 90 | cwd: process.cwd(), > 91 | env: { 92 | RUST_LOG: `posthog_cli=${config.logLevel}`, 93 | ...process.env,

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.12

2 findings
HIGH env-spread: src/index.ts:91 semgrep

Spreading entire process.env into an object — may capture all secrets 89 | await spawnLocal(config.cliBinaryPath, args, { 90 | cwd: process.cwd(), > 91 | env: { 92 | RUST_LOG: `posthog_cli=${config.logLevel}`, 93 | ...process.env,

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.11

2 findings
HIGH env-spread: src/index.ts:91 semgrep

Spreading entire process.env into an object — may capture all secrets 89 | await spawnLocal(config.cliBinaryPath, args, { 90 | cwd: process.cwd(), > 91 | env: { 92 | RUST_LOG: `posthog_cli=${config.logLevel}`, 93 | ...process.env,

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.10

2 findings
HIGH env-spread: src/index.ts:91 semgrep

Spreading entire process.env into an object — may capture all secrets 89 | await spawnLocal(config.cliBinaryPath, args, { 90 | cwd: process.cwd(), > 91 | env: { 92 | RUST_LOG: `posthog_cli=${config.logLevel}`, 93 | ...process.env,

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.9

2 findings
HIGH env-spread: src/index.ts:91 semgrep

Spreading entire process.env into an object — may capture all secrets 89 | await spawnLocal(config.cliBinaryPath, args, { 90 | cwd: process.cwd(), > 91 | env: { 92 | RUST_LOG: `posthog_cli=${config.logLevel}`, 93 | ...process.env,

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.8

2 findings
HIGH env-spread: src/index.ts:91 semgrep

Spreading entire process.env into an object — may capture all secrets 89 | await spawnLocal(config.cliBinaryPath, args, { 90 | cwd: process.cwd(), > 91 | env: { 92 | RUST_LOG: `posthog_cli=${config.logLevel}`, 93 | ...process.env,

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.7

2 findings
HIGH env-spread: src/index.ts:91 semgrep

Spreading entire process.env into an object — may capture all secrets 89 | await spawnLocal(config.cliBinaryPath, args, { 90 | cwd: process.cwd(), > 91 | env: { 92 | RUST_LOG: `posthog_cli=${config.logLevel}`, 93 | ...process.env,

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.6

2 findings
HIGH env-spread: src/index.ts:91 semgrep

Spreading entire process.env into an object — may capture all secrets 89 | await spawnLocal(config.cliBinaryPath, args, { 90 | cwd: process.cwd(), > 91 | env: { 92 | RUST_LOG: `posthog_cli=${config.logLevel}`, 93 | ...process.env,

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.5

2 findings
HIGH env-spread: src/index.ts:91 semgrep

Spreading entire process.env into an object — may capture all secrets 89 | await spawnLocal(config.cliBinaryPath, args, { 90 | cwd: process.cwd(), > 91 | env: { 92 | RUST_LOG: `posthog_cli=${config.logLevel}`, 93 | ...process.env,

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.4

2 findings
HIGH env-spread: src/index.ts:91 semgrep

Spreading entire process.env into an object — may capture all secrets 89 | await spawnLocal(config.cliBinaryPath, args, { 90 | cwd: process.cwd(), > 91 | env: { 92 | RUST_LOG: `posthog_cli=${config.logLevel}`, 93 | ...process.env,

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.3

2 findings
HIGH env-spread: src/index.ts:85 semgrep

Spreading entire process.env into an object — may capture all secrets 83 | await spawnLocal(config.cliBinaryPath, args, { 84 | cwd: process.cwd(), > 85 | env: { 86 | ...process.env, 87 | RUST_LOG: `posthog_cli=${config.logLevel}`,

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.2

2 findings
HIGH env-spread: src/index.ts:85 semgrep

Spreading entire process.env into an object — may capture all secrets 83 | await spawnLocal(config.cliBinaryPath, args, { 84 | cwd: process.cwd(), > 85 | env: { 86 | ...process.env, 87 | RUST_LOG: `posthog_cli=${config.logLevel}`,

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.1

2 findings
HIGH env-spread: src/index.ts:85 semgrep

Spreading entire process.env into an object — may capture all secrets 83 | await spawnLocal(config.cliBinaryPath, args, { 84 | cwd: process.cwd(), > 85 | env: { 86 | ...process.env, 87 | RUST_LOG: `posthog_cli=${config.logLevel}`,

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.0

2 findings
HIGH env-spread: src/index.ts:85 semgrep

Spreading entire process.env into an object — may capture all secrets 83 | await spawnLocal(config.cliBinaryPath, args, { 84 | cwd: process.cwd(), > 85 | env: { 86 | ...process.env, 87 | RUST_LOG: `posthog_cli=${config.logLevel}`,

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.4

2 findings
HIGH env-spread: src/index.ts:82 semgrep

Spreading entire process.env into an object — may capture all secrets 80 | await spawnLocal(config.cliBinaryPath, args, { 81 | cwd: process.cwd(), > 82 | env: { 83 | ...process.env, 84 | RUST_LOG: `posthog_cli=${config.logLevel}`,

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.3

2 findings
HIGH env-spread: src/index.ts:82 semgrep

Spreading entire process.env into an object — may capture all secrets 80 | await spawnLocal(config.cliBinaryPath, args, { 81 | cwd: process.cwd(), > 82 | env: { 83 | ...process.env, 84 | RUST_LOG: `posthog_cli=${config.logLevel}`,

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.2

2 findings
HIGH env-spread: src/index.ts:82 semgrep

Spreading entire process.env into an object — may capture all secrets 80 | await spawnLocal(config.cliBinaryPath, args, { 81 | cwd: process.cwd(), > 82 | env: { 83 | ...process.env, 84 | RUST_LOG: `posthog_cli=${config.logLevel}`,

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.1

2 findings
HIGH env-spread: src/index.ts:74 semgrep

Spreading entire process.env into an object — may capture all secrets 72 | await spawnLocal(config.cliBinaryPath, args, { 73 | cwd: process.cwd(), > 74 | env: { 75 | ...process.env, 76 | RUST_LOG: `posthog_cli=${config.logLevel}`,

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.0

2 findings
HIGH env-spread: src/index.ts:74 semgrep

Spreading entire process.env into an object — may capture all secrets 72 | await spawnLocal(config.cliBinaryPath, args, { 73 | cwd: process.cwd(), > 74 | env: { 75 | ...process.env, 76 | RUST_LOG: `posthog_cli=${config.logLevel}`,

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.2

2 findings
HIGH env-spread: src/index.ts:74 semgrep

Spreading entire process.env into an object — may capture all secrets 72 | await spawnLocal(config.cliBinaryPath, args, { 73 | cwd: process.cwd(), > 74 | env: { 75 | ...process.env, 76 | RUST_LOG: `posthog_cli=${config.logLevel}`,

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.0

2 findings
HIGH env-spread: src/index.ts:74 semgrep

Spreading entire process.env into an object — may capture all secrets 72 | await spawnLocal(config.cliBinaryPath, args, { 73 | cwd: process.cwd(), > 74 | env: { 75 | ...process.env, 76 | RUST_LOG: `posthog_cli=${config.logLevel}`,

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.