← Home

@pydantic/logfire-browser

JavaScript Browser SDK for Logfire - https://pydantic.dev/logfire

36
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

viicossamuelcolvinpydantic-userpetyosi

Keywords

logfireobservabilityopentelemetrytracingprofilingstatsmonitoring

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/browserMetrics-ClpXqdqf.js AI (source-diff): Minified bundler output for new web-vitals metrics feature, not true obfuscation. ai
source-diff source-size-tripled AI (source-diff): Size increase matches legitimately added OTel metrics/web-vitals feature code. ai
source-diff obfuscated-file:dist/browserMetrics-bhbn_Yb6.cjs AI (source-diff): CJS twin of the same minified metrics bundle; benign build output. ai
phantom-deps phantom-dep:@opentelemetry/core AI (phantom-deps): Declared runtime dep used transitively/bundled; not a direct import in source but legitimately needed. ai
provenance no-provenance AI (provenance): Pydantic org package; absence of Sigstore attestation is common and not a risk signal here. ai
provenance missing-githead AI (provenance): SLSA provenance attestation present; missing gitHead is a minor metadata gap, not a supply chain risk for this package. ai
publish-pattern new-deps-added AI (publish-pattern): @opentelemetry/otlp-transformer is a standard OpenTelemetry package, consistent with this SDK's purpose. ai

Versions (showing 36 of 36)

Version Deps Published
0.17.4 10 / 7
0.17.3 10 / 7
0.17.2 10 / 7
0.17.1 10 / 7
0.17.0 10 / 7
0.16.4 6 / 3
0.16.3 6 / 3
0.16.2 6 / 3
0.16.1 6 / 3
0.16.0 6 / 3
0.15.3 6 / 3
0.15.2 6 / 3
0.15.1 6 / 3
0.15.0 6 / 3
0.14.3 6 / 3
0.14.2 6 / 3
0.14.1 8 / 3
0.14.0 8 / 3
0.13.0 8 / 3
0.12.3 8 / 3
0.12.2 8 / 9
0.12.1 7 / 9
0.12.0 7 / 9
0.11.0 7 / 9
0.10.0 7 / 9
0.9.1 7 / 9
0.9.0 7 / 9
0.8.1 7 / 9
0.8.0 8 / 9
0.7.0 8 / 9
0.6.0 6 / 9
0.5.0 6 / 9
0.4.0 6 / 9
0.3.1 6 / 9
0.3.0 5 / 9
0.2.0 5 / 9

v0.17.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.17.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.17.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.17.1

3 findings
HIGH New obfuscated file: dist/browserMetrics-ClpXqdqf.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/browserMetrics-bhbn_Yb6.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.17.0

3 findings
HIGH New obfuscated file: dist/browserMetrics-ClpXqdqf.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/browserMetrics-bhbn_Yb6.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.10.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.9.1

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: pydantic-user → GitHub Actions (on 2025-09-18, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (pydantic-user) on 2025-09-18, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.7.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.