@segment/action-destinations
Destination Actions engine and definitions.
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Org-wide migration to CI/CD publisher with improved provenance, not a takeover. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Consistent with legitimate org publishing automation transition. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Mass removal matches consolidation to automated publisher, not compromise. | ai | |
| provenance | no-provenance | AI (provenance): Large established org package; lack of provenance is consistent across all versions of this package. | ai | |
| dependencies | unvetted-dep:@segment/actions-core | AI (dependencies): First-party Segment monorepo package; stable dependency across all versions of this package. | ai | |
| phantom-deps | phantom-dep:@types/node | AI (phantom-deps): @types/node is intentionally listed as a runtime dep for Node.js type definitions; stable false positive for this package. | ai |
Versions (showing 51 of 324)
| Version | Deps | Published |
|---|---|---|
| 3.497.0 | 21 / 7 | |
| 3.496.0 | 21 / 7 | |
| 3.495.0 | 21 / 7 | |
| 3.494.0 | 21 / 7 | |
| 3.493.0 | 21 / 7 | |
| 3.492.0 | 21 / 7 | |
| 3.491.0 | 21 / 7 | |
| 3.490.0 | 21 / 7 | |
| 3.489.0 | 21 / 7 | |
| 3.488.0 | 21 / 7 | |
| 3.487.0 | 21 / 7 | |
| 3.486.0 | 21 / 7 | |
| 3.485.0 | 21 / 7 | |
| 3.484.0 | 21 / 7 | |
| 3.483.0 | 21 / 7 | |
| 3.482.0 | 21 / 7 | |
| 3.481.0 | 21 / 7 | |
| 3.480.0 | 21 / 7 | |
| 3.479.0 | 21 / 7 | |
| 3.478.0 | 21 / 7 | |
| 3.477.0 | 21 / 7 | |
| 3.476.0 | 21 / 7 | |
| 3.475.0 | 21 / 7 | |
| 3.474.0 | 21 / 7 | |
| 3.473.0 | 21 / 7 | |
| 3.472.0 | 21 / 7 | |
| 3.471.0 | 21 / 7 | |
| 3.470.0 | 21 / 7 | |
| 3.469.0 | 21 / 7 | |
| 3.468.0 | 21 / 7 | |
| 3.467.0 | 21 / 7 | |
| 3.466.0 | 21 / 7 | |
| 3.465.0 | 21 / 7 | |
| 3.464.0 | 21 / 7 | |
| 3.463.0 | 21 / 7 | |
| 3.462.0 | 21 / 7 | |
| 3.461.0 | 21 / 7 | |
| 3.460.0 | 21 / 7 | |
| 3.459.0 | 21 / 7 | |
| 3.458.0 | 21 / 7 | |
| 3.457.0 | 21 / 7 | |
| 3.456.0 | 21 / 7 | |
| 3.455.0 | 21 / 7 | |
| 3.454.0 | 21 / 7 | |
| 3.453.0 | 21 / 7 | |
| 3.452.0 | 21 / 7 | |
| 3.451.0 | 21 / 7 | |
| 3.450.0 | 21 / 7 | |
| 3.449.0 | 21 / 7 | |
| 3.448.0 | 21 / 7 | |
| 3.447.0 | 21 / 7 |
v3.497.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.496.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.495.0
2 findingsThis version was published by a different npm account than previous versions on 2026-07-07. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.485.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.484.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.483.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.482.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.481.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.480.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.479.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.478.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.477.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.476.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.475.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.474.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.473.0
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (varadarajan-tw) than the most recent previously approved version (mdkhan-tw) on 2026-02-24, but varadarajan-tw is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.472.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.471.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.470.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.469.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.468.0
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (mdkhan-tw) than the most recent previously approved version (varadarajan-tw) on 2026-02-05, but mdkhan-tw is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.467.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.466.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.465.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.464.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.463.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.462.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.461.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.460.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.459.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.458.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.457.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.456.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.455.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.454.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.453.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.452.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.451.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.450.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.449.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.448.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.447.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.