@segment/action-destinations
Destination Actions engine and definitions.
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Org-wide migration to CI/CD publisher with improved provenance, not a takeover. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Consistent with legitimate org publishing automation transition. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Mass removal matches consolidation to automated publisher, not compromise. | ai | |
| provenance | no-provenance | AI (provenance): Large established org package; lack of provenance is consistent across all versions of this package. | ai | |
| dependencies | unvetted-dep:@segment/actions-core | AI (dependencies): First-party Segment monorepo package; stable dependency across all versions of this package. | ai | |
| phantom-deps | phantom-dep:@types/node | AI (phantom-deps): @types/node is intentionally listed as a runtime dep for Node.js type definitions; stable false positive for this package. | ai |
Versions (showing 100 of 324)
| Version | Deps | Published |
|---|---|---|
| 3.497.0 | 21 / 7 | |
| 3.496.0 | 21 / 7 | |
| 3.495.0 | 21 / 7 | |
| 3.494.0 | 21 / 7 | |
| 3.493.0 | 21 / 7 | |
| 3.492.0 | 21 / 7 | |
| 3.491.0 | 21 / 7 | |
| 3.490.0 | 21 / 7 | |
| 3.489.0 | 21 / 7 | |
| 3.488.0 | 21 / 7 | |
| 3.487.0 | 21 / 7 | |
| 3.486.0 | 21 / 7 | |
| 3.485.0 | 21 / 7 | |
| 3.484.0 | 21 / 7 | |
| 3.483.0 | 21 / 7 | |
| 3.482.0 | 21 / 7 | |
| 3.481.0 | 21 / 7 | |
| 3.480.0 | 21 / 7 | |
| 3.479.0 | 21 / 7 | |
| 3.478.0 | 21 / 7 | |
| 3.477.0 | 21 / 7 | |
| 3.476.0 | 21 / 7 | |
| 3.475.0 | 21 / 7 | |
| 3.474.0 | 21 / 7 | |
| 3.473.0 | 21 / 7 | |
| 3.472.0 | 21 / 7 | |
| 3.471.0 | 21 / 7 | |
| 3.470.0 | 21 / 7 | |
| 3.469.0 | 21 / 7 | |
| 3.468.0 | 21 / 7 | |
| 3.467.0 | 21 / 7 | |
| 3.466.0 | 21 / 7 | |
| 3.465.0 | 21 / 7 | |
| 3.464.0 | 21 / 7 | |
| 3.463.0 | 21 / 7 | |
| 3.462.0 | 21 / 7 | |
| 3.461.0 | 21 / 7 | |
| 3.460.0 | 21 / 7 | |
| 3.459.0 | 21 / 7 | |
| 3.458.0 | 21 / 7 | |
| 3.457.0 | 21 / 7 | |
| 3.456.0 | 21 / 7 | |
| 3.455.0 | 21 / 7 | |
| 3.454.0 | 21 / 7 | |
| 3.453.0 | 21 / 7 | |
| 3.452.0 | 21 / 7 | |
| 3.451.0 | 21 / 7 | |
| 3.450.0 | 21 / 7 | |
| 3.449.0 | 21 / 7 | |
| 3.448.0 | 21 / 7 | |
| 3.447.0 | 21 / 7 | |
| 3.446.0 | 21 / 7 | |
| 3.445.0 | 21 / 7 | |
| 3.444.0 | 20 / 7 | |
| 3.443.0 | 20 / 7 | |
| 3.442.0 | 20 / 7 | |
| 3.229.0 | 14 / 5 | |
| 3.228.0 | 14 / 5 | |
| 3.227.1 | 14 / 5 | |
| 3.227.0 | 14 / 5 | |
| 3.226.0 | 14 / 5 | |
| 3.225.0 | 14 / 5 | |
| 3.224.0 | 14 / 5 | |
| 3.221.1 | 14 / 5 | |
| 3.221.0 | 14 / 5 | |
| 3.220.0 | 14 / 5 | |
| 3.219.0 | 14 / 5 | |
| 3.218.0 | 14 / 5 | |
| 3.217.1 | 14 / 5 | |
| 3.217.0 | 14 / 5 | |
| 3.216.0 | 14 / 5 | |
| 3.214.0 | 14 / 5 | |
| 3.213.0 | 14 / 5 | |
| 3.210.1 | 14 / 5 | |
| 3.210.0 | 14 / 5 | |
| 3.209.0 | 14 / 5 | |
| 3.208.0 | 14 / 5 | |
| 3.207.0 | 14 / 5 | |
| 3.206.0 | 14 / 5 | |
| 3.205.3 | 14 / 5 | |
| 3.205.2 | 14 / 5 | |
| 3.205.1 | 14 / 5 | |
| 3.201.0 | 14 / 5 | |
| 3.200.1 | 14 / 5 | |
| 3.200.0 | 14 / 5 | |
| 3.199.0 | 14 / 5 | |
| 3.198.0 | 14 / 5 | |
| 3.197.0 | 14 / 5 | |
| 3.196.0 | 14 / 5 | |
| 3.195.0 | 14 / 5 | |
| 3.193.0 | 14 / 5 | |
| 3.192.0 | 14 / 5 | |
| 3.190.0 | 14 / 5 | |
| 3.189.0 | 14 / 5 | |
| 3.188.0 | 14 / 5 | |
| 3.186.0 | 14 / 5 | |
| 3.184.0 | 14 / 5 | |
| 3.183.0 | 14 / 5 | |
| 3.181.0 | 14 / 5 | |
| 3.180.0 | 14 / 5 |
v3.497.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.496.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.495.0
2 findingsThis version was published by a different npm account than previous versions on 2026-07-07. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.485.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.484.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.483.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.482.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.481.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.480.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.479.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.478.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.477.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.476.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.475.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.474.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.473.0
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (varadarajan-tw) than the most recent previously approved version (mdkhan-tw) on 2026-02-24, but varadarajan-tw is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.472.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.471.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.470.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.469.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.468.0
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (mdkhan-tw) than the most recent previously approved version (varadarajan-tw) on 2026-02-05, but mdkhan-tw is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.467.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.466.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.465.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.464.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.463.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.462.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.461.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.460.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.459.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.458.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.457.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.456.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.455.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.454.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.453.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.452.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.451.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.450.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.449.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.448.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.447.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.446.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.445.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.444.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.443.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.442.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.229.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.228.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.227.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.227.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.226.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.225.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.224.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.221.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.221.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.220.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.219.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.218.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.217.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.217.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.216.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.214.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.213.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.210.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.210.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.209.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.208.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.207.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.206.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.205.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.205.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.205.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.201.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.200.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.200.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.199.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.198.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.197.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.196.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.195.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.193.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.192.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.190.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.189.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.188.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.186.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.184.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.183.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.181.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.180.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.