@segment/actions-core
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): Manual publish by known maintainer, no code changes vs prior approved version. | ai | |
| provenance | publisher-changed | AI (provenance): CI/CD migration with SLSA attestation, improved provenance direction, not compromise. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Org-managed npm team transition, consistent with CI publisher switch. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Bulk maintainer list cleanup aligns with CI/CD publishing migration. | ai | |
| phantom-deps | phantom-dep:@types/node | AI (phantom-deps): @types/node is a legitimate runtime dep for type declarations in this Node.js package. | ai |
Versions (showing 51 of 63)
| Version | Deps | Published |
|---|---|---|
| 3.170.0 | 11 / 6 | |
| 3.169.0 | 11 / 6 | |
| 3.168.0 | 12 / 6 | |
| 3.167.0 | 12 / 6 | |
| 3.166.0 | 12 / 6 | |
| 3.165.0 | 12 / 6 | |
| 3.164.0 | 12 / 6 | |
| 3.163.0 | 12 / 6 | |
| 3.162.0 | 12 / 6 | |
| 3.161.0 | 12 / 6 | |
| 3.160.0 | 12 / 6 | |
| 3.159.0 | 12 / 6 | |
| 3.158.0 | 12 / 6 | |
| 3.157.0 | 12 / 6 | |
| 3.156.0 | 12 / 6 | |
| 3.155.0 | 12 / 6 | |
| 3.154.0 | 12 / 6 | |
| 3.153.0 | 12 / 6 | |
| 3.152.0 | 12 / 6 | |
| 3.151.0 | 12 / 6 | |
| 3.150.0 | 12 / 6 | |
| 3.149.0 | 12 / 6 | |
| 3.148.0 | 12 / 6 | |
| 3.147.0 | 12 / 6 | |
| 3.146.0 | 12 / 6 | |
| 3.145.0 | 12 / 6 | |
| 3.144.0 | 12 / 6 | |
| 3.143.0 | 13 / 6 | |
| 3.142.0 | 13 / 6 | |
| 3.141.0 | 13 / 6 | |
| 3.140.1 | 13 / 6 | |
| 3.140.0 | 13 / 6 | |
| 3.139.0 | 13 / 6 | |
| 3.138.0 | 13 / 6 | |
| 3.137.0 | 13 / 6 | |
| 3.136.0 | 13 / 6 | |
| 3.135.0 | 13 / 6 | |
| 3.134.0 | 13 / 6 | |
| 3.133.0 | 13 / 6 | |
| 3.132.0 | 13 / 6 | |
| 3.131.0 | 13 / 6 | |
| 3.130.0 | 13 / 6 | |
| 3.129.0 | 13 / 6 | |
| 3.128.0 | 13 / 6 | |
| 3.127.0 | 13 / 6 | |
| 3.126.0 | 13 / 6 | |
| 3.125.0 | 13 / 6 | |
| 3.124.0 | 13 / 6 | |
| 3.123.0 | 13 / 6 | |
| 3.122.0 | 13 / 6 | |
| 3.121.0 | 13 / 6 |
v3.170.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.169.0
2 findingsThis version was published by a different npm account than previous versions on 2026-07-09. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.151.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.150.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.149.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.148.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.147.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.146.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.145.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.144.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.143.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.142.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.141.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.140.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.140.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.139.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.138.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.137.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.136.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.135.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.134.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.133.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.132.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.131.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.130.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.129.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.128.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.127.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.126.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.125.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.124.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.123.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.122.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (forgetfulfellow) than the most recent previously approved version (joe.ayoub.segment) on 2024-07-09, but forgetfulfellow is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.121.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (marinhero) than the most recent previously approved version (joe.ayoub.segment) on 2024-07-03, but marinhero is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.