@segment/actions-core
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@types/node | AI (phantom-deps): @types/node is a legitimate runtime dep for type declarations in this Node.js package. | ai |
Versions (showing 17 of 17)
| Version | Deps | Published |
|---|---|---|
| 3.168.0 | 12 / 6 | |
| 3.167.0 | 12 / 6 | |
| 3.166.0 | 12 / 6 | |
| 3.165.0 | 12 / 6 | |
| 3.164.0 | 12 / 6 | |
| 3.163.0 | 12 / 6 | |
| 3.162.0 | 12 / 6 | |
| 3.161.0 | 12 / 6 | |
| 3.160.0 | 12 / 6 | |
| 3.159.0 | 12 / 6 | |
| 3.158.0 | 12 / 6 | |
| 3.157.0 | 12 / 6 | |
| 3.156.0 | 12 / 6 | |
| 3.155.0 | 12 / 6 | |
| 3.154.0 | 12 / 6 | |
| 3.153.0 | 12 / 6 | |
| 3.152.0 | 12 / 6 |
v3.167.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.166.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.165.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.164.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.163.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.162.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.161.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.160.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.159.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.158.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.157.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.156.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.155.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.154.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.153.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.152.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.