@segment/actions-core
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): Manual publish by known maintainer, no code changes vs prior approved version. | ai | |
| provenance | publisher-changed | AI (provenance): CI/CD migration with SLSA attestation, improved provenance direction, not compromise. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Org-managed npm team transition, consistent with CI publisher switch. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Bulk maintainer list cleanup aligns with CI/CD publishing migration. | ai | |
| phantom-deps | phantom-dep:@types/node | AI (phantom-deps): @types/node is a legitimate runtime dep for type declarations in this Node.js package. | ai |
Versions (showing 63 of 63)
| Version | Deps | Published |
|---|---|---|
| 3.170.0 | 11 / 6 | |
| 3.169.0 | 11 / 6 | |
| 3.168.0 | 12 / 6 | |
| 3.167.0 | 12 / 6 | |
| 3.166.0 | 12 / 6 | |
| 3.165.0 | 12 / 6 | |
| 3.164.0 | 12 / 6 | |
| 3.163.0 | 12 / 6 | |
| 3.162.0 | 12 / 6 | |
| 3.161.0 | 12 / 6 | |
| 3.160.0 | 12 / 6 | |
| 3.159.0 | 12 / 6 | |
| 3.158.0 | 12 / 6 | |
| 3.157.0 | 12 / 6 | |
| 3.156.0 | 12 / 6 | |
| 3.155.0 | 12 / 6 | |
| 3.154.0 | 12 / 6 | |
| 3.153.0 | 12 / 6 | |
| 3.152.0 | 12 / 6 | |
| 3.151.0 | 12 / 6 | |
| 3.150.0 | 12 / 6 | |
| 3.149.0 | 12 / 6 | |
| 3.148.0 | 12 / 6 | |
| 3.147.0 | 12 / 6 | |
| 3.146.0 | 12 / 6 | |
| 3.145.0 | 12 / 6 | |
| 3.144.0 | 12 / 6 | |
| 3.143.0 | 13 / 6 | |
| 3.142.0 | 13 / 6 | |
| 3.141.0 | 13 / 6 | |
| 3.140.1 | 13 / 6 | |
| 3.140.0 | 13 / 6 | |
| 3.139.0 | 13 / 6 | |
| 3.138.0 | 13 / 6 | |
| 3.137.0 | 13 / 6 | |
| 3.136.0 | 13 / 6 | |
| 3.135.0 | 13 / 6 | |
| 3.134.0 | 13 / 6 | |
| 3.133.0 | 13 / 6 | |
| 3.132.0 | 13 / 6 | |
| 3.131.0 | 13 / 6 | |
| 3.130.0 | 13 / 6 | |
| 3.129.0 | 13 / 6 | |
| 3.128.0 | 13 / 6 | |
| 3.127.0 | 13 / 6 | |
| 3.126.0 | 13 / 6 | |
| 3.125.0 | 13 / 6 | |
| 3.124.0 | 13 / 6 | |
| 3.123.0 | 13 / 6 | |
| 3.122.0 | 13 / 6 | |
| 3.121.0 | 13 / 6 | |
| 3.120.0 | 13 / 6 | |
| 3.117.0 | 13 / 6 | |
| 3.116.0 | 13 / 6 | |
| 3.115.0 | 13 / 6 | |
| 3.114.1 | 13 / 6 | |
| 3.114.0 | 13 / 6 | |
| 3.113.0 | 13 / 6 | |
| 3.112.0 | 13 / 6 | |
| 3.111.0 | 13 / 6 | |
| 3.110.0 | 13 / 6 | |
| 3.109.0 | 13 / 6 | |
| 3.108.0 | 13 / 6 |
v3.170.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.169.0
2 findingsThis version was published by a different npm account than previous versions on 2026-07-09. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.151.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.150.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.149.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.148.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.147.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.146.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.145.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.144.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.143.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.142.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.141.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.140.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.140.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.139.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.138.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.137.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.136.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.135.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.134.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.133.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.132.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.131.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.130.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.129.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.128.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.127.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.126.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.125.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.124.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.123.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.122.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (forgetfulfellow) than the most recent previously approved version (joe.ayoub.segment) on 2024-07-09, but forgetfulfellow is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.121.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (marinhero) than the most recent previously approved version (joe.ayoub.segment) on 2024-07-03, but marinhero is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.120.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (joe.ayoub.segment) than the most recent previously approved version (forgetfulfellow) on 2024-07-02, but joe.ayoub.segment is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.117.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (varadarajan-tw) than the most recent previously approved version (forgetfulfellow) on 2024-07-02, but varadarajan-tw is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.116.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.115.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.114.1
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: gkochar123.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (gkochar123) than the most recent previously approved version (forgetfulfellow) on 2024-06-12, but gkochar123 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.114.0
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: pooyaj.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (pooyaj) than the most recent previously approved version (forgetfulfellow) on 2024-06-11, but pooyaj is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.113.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.112.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.111.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.110.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.109.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.108.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.