@segment/analytics-browser-actions-fullsession
12
Versions
—
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
twilio-supply-chainsegmentiosegment-admin
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-added | AI (maintainer-change): Consistent with org-wide npm maintainer consolidation across Segment monorepo packages. | ai | |
| provenance | publisher-changed | AI (provenance): Org-wide shift to CI/CD publishing bot with SLSA attestation, not a compromise indicator. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Mass removal reflects org-wide maintainer list cleanup, not targeted takeover of this package. | ai | |
| provenance | no-provenance | AI (provenance): No provenance across all 89 versions; stable pattern for this publisher. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Consistent across all versions; not indicative of malicious intent for this package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Monorepo-published Segment plugin; missing metadata is a style issue, not a malware indicator. | ai | |
| dependencies | unvetted-dep:@segment/browser-destination-runtime | AI (dependencies): Core Segment browser destination runtime; expected dependency for this package family. | ai |
Versions (showing 12 of 12)
| Version | Deps | Published |
|---|---|---|
| 1.12.0 | 2 / 0 | |
| 1.11.0 | 2 / 0 | |
| 1.10.0 | 2 / 0 | |
| 1.9.0 | 2 / 0 | |
| 1.8.0 | 2 / 0 | |
| 1.7.0 | 2 / 0 | |
| 1.6.0 | 2 / 0 | |
| 1.5.0 | 2 / 0 | |
| 1.4.0 | 2 / 0 | |
| 1.3.0 | 2 / 0 | |
| 1.2.0 | 2 / 0 | |
| 1.1.0 | 2 / 0 |
v1.12.0
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.11.0
2 findings
HIGH
Publisher changed: varadarajan-tw → GitHub Actions (on 2026-07-09)
provenance
This version was published by a different npm account than previous versions on 2026-07-09. This could indicate a legitimate maintainer transition or an account compromise.
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.