← Home

@segment/analytics-next

20
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

twilio-supply-chainsegmentiosegment-admin

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/umd/tsub-middleware.bundle.89bf07058b3d3b126984.js AI (source-diff): Webpack UMD bundle output, hashed filename; minified not obfuscated. ai
source-diff obfuscated-file:dist/umd/ajs-destination.bundle.40628baed746e9904edc.js AI (source-diff): Webpack UMD bundle output, hashed filename; minified not obfuscated. ai
source-diff obfuscated-file:dist/umd/ajs-destination.bundle.8e6b895db75187c55313.js AI (source-diff): Webpack UMD bundle with banner; benign build artifact. ai
source-diff obfuscated-file:dist/umd/tsub-middleware.bundle.d94be5c4b3baf7f16aa2.js AI (source-diff): Webpack UMD bundle; benign build artifact. ai
source-diff obfuscated-file:dist/umd/407.bundle.61efa1acb302134c434b.js AI (source-diff): Webpack UMD build output, not obfuscation; regenerated each release. ai
source-diff obfuscated-file:dist/umd/tsub-middleware.bundle.c0f5511a001f780f591f.js AI (source-diff): Webpack-bundled tsub middleware; build artifact stable for this package. ai
source-diff obfuscated-file:src/vendor/tsub/tsub.ts AI (source-diff): Vendored generated @segment/tsub bundle; benign minified output. ai
phantom-deps phantom-dep:dset AI (phantom-deps): dset is a declared runtime dep; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:@segment/analytics.js-video-plugins AI (phantom-deps): Same-org dep; phantom-dep heuristic false positive for this package. ai

Versions (showing 20 of 20)

Version Deps Published
1.84.1 11 / 40
1.84.0 11 / 40
1.83.0 11 / 40
1.82.0 11 / 40
1.81.2 11 / 40
1.81.1 11 / 40
1.81.0 11 / 40
1.79.0 10 / 39
1.78.1 10 / 39
1.76.1 10 / 39
1.76.0 10 / 39
1.75.0 10 / 39
1.74.0 10 / 39
1.73.0 10 / 39
1.72.2 10 / 39
1.72.1 10 / 39
1.72.0 10 / 39
1.71.0 11 / 38
1.70.0 11 / 38
1.69.0 11 / 38

v1.84.1

4 findings
HIGH New obfuscated file: dist/umd/ajs-destination.bundle.40628baed746e9904edc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/umd/tsub-middleware.bundle.89bf07058b3d3b126984.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: segment-admin → GitHub Actions (on 2026-07-20, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (segment-admin) on 2026-07-20, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.81.0

5 findings
HIGH New obfuscated file: dist/umd/407.bundle.61efa1acb302134c434b.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/umd/ajs-destination.bundle.8e6b895db75187c55313.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/umd/tsub-middleware.bundle.d94be5c4b3baf7f16aa2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: src/vendor/tsub/tsub.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.79.0

5 findings
HIGH New obfuscated file: dist/umd/407.bundle.61efa1acb302134c434b.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/umd/ajs-destination.bundle.8e6b895db75187c55313.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/umd/tsub-middleware.bundle.d94be5c4b3baf7f16aa2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: src/vendor/tsub/tsub.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.78.1

5 findings
HIGH New obfuscated file: dist/umd/407.bundle.61efa1acb302134c434b.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/umd/ajs-destination.bundle.8e6b895db75187c55313.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/umd/tsub-middleware.bundle.d94be5c4b3baf7f16aa2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: src/vendor/tsub/tsub.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.76.1

3 findings
HIGH New obfuscated file: dist/umd/tsub-middleware.bundle.c0f5511a001f780f591f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: src/vendor/tsub/tsub.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.76.0

3 findings
HIGH New obfuscated file: dist/umd/tsub-middleware.bundle.c0f5511a001f780f591f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: src/vendor/tsub/tsub.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.75.0

3 findings
HIGH New obfuscated file: dist/umd/tsub-middleware.bundle.c0f5511a001f780f591f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: src/vendor/tsub/tsub.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.74.0

3 findings
HIGH New obfuscated file: dist/umd/tsub-middleware.bundle.c0f5511a001f780f591f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: src/vendor/tsub/tsub.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.73.0

3 findings
HIGH New obfuscated file: dist/umd/tsub-middleware.bundle.c0f5511a001f780f591f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: src/vendor/tsub/tsub.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.72.2

3 findings
HIGH New obfuscated file: dist/umd/tsub-middleware.bundle.c0f5511a001f780f591f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: src/vendor/tsub/tsub.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.72.1

3 findings
HIGH New obfuscated file: dist/umd/tsub-middleware.bundle.c0f5511a001f780f591f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: src/vendor/tsub/tsub.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.72.0

3 findings
HIGH New obfuscated file: dist/umd/tsub-middleware.bundle.c0f5511a001f780f591f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: src/vendor/tsub/tsub.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.71.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.70.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.69.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.