@sentry/nestjs
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | dormant-publish | AI (publish-pattern): Major version jump from v8 to v10 explains the gap; sentry-bot is a well-established publisher. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New OTel deps match the package's NestJS instrumentation purpose and are all established CNCF packages. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size increase consistent with bundling multiple OTel instrumentation libraries in a major version upgrade. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/api | AI (phantom-deps): Indirect dependency via instrumentation-nestjs-core; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/core | AI (phantom-deps): Indirect dependency via instrumentation-nestjs-core; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/semantic-conventions | AI (phantom-deps): Indirect dependency via instrumentation-nestjs-core; stable pattern for this package. | ai |
Versions (showing 51 of 74)
| Version | Deps | Published |
|---|---|---|
| 10.67.0 | 6 / 4 | |
| 10.66.0 | 6 / 4 | |
| 10.65.0 | 5 / 4 | |
| 10.64.0 | 5 / 4 | |
| 10.63.0 | 5 / 4 | |
| 10.62.0 | 5 / 4 | |
| 10.61.0 | 5 / 4 | |
| 10.60.0 | 5 / 4 | |
| 10.59.0 | 5 / 4 | |
| 10.58.0 | 5 / 4 | |
| 10.57.0 | 5 / 4 | |
| 10.56.0 | 5 / 4 | |
| 10.55.0 | 6 / 4 | |
| 10.54.0 | 6 / 4 | |
| 10.53.1 | 7 / 4 | |
| 10.53.0 | 7 / 4 | |
| 10.52.0 | 7 / 4 | |
| 10.51.0 | 7 / 4 | |
| 10.50.0 | 7 / 4 | |
| 10.49.0 | 7 / 4 | |
| 10.48.0 | 7 / 4 | |
| 10.47.0 | 7 / 4 | |
| 10.46.0 | 7 / 4 | |
| 10.45.0 | 7 / 4 | |
| 10.44.0 | 7 / 4 | |
| 10.43.0 | 7 / 4 | |
| 10.42.0 | 7 / 4 | |
| 10.41.0 | 7 / 4 | |
| 10.40.0 | 7 / 4 | |
| 10.39.0 | 7 / 4 | |
| 10.38.0 | 7 / 4 | |
| 10.37.0 | 7 / 4 | |
| 10.36.0 | 7 / 4 | |
| 10.35.0 | 7 / 4 | |
| 10.34.0 | 7 / 4 | |
| 10.33.0 | 7 / 4 | |
| 10.32.1 | 7 / 4 | |
| 10.32.0 | 7 / 4 | |
| 10.31.0 | 7 / 4 | |
| 10.30.0 | 7 / 4 | |
| 10.29.0 | 7 / 4 | |
| 10.28.0 | 7 / 4 | |
| 10.27.0 | 7 / 4 | |
| 10.26.0 | 7 / 4 | |
| 10.25.0 | 7 / 4 | |
| 10.24.0 | 7 / 4 | |
| 10.23.0 | 7 / 4 | |
| 10.22.0 | 7 / 4 | |
| 10.21.0 | 7 / 4 | |
| 10.20.0 | 7 / 4 | |
| 10.19.0 | 7 / 4 |
v10.67.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.66.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.65.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.64.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.63.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.62.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.