@sentry/replay
User replays for Sentry
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | dormant-publish | AI (publish-pattern): Major version jump (7→10) explains gap; sentry-bot is a trusted high-volume publisher. | ai | |
| source-diff | obfuscated-file:build/npm/esm/index.js | AI (source-diff): Standard bundled ESM output for Sentry replay SDK; readable code visible in sample. | ai | |
| source-diff | obfuscated-file:build/npm/cjs/worker-bundler.js | AI (source-diff): Bundled fflate compression library for web worker; expected for replay package. | ai | |
| source-diff | obfuscated-file:build/npm/esm/worker-bundler.js | AI (source-diff): Bundled fflate compression library for web worker; expected for replay package. | ai | |
| source-diff | obfuscated-file:build/npm/cjs/index.js | AI (source-diff): Standard bundled CJS output for Sentry replay SDK; readable code visible in sample. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Reflect.get() is used in a Proxy handler for deprecation warnings on mirrored APIs — idiomatic JS, not obfuscation. Stable pattern in Sentry SDK. | ai | |
| provenance | no-provenance | AI (provenance): Sentry does not publish with Sigstore provenance for this package; consistent across all releases and not a security risk given the trusted publisher. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Sentry is a large org; maintainer roster changes over time are routine. Publisher remains the trusted sentry-bot account with no new unknown maintainers added. | ai |
Versions (showing 51 of 193)
| Version | Deps | Published |
|---|---|---|
| 10.68.0 | 2 / 7 | |
| 10.67.0 | 2 / 7 | |
| 10.66.0 | 2 / 7 | |
| 10.65.0 | 2 / 7 | |
| 10.64.0 | 2 / 7 | |
| 10.63.0 | 2 / 7 | |
| 10.62.0 | 2 / 7 | |
| 10.61.0 | 2 / 7 | |
| 10.60.0 | 2 / 7 | |
| 10.59.0 | 2 / 7 | |
| 10.58.0 | 2 / 7 | |
| 7.120.4 | 4 / 6 | |
| 7.120.3 | 4 / 6 | |
| 7.120.2 | 4 / 6 | |
| 7.120.1 | 4 / 6 | |
| 7.120.0 | 4 / 6 | |
| 7.119.2 | 4 / 6 | |
| 7.119.1 | 4 / 6 | |
| 7.119.0 | 4 / 6 | |
| 7.118.0 | 4 / 6 | |
| 7.117.0 | 4 / 6 | |
| 7.116.0 | 4 / 6 | |
| 7.115.0 | 4 / 6 | |
| 7.114.0 | 4 / 6 | |
| 7.113.0 | 4 / 6 | |
| 7.112.2 | 4 / 6 | |
| 7.112.1 | 4 / 6 | |
| 7.112.0 | 4 / 6 | |
| 7.111.0 | 4 / 6 | |
| 7.110.1 | 4 / 6 | |
| 7.110.0 | 4 / 6 | |
| 7.109.0 | 4 / 6 | |
| 7.108.0 | 4 / 6 | |
| 7.107.0 | 4 / 6 | |
| 7.106.1 | 4 / 6 | |
| 7.106.0 | 4 / 6 | |
| 7.105.0 | 4 / 6 | |
| 7.104.0 | 4 / 6 | |
| 7.103.0 | 4 / 6 | |
| 7.102.1 | 4 / 6 | |
| 7.102.0 | 4 / 6 | |
| 7.101.1 | 4 / 6 | |
| 7.101.0 | 4 / 6 | |
| 7.100.1 | 4 / 6 | |
| 7.100.0 | 4 / 6 | |
| 7.99.0 | 4 / 6 | |
| 7.98.0 | 4 / 6 | |
| 7.97.0 | 4 / 6 | |
| 7.96.0 | 4 / 6 | |
| 7.95.0 | 4 / 6 | |
| 7.94.1 | 4 / 6 |
v10.68.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.67.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.66.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.65.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.64.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.63.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.