@zuplo/otel
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:ts-checked-fsm | AI (phantom-deps): ts-checked-fsm is a declared dependency used in build config; phantom-dep false positive for this bundled package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Internal utility package in a large corporate monorepo; missing README/keywords/description is consistent with the package's nature across all 1493 versions. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/api-logs | AI (phantom-deps): Package bundles its deps into ESM output; @opentelemetry/api-logs is declared in dependencies. Not a true phantom dep. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/resources | AI (phantom-deps): Package bundles its deps into ESM output; @opentelemetry/resources is declared in dependencies. Not a true phantom dep. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/otlp-transformer | AI (phantom-deps): Package bundles its deps into ESM output; @opentelemetry/otlp-transformer is declared in dependencies. Not a true phantom dep. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Fired on standard bundler output (esbuild/rollup minification). The sample shows Object.defineProperty for function naming, not malicious Reflect.get() usage. False positive for this bundled package. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/semantic-conventions | AI (phantom-deps): Package bundles its deps into ESM output; @opentelemetry/semantic-conventions is declared in dependencies. Not a true phantom dep. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/exporter-trace-otlp-http | AI (phantom-deps): Package bundles its deps into ESM output; @opentelemetry/exporter-trace-otlp-http is declared in dependencies. Not a true phantom dep. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/otlp-exporter-base | AI (phantom-deps): Package bundles its deps into ESM output; @opentelemetry/otlp-exporter-base is declared in dependencies. Not a true phantom dep. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/core | AI (phantom-deps): Package bundles its deps into ESM output; @opentelemetry/core is declared in dependencies. Not a true phantom dep. | ai |
Versions (showing 100 of 465)
| Version | Deps | Published |
|---|---|---|
| 6.59.6 | 8 / 2 | |
| 6.59.5 | 8 / 2 | |
| 6.59.4 | 8 / 2 | |
| 6.59.3 | 8 / 2 | |
| 6.59.2 | 8 / 2 | |
| 6.59.1 | 8 / 2 | |
| 6.59.0 | 8 / 2 | |
| 6.58.8 | 8 / 2 | |
| 6.58.7 | 8 / 2 | |
| 6.58.6 | 8 / 2 | |
| 6.58.5 | 8 / 2 | |
| 6.58.4 | 8 / 2 | |
| 6.58.2 | 8 / 2 | |
| 6.58.0 | 8 / 2 | |
| 6.57.19 | 8 / 2 | |
| 6.57.18 | 8 / 2 | |
| 6.57.17 | 8 / 2 | |
| 6.57.16 | 8 / 2 | |
| 6.57.15 | 8 / 2 | |
| 6.57.14 | 8 / 2 | |
| 6.57.13 | 8 / 2 | |
| 6.57.12 | 8 / 2 | |
| 6.57.11 | 8 / 2 | |
| 6.57.10 | 8 / 2 | |
| 6.57.7 | 8 / 2 | |
| 6.57.6 | 8 / 2 | |
| 6.57.5 | 8 / 2 | |
| 6.57.4 | 8 / 2 | |
| 6.57.3 | 8 / 2 | |
| 6.57.2 | 8 / 2 | |
| 6.57.1 | 8 / 2 | |
| 6.57.0 | 8 / 2 | |
| 6.56.8 | 8 / 2 | |
| 6.56.7 | 8 / 2 | |
| 6.56.6 | 8 / 2 | |
| 6.56.5 | 8 / 2 | |
| 6.56.4 | 8 / 2 | |
| 6.56.2 | 8 / 2 | |
| 6.56.1 | 8 / 2 | |
| 6.56.0 | 8 / 2 | |
| 6.55.6 | 8 / 2 | |
| 6.55.5 | 8 / 2 | |
| 6.55.4 | 8 / 2 | |
| 6.55.3 | 8 / 2 | |
| 6.55.2 | 8 / 2 | |
| 6.55.1 | 8 / 2 | |
| 6.55.0 | 8 / 2 | |
| 6.54.29 | 8 / 2 | |
| 6.54.26 | 8 / 2 | |
| 6.54.24 | 8 / 2 | |
| 6.54.23 | 8 / 2 | |
| 6.54.22 | 8 / 2 | |
| 6.54.21 | 8 / 2 | |
| 6.54.20 | 8 / 2 | |
| 6.54.19 | 8 / 2 | |
| 6.54.18 | 8 / 2 | |
| 6.54.17 | 8 / 2 | |
| 6.54.16 | 8 / 2 | |
| 6.54.15 | 8 / 2 | |
| 6.54.14 | 8 / 2 | |
| 6.54.13 | 8 / 2 | |
| 6.54.12 | 8 / 2 | |
| 6.54.9 | 8 / 2 | |
| 6.54.8 | 8 / 2 | |
| 6.54.7 | 8 / 2 | |
| 6.54.6 | 8 / 2 | |
| 6.54.5 | 8 / 2 | |
| 6.54.4 | 8 / 2 | |
| 6.54.3 | 8 / 2 | |
| 6.54.2 | 8 / 2 | |
| 6.54.1 | 8 / 2 | |
| 6.54.0 | 8 / 2 | |
| 6.53.1 | 8 / 2 | |
| 6.53.0 | 8 / 2 | |
| 6.52.25 | 8 / 2 | |
| 6.52.24 | 8 / 2 | |
| 6.52.23 | 8 / 2 | |
| 6.52.22 | 8 / 2 | |
| 6.52.21 | 8 / 2 | |
| 6.52.20 | 8 / 2 | |
| 6.52.19 | 8 / 2 | |
| 6.52.18 | 8 / 2 | |
| 6.52.17 | 8 / 2 | |
| 6.52.16 | 8 / 2 | |
| 6.52.15 | 8 / 2 | |
| 6.52.14 | 8 / 2 | |
| 6.52.13 | 8 / 2 | |
| 6.52.12 | 8 / 2 | |
| 6.52.10 | 8 / 2 | |
| 6.52.7 | 8 / 2 | |
| 6.52.6 | 8 / 2 | |
| 6.52.5 | 8 / 2 | |
| 6.52.4 | 8 / 2 | |
| 6.52.3 | 8 / 2 | |
| 6.52.2 | 8 / 2 | |
| 6.52.1 | 8 / 2 | |
| 6.52.0 | 8 / 2 | |
| 6.51.84 | 8 / 2 | |
| 6.51.83 | 8 / 2 | |
| 6.51.81 | 8 / 2 |
v6.58.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.57.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.54.13
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.52.25
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.52.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.