All inngest versions

inngest @3.53.1

rejected
This version was rejected. It did not pass GreenFlagged's security review and is not served by the registry. The findings and risk dispositions below explain why.
90
Risk Score
Apache-2.0
License
No
Install Scripts
26
Dependencies
43
Dev Dependencies
887.2 KB
Package Size
Published

Official SDK for Inngest.com. Inngest is the reliability layer for modern applications. Inngest combines durable execution, events, and queues into a zero-infra platform with built-in observability.

Maintainers

djfarrellyjpwilliamsdarwin67goodoldneoninngest-release-botlinell_inngest

Keywords

inngesttask managerworkflowworkflowsorchestrationtask orchestrationeventswebhookstask schedulerscheduled jobscron jobsqueueserverless event-driven systemsjob schedulerbackground jobsstep functionjob processingllm prompt chainingdurable executionlongrunninglong-runningtask sequencingdurable workflowreliabilityreliability layerparallel processingflow control

Dependencies (26)

PackageConstraintRegistry Status
ms ^2.1.3 auto_approved
zod ^3.25.0 auto_approved
ulid ^2.3.0 pending
chalk ^4.1.2 auto_approved
debug ^4.3.4 auto_approved
hash.js ^1.1.7 auto_approved
@types/ms ~2.1.0 needs_review
strip-ansi ^5.2.0 auto_approved
@inngest/ai ^0.1.3 auto_approved
cross-fetch ^4.0.0 auto_approved
@types/debug ^4.1.12 auto_approved
canonicalize ^1.0.8 pending
temporal-polyfill ^0.2.5 pending
@bufbuild/protobuf ^2.2.3 auto_approved
@opentelemetry/api ^1.9.0 auto_approved
json-stringify-safe ^5.0.1 auto_approved
serialize-error-cjs ^0.1.3 pending
@jpwilliams/waitgroup ^2.1.1 auto_approved
@standard-schema/spec ^1.0.0 auto_approved
@opentelemetry/resources >=2.0.0 <3.0.0 auto_approved
@opentelemetry/sdk-trace-base >=2.0.0 <3.0.0 auto_approved
@opentelemetry/instrumentation >=0.200.0 <0.300.0 auto_approved
@opentelemetry/context-async-hooks >=2.0.0 <3.0.0 auto_approved
@traceloop/instrumentation-anthropic ^0.20.0 pending
@opentelemetry/exporter-trace-otlp-http >=0.200.0 <0.300.0 auto_approved
@opentelemetry/auto-instrumentations-node >=0.66.0 <1.0.0 auto_approved

Dev Dependencies (43)

PackageConstraintRegistry Status
h3 ^1.8.1 auto_approved
koa ^2.14.2 auto_approved
shx ^0.3.4 auto_approved
tsx ^3.12.7 pending
glob ^10.3.10 auto_approved
hono ^4.2.7 auto_approved
next ^13.5.4 auto_approved
nock ^13.2.9 auto_approved
mitata ^0.1.11 auto_approved
tsdown 0.15.4 auto_approved
vitest ^3.0.8 auto_approved
express ^4.19.2 auto_approved
fastify ^4.21.0 auto_approved
globals ^15.14.0 auto_approved
nodemon ^2.0.20 pending
inquirer ^9.2.10 auto_approved
minimist ^1.2.8 auto_approved
prettier ^3.1.0 auto_approved
ts-proto ^2.6.1 auto_approved
callsites ^4.1.0 auto_approved
@types/koa ~3.0.0 auto_approved
aws-lambda ^1.0.7 auto_approved
genversion ^3.1.1 Not imported
typescript ^5.9.2 auto_approved
@types/node ~24.3.0 auto_approved
@vercel/node ^2.15.9 auto_approved
concurrently ^7.4.0 auto_approved
@actions/core ^1.10.0 auto_approved
@actions/exec ^1.1.1 auto_approved
@inngest/test workspace:^ Not imported
@sveltejs/kit ^1.27.3 auto_approved
@types/sha.js ~2.4.4 pending
@types/express ~5.0.3 auto_approved
@types/inquirer ~9.0.9 auto_approved
@types/minimist ~1.2.5 auto_approved
node-mocks-http ^1.11.0 auto_approved
@types/aws-lambda ~8.10.152 auto_approved
vitest-fetch-mock ^0.4.5 pending
@vitest/coverage-v8 3.0.8 needs_review
vite-tsconfig-paths ^5.1.4 pending
@total-typescript/shoehorn ^0.1.1 Not imported
@types/json-stringify-safe ~5.0.3 Not imported
@story-health/vitest-koa-mocks ^5.1.3 Not imported

Transitive Dependency Tree

171 transitive deps max depth 10
  ├─ @bufbuild/protobuf ^2.2.3 → 2.12.0
  ├─ @inngest/ai ^0.1.3 → 0.1.7
  ├─ @jpwilliams/waitgroup ^2.1.1 → 2.1.1
  ├─ @opentelemetry/api ^1.9.0 → 1.9.1
  ├─ @opentelemetry/auto-instrumentations-node >=0.66.0 <1.0.0 → 0.73.0
  ├─ @opentelemetry/context-async-hooks >=2.0.0 <3.0.0 → 2.7.0
  ├─ @opentelemetry/exporter-trace-otlp-http >=0.200.0 <0.300.0 → 0.216.0
  ├─ @opentelemetry/instrumentation >=0.200.0 <0.300.0 → 0.215.0
  ├─ @opentelemetry/resources >=2.0.0 <3.0.0 → 2.7.1
  ├─ @opentelemetry/sdk-trace-base >=2.0.0 <3.0.0 → 2.7.1
  ├─ @standard-schema/spec ^1.0.0 → 1.1.0
  ├─ @traceloop/instrumentation-anthropic ^0.20.0
  ├─ @types/debug ^4.1.12 → 4.1.13
  ├─ @types/ms ~2.1.0
  ├─ canonicalize ^1.0.8
  ├─ chalk ^4.1.2 → 4.1.2
  ├─ cross-fetch ^4.0.0 → 4.1.0
  ├─ debug ^4.3.4 → 4.4.3
  ├─ hash.js ^1.1.7 → 1.1.7
  ├─ json-stringify-safe ^5.0.1 → 5.0.1
  ├─ ms ^2.1.3 → 2.1.3
  ├─ serialize-error-cjs ^0.1.3
  ├─ strip-ansi ^5.2.0 → 5.2.0
  ├─ temporal-polyfill ^0.2.5
  ├─ ulid ^2.3.0
├─ zod ^3.25.0 → 3.25.76
  ├─ @opentelemetry/api-logs 0.215.0 → 0.215.0
  ├─ @opentelemetry/core 2.7.1 → 2.7.1
  ├─ @opentelemetry/instrumentation ^0.215.0 → 0.215.0
  ├─ @opentelemetry/instrumentation-amqplib ^0.62.0 → 0.62.0
  ├─ @opentelemetry/instrumentation-aws-lambda ^0.67.0 → 0.67.0
  ├─ @opentelemetry/instrumentation-aws-sdk ^0.70.0 → 0.70.0
  ├─ @opentelemetry/instrumentation-bunyan ^0.60.0 → 0.60.0
  ├─ @opentelemetry/instrumentation-cassandra-driver ^0.60.0 → 0.60.0
  ├─ @opentelemetry/instrumentation-connect ^0.58.0 → 0.58.0
  ├─ @opentelemetry/instrumentation-cucumber ^0.31.0 → 0.31.0
  ├─ @opentelemetry/instrumentation-dataloader ^0.32.0 → 0.32.0
  ├─ @opentelemetry/instrumentation-dns ^0.58.0 → 0.58.0
  ├─ @opentelemetry/instrumentation-express ^0.63.0 → 0.63.0
  ├─ @opentelemetry/instrumentation-fs ^0.34.0 → 0.34.0
  ├─ @opentelemetry/instrumentation-generic-pool ^0.58.0 → 0.58.0
  ├─ @opentelemetry/instrumentation-graphql ^0.63.0 → 0.63.0
  ├─ @opentelemetry/instrumentation-grpc ^0.215.0 → 0.215.0
  ├─ @opentelemetry/instrumentation-hapi ^0.61.0 → 0.61.0
  ├─ @opentelemetry/instrumentation-http ^0.215.0 → 0.215.0
  ├─ @opentelemetry/instrumentation-ioredis ^0.63.0 → 0.63.0
  ├─ @opentelemetry/instrumentation-kafkajs ^0.24.0 → 0.24.0
  ├─ @opentelemetry/instrumentation-knex ^0.59.0 → 0.59.0
  ├─ @opentelemetry/instrumentation-koa ^0.63.0 → 0.63.0
  ├─ @opentelemetry/instrumentation-lru-memoizer ^0.59.0 → 0.59.0
  ├─ @opentelemetry/instrumentation-memcached ^0.58.0 → 0.58.0
  ├─ @opentelemetry/instrumentation-mongodb ^0.68.0 → 0.68.0
  ├─ @opentelemetry/instrumentation-mongoose ^0.61.0 → 0.61.0
  ├─ @opentelemetry/instrumentation-mysql ^0.61.0 → 0.61.0
  ├─ @opentelemetry/instrumentation-mysql2 ^0.61.0 → 0.61.0
  ├─ @opentelemetry/instrumentation-nestjs-core ^0.61.0 → 0.61.0
  ├─ @opentelemetry/instrumentation-net ^0.59.0 → 0.59.0
  ├─ @opentelemetry/instrumentation-openai ^0.13.0 → 0.13.0
  ├─ @opentelemetry/instrumentation-oracledb ^0.40.0 → 0.40.0
  ├─ @opentelemetry/instrumentation-pg ^0.67.0 → 0.67.0
  ├─ @opentelemetry/instrumentation-pino ^0.61.0 → 0.61.0
  ├─ @opentelemetry/instrumentation-redis ^0.63.0 → 0.63.0
  ├─ @opentelemetry/instrumentation-restify ^0.60.0 → 0.60.0
  ├─ @opentelemetry/instrumentation-router ^0.59.0 → 0.59.0
  ├─ @opentelemetry/instrumentation-runtime-node ^0.28.0 → 0.28.0
  ├─ @opentelemetry/instrumentation-socket.io ^0.62.0 → 0.62.0
  ├─ @opentelemetry/instrumentation-tedious ^0.34.0 → 0.34.0
  ├─ @opentelemetry/instrumentation-undici ^0.25.0 → 0.25.0
  ├─ @opentelemetry/instrumentation-winston ^0.59.0 → 0.59.0
  ├─ @opentelemetry/otlp-exporter-base 0.216.0 → 0.216.0
  ├─ @opentelemetry/otlp-transformer 0.216.0 → 0.216.0
  ├─ @opentelemetry/resource-detector-alibaba-cloud ^0.33.5 → 0.33.6
  ├─ @opentelemetry/resource-detector-aws ^2.15.0 → 2.16.0
  ├─ @opentelemetry/resource-detector-azure ^0.23.0 → 0.23.0
  ├─ @opentelemetry/resource-detector-container ^0.8.6 → 0.8.7
  ├─ @opentelemetry/resource-detector-gcp ^0.50.0 → 0.50.0
  ├─ @opentelemetry/resources ^2.0.0 → 2.7.1
  ├─ @opentelemetry/resources 2.7.1 → 2.7.1
  ├─ @opentelemetry/sdk-node ^0.215.0 → 0.215.0
  ├─ @opentelemetry/sdk-trace-base 2.7.1 → 2.7.1
  ├─ @opentelemetry/semantic-conventions ^1.29.0 → 1.40.0
  ├─ @types/ms *
  ├─ @types/node ^22.10.5 → 22.19.17
  ├─ ansi-regex ^4.1.0 → 4.1.1
  ├─ ansi-styles ^4.1.0 → 4.3.0
  ├─ import-in-the-middle ^3.0.0 → 3.0.1
  ├─ inherits ^2.0.3 → 2.0.4
  ├─ minimalistic-assert ^1.0.1
  ├─ ms ^2.1.3 → 2.1.3
  ├─ node-fetch ^2.7.0
  ├─ require-in-the-middle ^8.0.0 → 8.0.1
  ├─ supports-color ^7.1.0 → 7.2.0
├─ typescript ^5.7.3 → 5.9.3
  ├─ @opentelemetry/api ^1.3.0 → 1.9.1
  ├─ @opentelemetry/api-logs ^0.215.0 → 0.215.0
  ├─ @opentelemetry/api-logs 0.215.0 → 0.215.0
  ├─ @opentelemetry/api-logs 0.216.0 → 0.216.0
  ├─ @opentelemetry/configuration 0.215.0 → 0.215.0
  ├─ @opentelemetry/context-async-hooks 2.7.0 → 2.7.0
  ├─ @opentelemetry/core 2.7.1 → 2.7.1
  ├─ @opentelemetry/core ^2.0.0 → 2.7.1
  ├─ @opentelemetry/core 2.7.0 → 2.7.0
  ├─ @opentelemetry/exporter-logs-otlp-grpc 0.215.0 → 0.215.0
  ├─ @opentelemetry/exporter-logs-otlp-http 0.215.0 → 0.215.0
  ├─ @opentelemetry/exporter-logs-otlp-proto 0.215.0 → 0.215.0
  ├─ @opentelemetry/exporter-metrics-otlp-grpc 0.215.0 → 0.215.0
  ├─ @opentelemetry/exporter-metrics-otlp-http 0.215.0 → 0.215.0
  ├─ @opentelemetry/exporter-metrics-otlp-proto 0.215.0 → 0.215.0
  ├─ @opentelemetry/exporter-prometheus 0.215.0 → 0.215.0
  ├─ @opentelemetry/exporter-trace-otlp-grpc 0.215.0 → 0.215.0
  ├─ @opentelemetry/exporter-trace-otlp-http 0.215.0 → 0.215.0
  ├─ @opentelemetry/exporter-trace-otlp-proto 0.215.0 → 0.215.0
  ├─ @opentelemetry/exporter-zipkin 2.7.0 → 2.7.0
  ├─ @opentelemetry/instrumentation ^0.215.0 → 0.215.0
  ├─ @opentelemetry/instrumentation 0.215.0 → 0.215.0
  ├─ @opentelemetry/otlp-exporter-base 0.215.0 → 0.215.0
  ├─ @opentelemetry/otlp-transformer 0.216.0 → 0.216.0
  ├─ @opentelemetry/propagator-b3 2.7.0 → 2.7.0
  ├─ @opentelemetry/propagator-jaeger 2.7.0 → 2.7.0
  ├─ @opentelemetry/redis-common ^0.38.3 → 0.38.3
  ├─ @opentelemetry/resources 2.7.1 → 2.7.1
  ├─ @opentelemetry/resources ^2.0.0 → 2.7.1
  ├─ @opentelemetry/resources 2.7.0 → 2.7.0
  ├─ @opentelemetry/sdk-logs 0.216.0 → 0.216.0
  ├─ @opentelemetry/sdk-logs 0.215.0 → 0.215.0
  ├─ @opentelemetry/sdk-metrics 2.7.0 → 2.7.0
  ├─ @opentelemetry/sdk-metrics 2.7.1 → 2.7.1
  ├─ @opentelemetry/sdk-trace-base 2.7.0 → 2.7.0
  ├─ @opentelemetry/sdk-trace-base 2.7.1 → 2.7.1
  ├─ @opentelemetry/sdk-trace-node 2.7.0 → 2.7.0
  ├─ @opentelemetry/semantic-conventions ^1.34.0 → 1.40.0
  ├─ @opentelemetry/semantic-conventions ^1.29.0 → 1.40.0
  ├─ @opentelemetry/semantic-conventions ^1.27.0 → 1.40.0
  ├─ @opentelemetry/semantic-conventions ^1.37.0 → 1.40.0
  ├─ @opentelemetry/semantic-conventions ^1.36.0 → 1.40.0
  ├─ @opentelemetry/semantic-conventions ^1.33.0 → 1.40.0
  ├─ @opentelemetry/semantic-conventions ^1.30.0 → 1.40.0
  ├─ @opentelemetry/semantic-conventions ^1.33.1 → 1.40.0
  ├─ @opentelemetry/semantic-conventions ^1.24.0 → 1.40.0
  ├─ @opentelemetry/sql-common ^0.41.2 → 0.41.2
  ├─ @types/aws-lambda ^8.10.155 → 8.10.161
  ├─ @types/bunyan 1.8.11 → 1.8.11
  ├─ @types/connect 3.4.38 → 3.4.38
  ├─ @types/memcached ^2.2.6 → 2.2.10
  ├─ @types/mysql 2.15.27 → 2.15.27
  ├─ @types/oracledb 6.5.2
  ├─ @types/pg 8.15.6 → 8.15.6
  ├─ @types/pg-pool 2.0.7 → 2.0.7
  ├─ @types/tedious ^4.0.14
  ├─ acorn ^8.15.0 → 8.16.0
  ├─ acorn-import-attributes ^1.9.5 → 1.9.5
  ├─ cjs-module-lexer ^2.2.0 → 2.2.0
  ├─ color-convert ^2.0.1
  ├─ debug ^4.3.5 → 4.4.3
  ├─ forwarded-parse 2.1.2 → 2.1.2
  ├─ gcp-metadata ^8.0.0 → 8.1.2
  ├─ has-flag ^4.0.0 → 4.0.0
  ├─ import-in-the-middle ^3.0.0 → 3.0.1
  ├─ module-details-from-path ^1.0.4 → 1.0.4
  ├─ module-details-from-path ^1.0.3 → 1.0.4
  ├─ protobufjs 8.0.1
  ├─ require-in-the-middle ^8.0.0 → 8.0.1
├─ undici-types ~6.21.0 → 6.21.0
  ├─ @grpc/grpc-js ^1.14.3 → 1.14.3
  ├─ @opentelemetry/api ^1.3.0 → 1.9.1
  ├─ @opentelemetry/api-logs 0.216.0 → 0.216.0
  ├─ @opentelemetry/api-logs 0.215.0 → 0.215.0
  ├─ @opentelemetry/context-async-hooks 2.7.0 → 2.7.0
  ├─ @opentelemetry/core ^2.0.0 → 2.7.1
  ├─ @opentelemetry/core 2.7.0 → 2.7.0
  ├─ @opentelemetry/core 2.7.1 → 2.7.1
  ├─ @opentelemetry/exporter-metrics-otlp-http 0.215.0 → 0.215.0
  ├─ @opentelemetry/otlp-exporter-base 0.215.0 → 0.215.0
  ├─ @opentelemetry/otlp-grpc-exporter-base 0.215.0 → 0.215.0
  ├─ @opentelemetry/otlp-transformer 0.215.0 → 0.215.0
  ├─ @opentelemetry/resources 2.7.1 → 2.7.1
  ├─ @opentelemetry/resources 2.7.0 → 2.7.0
  ├─ @opentelemetry/sdk-logs 0.215.0 → 0.215.0
  ├─ @opentelemetry/sdk-logs 0.216.0 → 0.216.0
  ├─ @opentelemetry/sdk-metrics 2.7.1 → 2.7.1
  ├─ @opentelemetry/sdk-metrics 2.7.0 → 2.7.0
  ├─ @opentelemetry/sdk-trace-base 2.7.1 → 2.7.1
  ├─ @opentelemetry/sdk-trace-base 2.7.0 → 2.7.0
  ├─ @opentelemetry/semantic-conventions ^1.29.0 → 1.40.0
  ├─ @types/node * → 25.6.0
  ├─ @types/pg * → 8.20.0
  ├─ acorn ^8.15.0 → 8.16.0
  ├─ acorn-import-attributes ^1.9.5 → 1.9.5
  ├─ cjs-module-lexer ^2.2.0 → 2.2.0
  ├─ debug ^4.3.5 → 4.4.3
  ├─ gaxios ^7.0.0 → 7.1.4
  ├─ google-logging-utils ^1.0.0 → 1.1.3
  ├─ import-in-the-middle ^3.0.0 → 3.0.1
  ├─ json-bigint ^1.0.0 → 1.0.0
  ├─ module-details-from-path ^1.0.4 → 1.0.4
  ├─ module-details-from-path ^1.0.3 → 1.0.4
  ├─ ms ^2.1.3 → 2.1.3
  ├─ pg-protocol * → 1.13.0
  ├─ pg-types ^2.2.0 → 2.2.0
  ├─ protobufjs 8.0.1
  ├─ require-in-the-middle ^8.0.0 → 8.0.1
├─ yaml ^2.0.0 → 2.8.3
  ├─ @grpc/grpc-js ^1.14.3 → 1.14.3
  ├─ @grpc/proto-loader ^0.8.0 → 0.8.0
  ├─ @js-sdsl/ordered-map ^4.4.2 → 4.4.2
  ├─ @opentelemetry/api ^1.3.0 → 1.9.1
  ├─ @opentelemetry/api-logs 0.216.0 → 0.216.0
  ├─ @opentelemetry/api-logs 0.215.0 → 0.215.0
  ├─ @opentelemetry/core 2.7.0 → 2.7.0
  ├─ @opentelemetry/core 2.7.1 → 2.7.1
  ├─ @opentelemetry/otlp-exporter-base 0.215.0 → 0.215.0
  ├─ @opentelemetry/otlp-transformer 0.215.0 → 0.215.0
  ├─ @opentelemetry/resources 2.7.0 → 2.7.0
  ├─ @opentelemetry/resources 2.7.1 → 2.7.1
  ├─ @opentelemetry/sdk-logs 0.215.0 → 0.215.0
  ├─ @opentelemetry/sdk-metrics 2.7.0 → 2.7.0
  ├─ @opentelemetry/sdk-trace-base 2.7.0 → 2.7.0
  ├─ @opentelemetry/semantic-conventions ^1.29.0 → 1.40.0
  ├─ @types/node * → 25.6.0
  ├─ acorn ^8.15.0 → 8.16.0
  ├─ acorn-import-attributes ^1.9.5 → 1.9.5
  ├─ bignumber.js ^9.0.0 → 9.3.1
  ├─ cjs-module-lexer ^2.2.0 → 2.2.0
  ├─ debug ^4.3.5 → 4.4.3
  ├─ extend ^3.0.2 → 3.0.2
  ├─ https-proxy-agent ^7.0.1 → 7.0.6
  ├─ module-details-from-path ^1.0.4 → 1.0.4
  ├─ module-details-from-path ^1.0.3 → 1.0.4
  ├─ ms ^2.1.3 → 2.1.3
  ├─ node-fetch ^3.3.2 → 3.3.2
  ├─ pg-int8 1.0.1
  ├─ pg-protocol * → 1.13.0
  ├─ pg-types ^2.2.0 → 2.2.0
  ├─ postgres-array ~2.0.0
  ├─ postgres-bytea ~1.0.0
  ├─ postgres-date ~1.0.4
  ├─ postgres-interval ^1.1.0
  ├─ protobufjs ^8.0.1 → 8.0.3
├─ undici-types ~7.19.0 → 7.19.2
  ├─ @grpc/proto-loader ^0.8.0 → 0.8.0
  ├─ @js-sdsl/ordered-map ^4.4.2 → 4.4.2
  ├─ @opentelemetry/api ^1.3.0 → 1.9.1
  ├─ @opentelemetry/api-logs 0.215.0 → 0.215.0
  ├─ @opentelemetry/core 2.7.0 → 2.7.0
  ├─ @opentelemetry/core 2.7.1 → 2.7.1
  ├─ @opentelemetry/otlp-transformer 0.215.0 → 0.215.0
  ├─ @opentelemetry/resources 2.7.0 → 2.7.0
  ├─ @opentelemetry/sdk-logs 0.215.0 → 0.215.0
  ├─ @opentelemetry/sdk-metrics 2.7.0 → 2.7.0
  ├─ @opentelemetry/sdk-trace-base 2.7.0 → 2.7.0
  ├─ @opentelemetry/semantic-conventions ^1.29.0 → 1.40.0
  ├─ @types/node >=13.7.0 → 25.6.0
  ├─ agent-base ^7.1.2 → 7.1.4
  ├─ data-uri-to-buffer ^4.0.0 → 4.0.1
  ├─ debug 4 → 4.4.3
  ├─ fetch-blob ^3.1.4 → 3.2.0
  ├─ formdata-polyfill ^4.0.10 → 4.0.10
  ├─ lodash.camelcase ^4.3.0 → 4.3.0
  ├─ long ^5.0.0 → 5.3.2
  ├─ ms ^2.1.3 → 2.1.3
  ├─ pg-int8 1.0.1
  ├─ postgres-array ~2.0.0
  ├─ postgres-bytea ~1.0.0
  ├─ postgres-date ~1.0.4
  ├─ postgres-interval ^1.1.0
  ├─ protobufjs ^8.0.1 → 8.0.3
  ├─ protobufjs ^7.5.3 → 7.5.6
  ├─ undici-types ~7.19.0 → 7.19.2
├─ yargs ^17.7.2 → 17.7.2
  ├─ @opentelemetry/api ^1.3.0 → 1.9.1
  ├─ @opentelemetry/api-logs 0.215.0 → 0.215.0
  ├─ @opentelemetry/core 2.7.0 → 2.7.0
  ├─ @opentelemetry/resources 2.7.0 → 2.7.0
  ├─ @opentelemetry/sdk-logs 0.215.0 → 0.215.0
  ├─ @opentelemetry/sdk-metrics 2.7.0 → 2.7.0
  ├─ @opentelemetry/sdk-trace-base 2.7.0 → 2.7.0
  ├─ @opentelemetry/semantic-conventions ^1.29.0 → 1.40.0
  ├─ @protobufjs/aspromise ^1.1.2 → 1.1.2
  ├─ @protobufjs/base64 ^1.1.2 → 1.1.2
  ├─ @protobufjs/codegen ^2.0.5 → 2.0.5
  ├─ @protobufjs/eventemitter ^1.1.0 → 1.1.0
  ├─ @protobufjs/fetch ^1.1.0 → 1.1.0
  ├─ @protobufjs/float ^1.0.2 → 1.0.2
  ├─ @protobufjs/inquire ^1.1.1 → 1.1.1
  ├─ @protobufjs/path ^1.1.2 → 1.1.2
  ├─ @protobufjs/pool ^1.1.0 → 1.1.0
  ├─ @protobufjs/utf8 ^1.1.1 → 1.1.1
  ├─ @types/node >=13.7.0 → 25.6.0
  ├─ cliui ^8.0.1 → 8.0.1
  ├─ escalade ^3.1.1 → 3.2.0
  ├─ fetch-blob ^3.1.2 → 3.2.0
  ├─ get-caller-file ^2.0.5 → 2.0.5
  ├─ lodash.camelcase ^4.3.0 → 4.3.0
  ├─ long ^5.0.0 → 5.3.2
  ├─ ms ^2.1.3 → 2.1.3
  ├─ node-domexception ^1.0.0 → 1.0.0
  ├─ protobufjs ^7.5.3 → 7.5.6
  ├─ protobufjs ^8.0.1 → 8.0.3
  ├─ require-directory ^2.1.1 → 2.1.1
  ├─ string-width ^4.2.3 → 4.2.3
  ├─ undici-types ~7.19.0 → 7.19.2
  ├─ web-streams-polyfill ^3.0.3 → 3.3.3
  ├─ y18n ^5.0.5 → 5.0.8
  ├─ yargs ^17.7.2 → 17.7.2
├─ yargs-parser ^21.1.1 → 21.1.1
  ├─ @opentelemetry/api ^1.3.0 → 1.9.1
  ├─ @opentelemetry/api-logs 0.215.0 → 0.215.0
  ├─ @opentelemetry/core 2.7.0 → 2.7.0
  ├─ @opentelemetry/resources 2.7.0 → 2.7.0
  ├─ @opentelemetry/semantic-conventions ^1.29.0 → 1.40.0
  ├─ @protobufjs/aspromise ^1.1.1 → 1.1.2
  ├─ @protobufjs/aspromise ^1.1.2 → 1.1.2
  ├─ @protobufjs/base64 ^1.1.2 → 1.1.2
  ├─ @protobufjs/codegen ^2.0.5 → 2.0.5
  ├─ @protobufjs/eventemitter ^1.1.0 → 1.1.0
  ├─ @protobufjs/fetch ^1.1.0 → 1.1.0
  ├─ @protobufjs/float ^1.0.2 → 1.0.2
  ├─ @protobufjs/inquire ^1.1.1 → 1.1.1
  ├─ @protobufjs/inquire ^1.1.0 → 1.1.1
  ├─ @protobufjs/path ^1.1.2 → 1.1.2
  ├─ @protobufjs/pool ^1.1.0 → 1.1.0
  ├─ @protobufjs/utf8 ^1.1.1 → 1.1.1
  ├─ @types/node >=13.7.0 → 25.6.0
  ├─ cliui ^8.0.1 → 8.0.1
  ├─ emoji-regex ^8.0.0
  ├─ escalade ^3.1.1 → 3.2.0
  ├─ get-caller-file ^2.0.5 → 2.0.5
  ├─ is-fullwidth-code-point ^3.0.0
  ├─ long ^5.0.0 → 5.3.2
  ├─ node-domexception ^1.0.0 → 1.0.0
  ├─ require-directory ^2.1.1 → 2.1.1
  ├─ string-width ^4.2.3 → 4.2.3
  ├─ string-width ^4.2.0 → 4.2.3
  ├─ strip-ansi ^6.0.1 → 6.0.1
  ├─ undici-types ~7.19.0 → 7.19.2
  ├─ web-streams-polyfill ^3.0.3 → 3.3.3
  ├─ wrap-ansi ^7.0.0 → 7.0.0
  ├─ y18n ^5.0.5 → 5.0.8
├─ yargs-parser ^21.1.1 → 21.1.1
  ├─ @opentelemetry/api ^1.3.0 → 1.9.1
  ├─ @opentelemetry/core 2.7.0 → 2.7.0
  ├─ @opentelemetry/semantic-conventions ^1.29.0 → 1.40.0
  ├─ @protobufjs/aspromise ^1.1.1 → 1.1.2
  ├─ @protobufjs/inquire ^1.1.0 → 1.1.1
  ├─ ansi-regex ^5.0.1 → 5.0.1
  ├─ ansi-styles ^4.0.0 → 4.3.0
  ├─ emoji-regex ^8.0.0
  ├─ is-fullwidth-code-point ^3.0.0
  ├─ string-width ^4.2.0 → 4.2.3
  ├─ string-width ^4.1.0 → 4.2.3
  ├─ strip-ansi ^6.0.0 → 6.0.1
  ├─ strip-ansi ^6.0.1 → 6.0.1
  ├─ undici-types ~7.19.0 → 7.19.2
├─ wrap-ansi ^7.0.0 → 7.0.0
  ├─ @opentelemetry/semantic-conventions ^1.29.0 → 1.40.0
  ├─ ansi-regex ^5.0.1 → 5.0.1
  ├─ ansi-styles ^4.0.0 → 4.3.0
  ├─ color-convert ^2.0.1
  ├─ emoji-regex ^8.0.0
  ├─ is-fullwidth-code-point ^3.0.0
  ├─ string-width ^4.1.0 → 4.2.3
  ├─ strip-ansi ^6.0.0 → 6.0.1
  ├─ strip-ansi ^6.0.1 → 6.0.1

Changes from v4.2.4

Dependency Changes

ChangePackageVersion
added chalk ^4.1.2
added strip-ansi ^5.2.0

Script Changes

- test:integration

File Changes

48 added 176 removed 325 modified size delta: -484.3 KB

Risk Dispositions (2 applicable to this version, 0 other)

Accepted rules are downgraded to INFO on future analyses; rejected rules escalate to CRITICAL.

Rule Source Disposition Author Reason
regressed-provenance provenance reject AI AI (provenance): inngest has consistently published with CI/CD provenance attestations; any version lacking attestation is a strong compromise signal for this package.
publisher-changed provenance reject AI AI (provenance): inngest is published via GitHub Actions; a human npm account (linell_inngest, first seen 10 days ago) publishing this package is a strong account-compromise indicator.

SAST Findings (2)

HIGH Provenance attestation missing — previous versions had it provenance

This version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. The axios attack (March 2026) exhibited exactly this pattern.

HIGH Publisher changed: GitHub Actions → linell_inngest (on 2026-04-20) provenance

This version was published by a different npm account than previous versions on 2026-04-20. This could indicate a legitimate maintainer transition or an account compromise.

Review Summary

Risk score: 90. Findings: 2 high (+50), 4 medium (+40), 14 info (+0).

Commit: 1a5b63a89bed Browse source

Published to npm: