← Home

n8n-core

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

jan_n8n_ion8n-matsuuucornelius_n8n_iotomin8n

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern new-deps-added AI (publish-pattern): New deps are well-known (@azure, @sentry, @n8n/*), consistent with active n8n development. ai
phantom-deps phantom-dep:qs AI (phantom-deps): Monorepo build artifact; qs likely used indirectly, no malicious behavior found. ai
phantom-deps phantom-dep:form-data AI (phantom-deps): form-data is a declared dependency used indirectly; stable false positive for this package. ai
provenance publisher-changed AI (provenance): tomin8n is an established n8n org publisher with 180 approved packages; transition from jan_n8n_io is a documented org account change. ai
maintainer-change maintainer-added AI (maintainer-change): Same org transition; tomin8n has strong track record across n8n packages. ai
publish-pattern dormant-publish AI (publish-pattern): Dormancy reflects the publisher account change, not actual project inactivity; n8n-core is actively maintained. ai
phantom-deps phantom-dep:xml2js AI (phantom-deps): Declared in package.json deps; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:callsites AI (phantom-deps): Declared in package.json deps; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:winston AI (phantom-deps): Declared in package.json deps; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:picocolors AI (phantom-deps): Declared in package.json deps; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:htmlparser2 AI (phantom-deps): Declared in package.json deps; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:@n8n/workflow-sdk AI (phantom-deps): Declared in package.json deps; phantom-dep heuristic false positive for this package. ai

Versions (showing 51 of 173)

View all versions
Version Deps Published
2.32.2 41 / 22
2.32.1 41 / 22
2.32.0 41 / 22
2.31.3 41 / 22
2.31.2 41 / 22
2.31.1 41 / 22
2.31.0 41 / 22
2.30.4 41 / 21
2.30.3 41 / 21
2.30.2 41 / 21
2.30.1 41 / 21
2.30.0 41 / 21
2.29.8 40 / 21
2.29.7 40 / 21
2.29.6 40 / 21
2.29.5 40 / 21
2.29.4 40 / 21
2.29.3 41 / 20
2.29.2 41 / 20
2.29.1 41 / 20
2.29.0 41 / 20
2.28.5 39 / 17
2.28.4 40 / 16
2.28.3 40 / 16
2.28.2 40 / 16
2.28.1 40 / 16
2.28.0 40 / 16
2.27.4 35 / 15
2.27.3 35 / 15
2.27.2 35 / 15
2.27.1 35 / 15
2.27.0 35 / 15
2.26.4 40 / 16
2.26.3 40 / 16
2.26.2 40 / 16
2.26.1 40 / 16
2.26.0 40 / 16
2.25.2 39 / 16
2.25.1 39 / 16
2.25.0 39 / 16
2.24.0 39 / 16
2.23.1 39 / 10
2.23.0 39 / 10
2.22.4 39 / 10
2.22.3 39 / 10
2.22.2 39 / 10
2.22.1 39 / 10
2.22.0 39 / 10
2.21.5 39 / 10
2.21.4 39 / 10
2.21.3 39 / 10

v2.32.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.32.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.32.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.31.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.31.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.31.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.31.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.30.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.30.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.30.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.30.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.30.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.29.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.29.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.29.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.29.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.29.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.29.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.29.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.29.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.29.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.28.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.28.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.28.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.28.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.27.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.