n8n-nodes-base
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@n8n/vm2 | AI (dependencies): n8n's own maintained vm2 fork, published under the @n8n scope. | ai | |
| phantom-deps | phantom-dep:@smithy/protocol-http | AI (phantom-deps): Framework-scoped AWS SDK package; loaded by convention in AWS credential/HTTP handler chain. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/credential-providers | AI (phantom-deps): Framework-scoped AWS SDK package; loaded by convention in AWS credential/HTTP handler chain. | ai | |
| phantom-deps | phantom-dep:@smithy/node-http-handler | AI (phantom-deps): Framework-scoped AWS SDK package; loaded by convention in AWS credential/HTTP handler chain. | ai | |
| phantom-deps | phantom-dep:@smithy/signature-v4 | AI (phantom-deps): Framework-scoped AWS SDK package; loaded by convention in AWS credential/HTTP handler chain. | ai | |
| phantom-deps | phantom-dep:@smithy/types | AI (phantom-deps): Framework-scoped AWS SDK package; loaded by convention in AWS credential/HTTP handler chain. | ai | |
| phantom-deps | phantom-dep:undici | AI (phantom-deps): Implicit runtime dependency; stable pattern for this node-definitions package. | ai | |
| phantom-deps | phantom-dep:@aws-crypto/sha256-js | AI (phantom-deps): Used by AWS-integration node files loaded dynamically, not top-level; expected for this monorepo. | ai | |
| phantom-deps | phantom-dep:@n8n/errors | AI (phantom-deps): Internal n8n package loaded dynamically; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@kafkajs/confluent-schema-registry | AI (phantom-deps): Kafka node loads this at runtime; stable false positive. | ai | |
| phantom-deps | phantom-dep:json-schema | AI (phantom-deps): Runtime-loaded optional dep; stable false positive for this package's dynamic architecture. | ai | |
| phantom-deps | phantom-dep:@n8n/backend-network | AI (phantom-deps): Internal n8n package loaded dynamically; stable false positive. | ai | |
| phantom-deps | phantom-dep:mqtt-packet | AI (phantom-deps): MQTT node loads this at runtime; stable false positive. | ai | |
| phantom-deps | phantom-dep:axios | AI (phantom-deps): n8n-nodes-base uses dynamic require for optional integrations; axios is loaded at runtime by HTTP nodes. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): n8n uses automated CI/CD releases; rapid successive publishes are expected and attested via SLSA provenance. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): n8n org maintainers added via CI pipeline with SLSA provenance; consistent with org growth pattern. | ai | |
| phantom-deps | phantom-dep:proxy-from-env | AI (phantom-deps): proxy-from-env is a standard axios companion for proxy resolution; declared alongside axios addition, not a suspicious phantom dep. | ai | |
| source-diff | obfuscated-file:dist/nodes/Microsoft/Entra/test/mocks.js | AI (source-diff): File contains plain-text mock API response fixtures with long lines, not obfuscated/minified code. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Large monorepo node package; file count growth reflects legitimate new node definitions across major version bump. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): n8n-nodes-base regularly adds new deps with each release; isolated-vm and @thednp/dommatrix are legitimate libraries. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): n8n-nodes-base is continuously published; dormancy flag is an artifact of comparing against a stale approved baseline. | ai | |
| dependencies | unvetted-dep:minifaker | AI (dependencies): Fake data generator used in n8n nodes; stable for this package. | ai | |
| npm-metadata | url-dep:xlsx | AI (npm-metadata): SheetJS distributes via their CDN after npm removal; stable pattern for this package. | ai | |
| dependencies | unvetted-dep:xlsx | AI (dependencies): Known SheetJS library distributed via CDN; stable for n8n-nodes-base. | ai | |
| dependencies | unvetted-dep:js-nacl | AI (dependencies): Established NaCl crypto binding; stable dependency for this package. | ai | |
| dependencies | unvetted-dep:rfc2047 | AI (dependencies): Email header encoding library; stable utility dep for n8n-nodes-base. | ai | |
| dependencies | unvetted-dep:promise-ftp | AI (dependencies): FTP client library for n8n FTP node; stable for this package. | ai | |
| dependencies | unvetted-dep:generate-schema | AI (dependencies): Schema generation utility; stable dep for n8n-nodes-base. | ai | |
| phantom-deps | phantom-dep:pg | AI (phantom-deps): n8n-nodes-base dynamically loads optional integrations; static import analysis produces false positives for this package. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/client-sso-oidc | AI (phantom-deps): Same dynamic-load architecture; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@mozilla/readability | AI (phantom-deps): Same dynamic-load architecture; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:xmlhttprequest-ssl | AI (phantom-deps): Same dynamic-load architecture; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:snowflake-sdk | AI (phantom-deps): Same dynamic-load architecture; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:sanitize-html | AI (phantom-deps): Same dynamic-load architecture; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:html-to-text | AI (phantom-deps): Same dynamic-load architecture; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:isolated-vm | AI (phantom-deps): Same dynamic-load architecture; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:eventsource | AI (phantom-deps): Same dynamic-load architecture; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:rss-parser | AI (phantom-deps): Same dynamic-load architecture; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:basic-auth | AI (phantom-deps): Same dynamic-load architecture; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:fast-glob | AI (phantom-deps): Same dynamic-load architecture; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:node-ssh | AI (phantom-deps): Same dynamic-load architecture; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:otpauth | AI (phantom-deps): Same dynamic-load architecture; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:semver | AI (phantom-deps): Same dynamic-load architecture; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:alasql | AI (phantom-deps): Same dynamic-load architecture; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:redis | AI (phantom-deps): Same dynamic-load architecture; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:jsdom | AI (phantom-deps): Same dynamic-load architecture; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:isbot | AI (phantom-deps): Same dynamic-load architecture; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:cron | AI (phantom-deps): Same dynamic-load architecture; stable false positive for this package. | ai |
Versions (showing 58 of 58)
| Version | Deps | Published |
|---|---|---|
| 2.31.1 | 91 / 42 | |
| 2.30.4 | 91 / 41 | |
| 2.30.1 | 91 / 41 | |
| 2.30.0 | 91 / 41 | |
| 2.29.2 | 86 / 41 | |
| 2.28.4 | 78 / 34 | |
| 2.26.2 | 78 / 33 | |
| 2.25.1 | 76 / 33 | |
| 2.24.0 | 76 / 33 | |
| 2.22.3 | 75 / 32 | |
| 2.22.2 | 75 / 32 | |
| 2.22.0 | 75 / 32 | |
| 2.20.7 | 75 / 32 | |
| 2.15.1 | 75 / 32 | |
| 2.8.1 | 74 / 32 | |
| 2.8.0 | 74 / 32 | |
| 2.7.2 | 74 / 32 | |
| 2.7.1 | 74 / 32 | |
| 2.7.0 | 74 / 32 | |
| 2.6.2 | 74 / 29 | |
| 2.6.1 | 74 / 29 | |
| 2.6.0 | 74 / 29 | |
| 2.5.2 | 74 / 28 | |
| 2.5.1 | 74 / 28 | |
| 2.5.0 | 74 / 28 | |
| 2.4.4 | 74 / 28 | |
| 2.1.4 | 74 / 28 | |
| 1.121.41 | 74 / 28 | |
| 1.121.40 | 74 / 28 | |
| 1.121.39 | 74 / 28 | |
| 1.121.38 | 74 / 28 | |
| 1.121.37 | 74 / 28 | |
| 1.121.36 | 74 / 28 | |
| 1.121.35 | 74 / 28 | |
| 1.121.34 | 74 / 28 | |
| 1.121.33 | 74 / 28 | |
| 1.121.32 | 74 / 28 | |
| 1.121.31 | 74 / 28 | |
| 1.121.30 | 74 / 28 | |
| 1.121.29 | 74 / 28 | |
| 1.121.28 | 74 / 28 | |
| 1.121.27 | 74 / 28 | |
| 1.121.26 | 74 / 28 | |
| 1.121.25 | 74 / 28 | |
| 1.121.24 | 74 / 28 | |
| 1.121.23 | 74 / 28 | |
| 1.121.22 | 74 / 28 | |
| 1.121.21 | 74 / 28 | |
| 1.121.20 | 74 / 28 | |
| 1.121.19 | 74 / 28 | |
| 1.121.18 | 74 / 28 | |
| 1.121.17 | 74 / 28 | |
| 1.121.16 | 74 / 28 | |
| 1.121.15 | 74 / 28 | |
| 1.121.14 | 74 / 28 | |
| 1.121.13 | 74 / 28 | |
| 1.121.12 | 74 / 28 | |
| 1.121.11 | 74 / 28 |
v2.31.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.30.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.30.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.30.0
2 findingsDeclared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.29.2
7 findingsDeclared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).
Declared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).
Declared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).
Declared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).
Declared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).
Declared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.28.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.8.1
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (tomin8n) on 2026-02-13, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v2.8.0
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (tomin8n) on 2026-02-11, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v2.7.2
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (tomin8n) than the most recent previously approved version (GitHub Actions) on 2026-02-13, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v2.7.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.7.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.6.2
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (tomin8n) than the most recent previously approved version (jan_n8n_io) on 2026-02-06, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v2.6.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.6.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.5.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.5.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.5.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.4.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.121.41
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.121.40
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.121.39
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.121.19
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.121.18
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.121.17
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.121.16
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.121.15
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.121.14
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (tomin8n) than the most recent previously approved version (GitHub Actions) on 2026-02-20, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v1.121.13
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (tomin8n) than the most recent previously approved version (jan_n8n_io) on 2026-02-06, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v1.121.12
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.121.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.