← Home

n8n-workflow

51
Versions
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures No source commit

Maintainers

jan_n8n_ion8n-matsuuucornelius_n8n_iotomin8n

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@sentry/core AI (phantom-deps): Sentry SDK likely used via re-export/build tooling; not malicious. ai
publish-pattern new-deps-added AI (publish-pattern): All new deps are well-known/first-party packages, normal for this monorepo release. ai
provenance publisher-changed AI (provenance): tomin8n is an n8n org member with 107 approved packages; legitimate maintainer rotation. ai
maintainer-change maintainer-added AI (maintainer-change): tomin8n is an established n8n org publisher; stable for this package. ai
license uncommon-license:SEE LICENSE IN LICENSE.md AI (license): n8n uses a custom license file; stable across all versions of this package. ai
dependencies unvetted-dep:@n8n/errors AI (dependencies): First-party n8n scoped package; stable dependency pattern for this monorepo. ai
dependencies unvetted-dep:@n8n/expression-runtime AI (dependencies): First-party n8n scoped package; stable dependency pattern for this monorepo. ai
dependencies unvetted-dep:@n8n/tournament AI (dependencies): First-party n8n scoped package; stable dependency pattern for this monorepo. ai
dependencies unvetted-dep:transliteration AI (dependencies): Well-known utility library; no known advisories, consistent with n8n's text-processing needs. ai
phantom-deps phantom-dep:ast-types AI (phantom-deps): ast-types is a transitive dep of recast (listed in dependencies); phantom detection is a false positive here. ai

Versions (showing 51 of 119)

View all versions
Version Deps Published
2.33.0 26 / 22
2.32.1 26 / 22
2.32.0 26 / 22
2.31.3 26 / 21
2.31.2 26 / 21
2.31.1 26 / 21
2.31.0 26 / 21
2.30.2 26 / 20
2.30.1 26 / 20
2.30.0 26 / 20
2.29.3 25 / 20
2.29.2 25 / 20
2.29.1 26 / 20
2.29.0 26 / 20
2.28.4 19 / 17
2.28.3 20 / 17
2.28.2 20 / 17
2.28.1 20 / 17
2.28.0 20 / 17
2.27.2 19 / 17
2.27.1 19 / 17
2.27.0 19 / 17
2.26.3 19 / 17
2.26.2 19 / 17
2.26.1 19 / 17
2.26.0 19 / 17
2.25.2 19 / 16
2.25.1 19 / 16
2.25.0 19 / 16
2.24.0 19 / 16
2.23.0 19 / 13
2.22.3 19 / 13
2.22.2 19 / 13
2.22.1 19 / 13
2.22.0 19 / 13
2.21.2 19 / 13
2.21.1 19 / 13
2.21.0 19 / 13
2.20.3 19 / 13
2.20.2 19 / 13
2.20.1 19 / 13
2.20.0 19 / 13
2.19.0 19 / 13
2.18.3 19 / 13
2.18.2 19 / 13
2.18.1 19 / 13
2.18.0 19 / 13
2.17.2 20 / 12
2.17.1 20 / 12
2.17.0 20 / 12
2.16.0 20 / 12

v2.33.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.32.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.32.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.31.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.31.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.31.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.31.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.30.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.30.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.30.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.29.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.29.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.29.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.29.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.28.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.28.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.28.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.