posthog-js
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:query-selector-shadow-dom | AI (phantom-deps): Used in bundled dist output, not scannable as source import. | ai | |
| vendored-integrity | tampered-vendored-dep:. | AI (vendored-integrity): Diffs are rebuilt dist/sourcemap files from normal version bump, not authorship tampering. | ai | |
| phantom-deps | phantom-dep:core-js | AI (phantom-deps): Known implicit runtime dependency. | ai | |
| phantom-deps | phantom-dep:dompurify | AI (phantom-deps): Used in bundled dist output, not scannable as source import. | ai | |
| phantom-deps | phantom-dep:web-vitals | AI (phantom-deps): Used in bundled dist output, not scannable as source import. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Official 8.9M-download PostHog lib with doc-only README; low-value signals are stable false positives. | ai | |
| dependencies | unvetted-dep:@posthog/browser-common | AI (dependencies): First-party PostHog scoped package, same publisher/org as posthog-js. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Established high-trust package with CI/CD provenance; no compromise indicators. | ai | |
| phantom-deps | phantom-dep:fflate | AI (phantom-deps): Used via build/config, stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:rrweb-snapshot | AI (phantom-deps): Used via build/config, stable false positive for this package. | ai | |
| source-diff | obfuscated-file:dist/customizations.js | AI (source-diff): Minified rollup/terser build output for official posthog-js; recurs every release. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Reflect.get() used in Proxy trap handlers for rrweb session recording — standard pattern, not obfuscation. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/api | AI (phantom-deps): Peer/transitive dep used by other @opentelemetry packages in the bundle. | ai | |
| source-diff | obfuscated-file:dist/rrweb-plugin-console-record.js | AI (source-diff): Minified dist bundle of rrweb console-record plugin; standard for this package. | ai | |
| source-diff | obfuscated-file:dist/rrweb.js | AI (source-diff): Minified dist bundle of rrweb session recording lib; standard for this package. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): posthog-js publishes ~every 2 days (1135 versions over 2257 days). Dormancy is relative to last approved version in this pipeline, not actual package inactivity. | ai | |
| source-diff | obfuscated-file:dist/product-tours-preview.js | AI (source-diff): Standard minified Preact component code for product tours feature. Recognizable VDOM patterns, no malicious indicators. | ai | |
| source-diff | obfuscated-file:dist/logs.js | AI (source-diff): Standard minified OpenTelemetry SDK logging code. Recognizable OTEL patterns, no malicious indicators. | ai | |
| source-diff | obfuscated-file:lib/src/extensions/surveys/icons.js | AI (source-diff): Minified SVG icon definitions using Preact JSX runtime. Clearly benign build output. | ai | |
| source-diff | obfuscated-file:dist/element-inference.js | AI (source-diff): Standard minified CSS selector utility code. Recognizable parsing patterns, no malicious indicators. | ai | |
| source-diff | obfuscated-file:dist/conversations.js | AI (source-diff): Standard minified Preact/JS build artifact for posthog-js dist/ folder. Code patterns are recognizable framework code, not obfuscated malware. | ai | |
| provenance | publisher-changed | AI (provenance): posthog-js publishes via GitHub Actions CI/CD with SLSA provenance attestation. The move from personal account to automated CI is a security improvement, not a risk signal. | ai | |
| source-diff | obfuscated-file:dist/product-tours.js | AI (source-diff): Standard minified Preact component code for product tours feature. Recognizable VDOM patterns, no malicious indicators. | ai | |
| source-diff | encoded-string-file:dist/module.full.no-external.js | AI (source-diff): Minified session-recording bundle; long strings are embedded assets. Same pattern already accepted in sibling dist files. | ai | |
| source-diff | encoded-string-file:dist/lazy-recorder.js | AI (source-diff): Minified session-recording bundle; long strings are embedded assets (CSS/SVG). Same pattern already accepted in sibling dist files. No malicious indicators. | ai | |
| source-diff | encoded-string-file:dist/module.full.js | AI (source-diff): Minified session-recording bundle; long strings are embedded assets. Same pattern already accepted in sibling dist files. | ai | |
| source-diff | encoded-string-file:dist/recorder-v2.js | AI (source-diff): Minified session-recording bundle; long strings are embedded assets. Same pattern already accepted in sibling dist files. | ai | |
| source-diff | encoded-string-file:dist/recorder.js | AI (source-diff): Minified session-recording bundle; long strings are embedded assets. Same pattern already accepted in sibling dist files. | ai | |
| source-diff | obfuscated-file:dist/default-extensions.js | AI (source-diff): posthog-js ships minified browser bundles as part of its normal distribution; these are standard build artifacts, not obfuscated malware. | ai | |
| source-diff | large-new-source-files | AI (source-diff): posthog-js regularly adds new bundle variants; 49 new files reflects new extension/slim module additions, not injected code. | ai | |
| source-diff | encoded-string-file:dist/array.full.no-external.js | AI (source-diff): Long strings in minified bundles are standard minification artifacts (rrweb DOM recording code), not encoded malicious payloads. | ai | |
| source-diff | encoded-string-file:dist/array.full.js | AI (source-diff): Long strings in minified bundles are standard minification artifacts (rrweb DOM recording code), not encoded malicious payloads. | ai | |
| source-diff | encoded-string-file:dist/all-external-dependencies.js | AI (source-diff): Long strings in minified bundles are standard minification artifacts (rrweb DOM recording code), not encoded malicious payloads. | ai | |
| source-diff | obfuscated-file:dist/module.slim.no-external.js | AI (source-diff): posthog-js ships minified browser bundles as part of its normal distribution; these are standard build artifacts, not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/module.slim.js | AI (source-diff): posthog-js ships minified browser bundles as part of its normal distribution; these are standard build artifacts, not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/extension-bundles.js | AI (source-diff): posthog-js ships minified browser bundles as part of its normal distribution; these are standard build artifacts, not obfuscated malware. | ai |
Versions (showing 100 of 1033)
| Version | Deps | Published |
|---|---|---|
| 1.407.3 | 9 / 66 | |
| 1.407.2 | 9 / 66 | |
| 1.407.1 | 9 / 66 | |
| 1.407.0 | 9 / 66 | |
| 1.406.2 | 9 / 66 | |
| 1.406.1 | 9 / 66 | |
| 1.406.0 | 9 / 66 | |
| 1.405.3 | 8 / 66 | |
| 1.405.2 | 8 / 66 | |
| 1.405.1 | 8 / 66 | |
| 1.405.0 | 8 / 66 | |
| 1.404.1 | 8 / 66 | |
| 1.404.0 | 8 / 66 | |
| 1.403.0 | 8 / 66 | |
| 1.402.3 | 8 / 66 | |
| 1.402.2 | 8 / 66 | |
| 1.402.1 | 8 / 66 | |
| 1.402.0 | 8 / 66 | |
| 1.401.0 | 8 / 66 | |
| 1.400.1 | 8 / 66 | |
| 1.400.0 | 8 / 66 | |
| 1.399.5 | 8 / 66 | |
| 1.399.4 | 8 / 66 | |
| 1.399.3 | 8 / 66 | |
| 1.399.2 | 8 / 66 | |
| 1.399.1 | 8 / 66 | |
| 1.399.0 | 8 / 66 | |
| 1.398.7 | 8 / 66 | |
| 1.398.6 | 8 / 66 | |
| 1.398.5 | 8 / 66 | |
| 1.398.4 | 8 / 66 | |
| 1.398.3 | 8 / 66 | |
| 1.398.2 | 8 / 66 | |
| 1.398.1 | 8 / 66 | |
| 1.398.0 | 8 / 66 | |
| 1.397.0 | 8 / 66 | |
| 1.396.9 | 8 / 66 | |
| 1.396.8 | 8 / 66 | |
| 1.396.7 | 8 / 66 | |
| 1.396.6 | 8 / 66 | |
| 1.396.5 | 8 / 66 | |
| 1.396.4 | 8 / 66 | |
| 1.396.3 | 8 / 66 | |
| 1.396.2 | 8 / 66 | |
| 1.396.1 | 8 / 66 | |
| 1.396.0 | 8 / 66 | |
| 1.395.0 | 8 / 66 | |
| 1.394.0 | 8 / 66 | |
| 1.393.6 | 8 / 66 | |
| 1.393.5 | 8 / 66 | |
| 1.393.4 | 8 / 66 | |
| 1.393.3 | 8 / 66 | |
| 1.393.2 | 8 / 66 | |
| 1.393.1 | 8 / 66 | |
| 1.393.0 | 8 / 66 | |
| 1.392.0 | 8 / 66 | |
| 1.391.9 | 8 / 71 | |
| 1.391.8 | 8 / 71 | |
| 1.391.7 | 8 / 71 | |
| 1.391.6 | 8 / 71 | |
| 1.391.5 | 8 / 71 | |
| 1.391.4 | 8 / 71 | |
| 1.391.3 | 8 / 71 | |
| 1.391.2 | 8 / 71 | |
| 1.391.1 | 8 / 71 | |
| 1.391.0 | 8 / 71 | |
| 1.390.2 | 8 / 71 | |
| 1.390.1 | 8 / 71 | |
| 1.390.0 | 8 / 71 | |
| 1.389.1 | 8 / 71 | |
| 1.389.0 | 8 / 71 | |
| 1.388.2 | 8 / 71 | |
| 1.388.1 | 8 / 71 | |
| 1.388.0 | 8 / 71 | |
| 1.387.0 | 8 / 71 | |
| 1.386.8 | 8 / 71 | |
| 1.386.7 | 8 / 71 | |
| 1.386.6 | 8 / 71 | |
| 1.386.5 | 8 / 71 | |
| 1.386.4 | 8 / 71 | |
| 1.386.3 | 8 / 71 | |
| 1.386.2 | 8 / 71 | |
| 1.386.1 | 8 / 71 | |
| 1.386.0 | 8 / 71 | |
| 1.385.0 | 8 / 71 | |
| 1.384.3 | 8 / 71 | |
| 1.384.2 | 8 / 71 | |
| 1.384.1 | 8 / 71 | |
| 1.384.0 | 8 / 71 | |
| 1.383.3 | 8 / 71 | |
| 1.383.2 | 8 / 71 | |
| 1.383.1 | 8 / 71 | |
| 1.383.0 | 8 / 71 | |
| 1.382.0 | 8 / 71 | |
| 1.381.0 | 8 / 71 | |
| 1.380.1 | 8 / 71 | |
| 1.380.0 | 8 / 71 | |
| 1.379.3 | 8 / 71 | |
| 1.379.2 | 8 / 71 | |
| 1.379.1 | 8 / 71 |
v1.407.3
2 findingsThe directory `.` byte-matched 616 of 716 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 100 file(s) inside it differ from that package's bytes at the same path: dist/all-external-dependencies.js, dist/all-external-dependencies.js.map, dist/array.full.es5.js, dist/array.full.es5.js.map, dist/array.full.js, dist/array.full.js.map, dist/array.full.no-external.js, dist/array.full.no-external.js.map, dist/array.js, dist/array.js.map, dist/array.no-external.js, dist/array.no-external.js.map, dist/conversations.js, dist/customizations.d.ts, dist/customizations.full.js, dist/customizations.full.js.map, dist/customizations.js, dist/customizations.js.map, dist/default-extensions.js, dist/default-extensions.js.map (+80 more). A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.407.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.407.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.407.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.406.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.406.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.406.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.405.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.405.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.405.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.405.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.404.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.404.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.403.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.402.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.402.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.402.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.402.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.401.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.400.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.400.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.399.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.399.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.399.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.399.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.399.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.399.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.398.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.398.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.398.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.398.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.398.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.398.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.398.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.398.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.397.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.396.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.396.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.396.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.396.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.396.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.396.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.396.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.396.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.396.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.396.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.