← Home

@opentelemetry/exporter-metrics-otlp-grpc

OpenTelemetry Collector Metrics Exporter allows user to send collected metrics to the OpenTelemetry Collector

51
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

dyladanpichlermarcoverbalancenpmjs-accounttrentmmartinkuba

Keywords

opentelemetrynodejsgrpctracingprofilingmetricsstats

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@opentelemetry/sdk-metrics-base AI (dependencies): Same-org sibling package from the official opentelemetry-js monorepo; no real risk, expected dependency for this metrics exporter. ai
provenance no-provenance AI (provenance): This is a 2021-era release from the official OpenTelemetry JS monorepo; Sigstore provenance was not standard practice at this version's publish time. ai
phantom-deps phantom-dep:@grpc/proto-loader AI (phantom-deps): @grpc/proto-loader is a declared runtime dependency used for proto loading configuration; the phantom-dep finding reflects indirect usage patterns typical for this package. ai
dependencies unvetted-dep:@opentelemetry/otlp-grpc-exporter-base AI (dependencies): Internal @opentelemetry org dependency; same project ecosystem. ai
dependencies unvetted-dep:@opentelemetry/exporter-metrics-otlp-http AI (dependencies): Internal @opentelemetry org dependency; same project ecosystem. ai
dependencies unvetted-dep:@opentelemetry/core AI (dependencies): Internal @opentelemetry org dependency; same project ecosystem. ai
dependencies unvetted-dep:@opentelemetry/resources AI (dependencies): Internal @opentelemetry org dependency; same project ecosystem. ai
dependencies unvetted-dep:@opentelemetry/sdk-metrics AI (dependencies): Internal @opentelemetry org dependency; same project ecosystem. ai
dependencies unvetted-dep:@opentelemetry/otlp-transformer AI (dependencies): Internal @opentelemetry org dependency; same project ecosystem. ai
dependencies unvetted-dep:@opentelemetry/otlp-exporter-base AI (dependencies): Internal @opentelemetry org dependency; same project ecosystem. ai
provenance publisher-changed AI (provenance): Transition from individual maintainer to GitHub Actions CI/CD with SLSA provenance attestation is a security improvement for this established OpenTelemetry monorepo package. Generalizes to future versions. ai
phantom-deps phantom-dep:@opentelemetry/otlp-exporter-base AI (phantom-deps): Internal org dependency; phantom dep pattern is expected for @opentelemetry packages. ai
phantom-deps phantom-dep:@grpc/grpc-js AI (phantom-deps): gRPC exporter legitimately uses gRPC; phantom dep is expected for this package type. ai
phantom-deps phantom-dep:@opentelemetry/resources AI (phantom-deps): Internal org dependency; phantom dep pattern is expected for @opentelemetry packages. ai
phantom-deps phantom-dep:@opentelemetry/sdk-metrics AI (phantom-deps): Internal org dependency; phantom dep pattern is expected for @opentelemetry packages. ai
phantom-deps phantom-dep:@opentelemetry/core AI (phantom-deps): Internal org dependency; phantom dep pattern is expected for @opentelemetry packages. ai

Versions (showing 51 of 66)

View all versions
Version Deps Published
0.218.0 8 / 10
0.217.0 8 / 10
0.216.0 8 / 10
0.215.0 8 / 10
0.214.0 8 / 10
0.213.0 8 / 10
0.212.0 8 / 10
0.211.0 8 / 10
0.210.0 8 / 10
0.209.0 8 / 10
0.208.0 8 / 10
0.207.0 8 / 10
0.206.0 8 / 10
0.205.0 8 / 11
0.204.0 8 / 11
0.203.0 8 / 12
0.202.0 8 / 12
0.201.1 8 / 12
0.201.0 8 / 12
0.200.0 8 / 12
0.57.2 8 / 12
0.57.1 8 / 12
0.57.0 8 / 12
0.56.0 8 / 12
0.55.0 8 / 12
0.54.2 8 / 12
0.54.1 8 / 12
0.54.0 8 / 12
0.53.0 8 / 13
0.52.1 8 / 14
0.52.0 8 / 14
0.51.1 8 / 15
0.51.0 7 / 15
0.50.0 7 / 15
0.49.1 7 / 15
0.49.0 7 / 15
0.48.0 7 / 15
0.47.0 7 / 16
0.46.0 7 / 16
0.45.1 7 / 16
0.45.0 7 / 16
0.44.0 7 / 16
0.43.0 7 / 16
0.42.0 7 / 16
0.41.2 7 / 16
0.41.1 7 / 16
0.41.0 8 / 16
0.40.0 7 / 14
0.39.1 7 / 14
0.39.0 7 / 14
0.38.0 7 / 15

v0.218.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.217.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.216.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.214.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.213.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.212.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.211.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.210.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.209.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.208.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.207.0

2 findings
HIGH Publisher changed: dyladan → GitHub Actions (on 2025-10-21) provenance

This version was published by a different npm account than previous versions on 2025-10-21. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.206.0

2 findings
HIGH Publisher changed: dyladan → GitHub Actions (on 2025-10-06) provenance

This version was published by a different npm account than previous versions on 2025-10-06. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.205.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v0.204.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v0.203.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v0.202.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v0.201.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v0.201.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v0.200.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v0.57.2

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

INFO Publisher changed: pichlermarc → dyladan (on 2025-02-13) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2025-02-13. This could indicate a legitimate maintainer transition or an account compromise.

v0.57.1

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

INFO Publisher changed: pichlermarc → dyladan (on 2025-01-14) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2025-01-14. This could indicate a legitimate maintainer transition or an account compromise.

v0.57.0

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

INFO Publisher changed: pichlermarc → dyladan (on 2024-12-18) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2024-12-18. This could indicate a legitimate maintainer transition or an account compromise.

v0.56.0

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

INFO Publisher changed: pichlermarc → dyladan (on 2024-12-04) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2024-12-04. This could indicate a legitimate maintainer transition or an account compromise.

v0.55.0

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

INFO Publisher changed: pichlermarc → dyladan (on 2024-11-18) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2024-11-18. This could indicate a legitimate maintainer transition or an account compromise.

v0.54.2

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

INFO Publisher changed: pichlermarc → dyladan (on 2024-11-07) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2024-11-07. This could indicate a legitimate maintainer transition or an account compromise.

v0.54.1

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

INFO Publisher changed: pichlermarc → dyladan (on 2024-11-05) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2024-11-05. This could indicate a legitimate maintainer transition or an account compromise.

v0.54.0

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

INFO Publisher changed: pichlermarc → dyladan (on 2024-10-23) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2024-10-23. This could indicate a legitimate maintainer transition or an account compromise.

v0.53.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.52.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.52.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.51.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.51.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.50.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.49.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.49.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.48.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.47.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.46.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.45.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.45.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.44.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.43.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.42.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.41.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.41.1

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: pichlermarc → dyladan (on 2023-07-24) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2023-07-24. This could indicate a legitimate maintainer transition or an account compromise.

v0.41.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.40.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: dyladan → pichlermarc (on 2023-06-06) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2023-06-06. This could indicate a legitimate maintainer transition or an account compromise.

v0.39.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.39.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.38.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.