← Home

@opentelemetry/node

OpenTelemetry Node SDK provides automatic telemetry (tracing, metrics, etc) for Node.js applications

38
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

mayurkale22bogdandrutudyladanobecny

Keywords

opentelemetrynodejstracingprofilingmetricsstats

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): mayurkale22 is a long-standing OpenTelemetry contributor (825 approved packages, first seen 2554 days ago); publisher rotation is expected in a large OSS project with multiple maintainers. ai
phantom-deps phantom-dep:semver AI (phantom-deps): semver is a legitimate declared runtime dependency in this TypeScript package; indirect import pattern is expected in a monorepo build. ai
phantom-deps phantom-dep:@opentelemetry/core AI (phantom-deps): Same-org scoped dependency; indirect import pattern is expected in the OpenTelemetry JS monorepo. ai
phantom-deps phantom-dep:@opentelemetry/types AI (phantom-deps): Same-org scoped dependency; indirect import pattern is expected in the OpenTelemetry JS monorepo. ai
typosquat typosquat.levenshtein:zod AI (typosquat): @opentelemetry/node is an official CNCF OpenTelemetry scoped package; Levenshtein match against 'zod' is a false positive with no plausible typosquat relationship. ai
phantom-deps phantom-dep:@opentelemetry/tracing AI (phantom-deps): Same-org scoped dependency; indirect import pattern is expected in the OpenTelemetry JS monorepo. ai
phantom-deps phantom-dep:@opentelemetry/scope-async-hooks AI (phantom-deps): Same-org scoped dependency; indirect import pattern is expected in the OpenTelemetry JS monorepo. ai
phantom-deps phantom-dep:require-in-the-middle AI (phantom-deps): Legitimate runtime dependency for Node.js module interception; indirect import pattern is expected in this package. ai

Versions (showing 38 of 38)

Version Deps Published
0.24.0 6 / 16
0.23.0 6 / 17
0.22.0 6 / 17
0.21.0 6 / 17
0.20.0 6 / 17
0.19.0 6 / 17
0.18.2 5 / 16
0.18.1 5 / 16
0.18.0 5 / 16
0.17.0 5 / 17
0.16.0 6 / 15
0.15.0 6 / 15
0.14.0 6 / 15
0.13.0 6 / 15
0.12.0 6 / 15
0.11.0 6 / 15
0.10.2 6 / 15
0.10.1 6 / 15
0.10.0 6 / 15
0.9.0 6 / 15
0.8.3 6 / 15
0.8.2 6 / 15
0.8.1 6 / 17
0.8.0 6 / 17
0.7.0 6 / 17
0.6.1 6 / 17
0.6.0 6 / 17
0.5.2 6 / 17
0.5.1 6 / 17
0.5.0 6 / 17
0.4.0 6 / 15
0.3.3 6 / 15
0.3.2 6 / 15
0.3.1 6 / 15
0.3.0 6 / 15
0.2.0 6 / 15
0.1.1 6 / 15
0.1.0 6 / 15

v0.24.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.23.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.22.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.21.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.20.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.19.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.18.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.18.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.18.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.17.0

2 findings
HIGH Publisher changed: obecny → dyladan (on 2021-02-17) provenance

This version was published by a different npm account than previous versions on 2021-02-17. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.16.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: dyladan → obecny (on 2021-02-01) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-02-01. This could indicate a legitimate maintainer transition or an account compromise.

v0.15.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.14.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.13.0

2 findings
HIGH Publisher changed: obecny → dyladan (on 2020-12-04) provenance

This version was published by a different npm account than previous versions on 2020-12-04. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: dyladan → obecny (on 2020-10-19) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2020-10-19. This could indicate a legitimate maintainer transition or an account compromise.

v0.11.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: dyladan → obecny (on 2020-09-01) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2020-09-01. This could indicate a legitimate maintainer transition or an account compromise.

v0.10.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: mayurkale22 → dyladan (on 2020-07-27) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2020-07-27. This could indicate a legitimate maintainer transition or an account compromise.

v0.9.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: dyladan → mayurkale22 (on 2020-06-18) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2020-06-18. This could indicate a legitimate maintainer transition or an account compromise.

v0.8.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.8.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.8.1

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: mayurkale22 → dyladan (on 2020-05-18) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2020-05-18. This could indicate a legitimate maintainer transition or an account compromise.

v0.8.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.0

2 findings
HIGH Publisher changed: dyladan → mayurkale22 (on 2020-04-24) provenance

This version was published by a different npm account than previous versions on 2020-04-24. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.1

2 findings
HIGH Publisher changed: mayurkale22 → dyladan (on 2020-04-08) provenance

This version was published by a different npm account than previous versions on 2020-04-08. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: dyladan → mayurkale22 (on 2020-04-02) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2020-04-02. This could indicate a legitimate maintainer transition or an account compromise.

v0.5.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.1

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: mayurkale22 → dyladan (on 2020-03-20) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2020-03-20. This could indicate a legitimate maintainer transition or an account compromise.

v0.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.