← Home

@mikro-orm/postgresql

43
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

b4nan

Keywords

data-mapperdddentityidentity-mapjavascriptjsmariadbmikro-ormmongomongodbmysqlormpostgresqlsqlitesqlite3tstypescriptunit-of-work

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition from maintainer to GitHub Actions CI/CD publishing; SLSA attestation confirms legitimacy. ai
dependencies unvetted-dep:@mikro-orm/knex AI (dependencies): Same-monorepo sibling package; unvetted status is a pipeline gap, not a real supply chain risk for this package. ai
dependencies unvetted-dep:pg-cursor AI (dependencies): Standard PostgreSQL cursor library; expected dependency for this ORM driver. ai
dependencies unvetted-dep:@mikro-orm/sql AI (dependencies): Core mikro-orm SQL package; expected sibling dependency in the monorepo. ai

Versions (showing 43 of 43)

Version Deps Published
7.1.7 7 / 1
7.1.6 7 / 1
7.1.5 7 / 1
7.1.4 7 / 1
7.1.3 7 / 1
7.1.2 7 / 1
7.1.1 7 / 1
7.1.0 7 / 1
7.0.17 7 / 1
7.0.16 7 / 1
7.0.15 7 / 1
7.0.14 7 / 1
7.0.13 7 / 1
7.0.12 7 / 1
7.0.11 7 / 1
7.0.10 7 / 1
7.0.9 7 / 1
7.0.8 7 / 1
7.0.7 7 / 1
7.0.6 7 / 1
7.0.5 7 / 1
7.0.4 7 / 1
7.0.3 7 / 1
7.0.2 7 / 1
7.0.1 7 / 1
7.0.0 7 / 1
6.6.16 5 / 1
6.6.15 5 / 1
6.6.14 5 / 1
6.6.13 5 / 1
6.6.12 5 / 1
6.6.11 5 / 1
6.6.10 5 / 1
6.6.9 5 / 1
6.6.8 5 / 1
6.6.7 5 / 1
6.6.6 5 / 1
6.6.5 5 / 1
6.6.4 5 / 1
6.6.3 5 / 1
6.6.2 5 / 1
6.6.1 5 / 1
6.6.0 5 / 1

v7.1.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.1.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.1.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.6.16

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.