@paperclipai/db
16
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
dottadevinfoley
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | rapid-publish | AI (publish-pattern): Automated CalVer CI releases; 583 versions in 115 days is the established pattern for this package. | ai | |
| source-diff | large-new-source-files | AI (source-diff): New files are Drizzle migration snapshots (JSON), consistent with DB schema evolution, not injected code. | ai | |
| provenance | publisher-changed | AI (provenance): Transition from personal account (dotta) to GitHub Actions CI/CD publishing is a supply chain improvement, backed by SLSA provenance attestation. Generalizes to future versions published via the same pipeline. | ai | |
| dependencies | unvetted-dep:embedded-postgres | AI (dependencies): embedded-postgres is a legitimate library for embedding PostgreSQL; contextually appropriate for a database package. Addition is intentional and documented in package.json. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Package is a scoped internal library (@paperclipai/db) with a clear repo URL; missing description is cosmetic and not a malware indicator for this package. | ai | |
| typosquat | typosquat.levenshtein:qs | AI (typosquat): Scoped package @paperclipai/db has no relation to 'qs'; Levenshtein match is a false positive driven by short package name suffix. | ai | |
| typosquat | typosquat.levenshtein:pg | AI (typosquat): Scoped package @paperclipai/db is a database utility in the paperclipai monorepo; Levenshtein match to 'pg' is a false positive with no impersonation intent. | ai |
Versions (showing 16 of 16)
| Version | Deps | Published |
|---|---|---|
| 2026.707.0 | 4 / 5 | |
| 2026.626.0 | 4 / 5 | |
| 2026.525.0 | 4 / 5 | |
| 2026.428.0 | 4 / 5 | |
| 2026.416.0 | 4 / 5 | |
| 2026.403.0 | 4 / 5 | |
| 2026.325.0 | 4 / 5 | |
| 2026.318.0 | 4 / 5 | |
| 0.3.1 | 3 / 5 | |
| 0.3.0 | 3 / 5 | |
| 0.2.7 | 3 / 4 | |
| 0.2.6 | 3 / 4 | |
| 0.2.5 | 3 / 4 | |
| 0.2.4 | 3 / 4 | |
| 0.2.3 | 3 / 4 | |
| 0.2.2 | 3 / 4 |
v2026.707.0
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.626.0
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.