← Home

@php-wasm/fs-journal

Bindings to journal the PHP filesystem

82
Versions
GPL-2.0-or-later
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

bgrgicakadamzielbrandonpayton-a8csejasdanielbachhuberyannickdecatjanjakesakirk

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Package publishes via GitHub Actions CI with SLSA attestation; publisher=GitHub Actions is the expected stable pattern. ai
maintainer-change maintainer-added AI (maintainer-change): New maintainers are WordPress Playground contributors; consistent with org-level project growth. ai
phantom-deps phantom-dep:yargs AI (phantom-deps): Monorepo workspace dep declared at package level; stable false positive for this package. ai
phantom-deps phantom-dep:express AI (phantom-deps): Monorepo workspace dep declared at package level; stable false positive for this package. ai
phantom-deps phantom-dep:jsonc-parser AI (phantom-deps): Monorepo workspace dep declared at package level; stable false positive for this package. ai
phantom-deps phantom-dep:ws AI (phantom-deps): Monorepo workspace dep declared at package level; stable false positive for this package. ai
phantom-deps phantom-dep:fast-xml-parser AI (phantom-deps): Monorepo workspace dep declared at package level; stable false positive for this package. ai
phantom-deps phantom-dep:wasm-feature-detect AI (phantom-deps): Monorepo workspace dep declared at package level; stable false positive for this package. ai
phantom-deps phantom-dep:fs-ext-extra-prebuilt AI (phantom-deps): Platform-specific binary package; phantom-dep heuristic is a stable false positive here. ai
phantom-deps phantom-dep:@php-wasm/node AI (phantom-deps): Same-org sibling dep; stable false positive for this package. ai
phantom-deps phantom-dep:ini AI (phantom-deps): Monorepo workspace dep declared at package level; stable false positive for this package. ai

Versions (showing 82 of 82)

Version Deps Published
3.1.47 3 / 0
3.1.46 3 / 0
3.1.45 3 / 0
3.1.44 3 / 0
3.1.43 3 / 0
3.1.42 3 / 0
3.1.41 3 / 0
3.1.40 3 / 0
3.1.39 3 / 0
3.1.38 3 / 0
3.1.36 3 / 0
3.1.35 3 / 0
3.1.34 3 / 0
3.1.33 3 / 0
3.1.32 3 / 0
3.1.31 3 / 0
3.1.30 3 / 0
3.1.29 3 / 0
3.1.28 13 / 0
3.1.27 13 / 0
3.1.26 13 / 0
3.1.25 12 / 0
3.1.22 12 / 0
3.1.21 12 / 0
3.1.20 12 / 0
3.1.19 12 / 0
3.1.18 12 / 0
3.1.16 12 / 0
3.1.15 12 / 0
3.1.14 12 / 0
3.1.13 12 / 0
3.1.12 12 / 0
3.1.11 12 / 0
3.1.10 12 / 0
3.1.9 12 / 0
3.1.8 12 / 0
3.1.5 12 / 0
3.1.4 12 / 0
3.1.3 12 / 0
3.1.2 10 / 0
3.1.1 10 / 0
3.1.0 10 / 0
3.0.54 9 / 0
3.0.53 9 / 0
3.0.52 9 / 0
3.0.51 9 / 0
3.0.46 9 / 0
3.0.45 9 / 0
3.0.44 9 / 0
3.0.43 9 / 0
3.0.42 9 / 0
3.0.41 9 / 0
3.0.40 9 / 0
3.0.39 9 / 0
3.0.38 9 / 0
3.0.37 9 / 0
3.0.36 9 / 0
3.0.35 9 / 0
3.0.34 9 / 0
3.0.33 9 / 0
3.0.32 9 / 0
3.0.31 9 / 0
3.0.30 9 / 0
3.0.22 10 / 0
3.0.21 10 / 0
3.0.20 10 / 0
3.0.19 10 / 0
3.0.18 10 / 0
3.0.17 10 / 0
3.0.16 10 / 0
3.0.15 10 / 0
3.0.14 10 / 0
3.0.13 10 / 0
3.0.12 10 / 0
3.0.8 10 / 0
3.0.6 10 / 0
3.0.5 10 / 0
3.0.4 10 / 0
3.0.3 10 / 0
3.0.2 10 / 0
3.0.1 10 / 0
3.0.0 10 / 0

v3.1.47

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.46

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.45

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.44

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.43

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.