← Home

@php-wasm/node

15
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

bgrgicakadamzielbrandonpayton-a8csejasdanielbachhuberyannickdecatjanjakesakirk

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
typosquat typosquat.levenshtein:zod AI (typosquat): @php-wasm/node is a scoped package with no resemblance to 'zod'; Levenshtein match is a false positive. ai
phantom-deps phantom-dep:ini AI (phantom-deps): Declared runtime dep used transitively or via config; stable false positive for this monorepo package. ai
phantom-deps phantom-dep:yargs AI (phantom-deps): Declared runtime dep; phantom-dep heuristic fires on monorepo build artifacts. ai
phantom-deps phantom-dep:express AI (phantom-deps): Declared runtime dep; phantom-dep heuristic fires on monorepo build artifacts. ai
phantom-deps phantom-dep:jsonc-parser AI (phantom-deps): Declared runtime dep; phantom-dep heuristic fires on monorepo build artifacts. ai
phantom-deps phantom-dep:fast-xml-parser AI (phantom-deps): Declared runtime dep; phantom-dep heuristic fires on monorepo build artifacts. ai
phantom-deps phantom-dep:wasm-feature-detect AI (phantom-deps): Declared runtime dep; phantom-dep heuristic fires on monorepo build artifacts. ai
phantom-deps phantom-dep:@wp-playground/common AI (phantom-deps): Declared runtime dep from same monorepo; phantom-dep heuristic fires on monorepo build artifacts. ai

Versions (showing 15 of 15)

Version Deps Published
3.1.35 15 / 0
3.1.34 15 / 0
3.1.33 15 / 0
3.1.32 15 / 0
3.1.31 15 / 0
3.1.30 15 / 0
3.1.29 15 / 0
3.1.28 22 / 0
3.1.27 22 / 0
3.1.26 22 / 0
3.1.25 21 / 0
3.1.22 21 / 0
3.1.21 21 / 0
3.1.20 20 / 0
3.1.14 21 / 0

v3.1.35

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.34

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.33

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.32

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.31

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.30

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.29

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.28

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.27

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.26

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.25

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.22

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.20

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.14

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.