@php-wasm/web
PHP.wasm for the web
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:ajv | AI (phantom-deps): Config-file reference; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:isomorphic-git | AI (phantom-deps): Config-file reference; stable pattern for this package. | ai | |
| dependencies | unvetted-dep:@php-wasm/web-7-2 | AI (dependencies): Sibling monorepo package published in lockstep, not a third-party dep. | ai | |
| phantom-deps | phantom-dep:selfsigned | AI (phantom-deps): Used in config/build tooling, not direct import; benign for this package. | ai | |
| dependencies | unvetted-dep:@php-wasm/web-7-3 | AI (dependencies): Sibling monorepo package published in lockstep, not a third-party dep. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): Monorepo hoist of common utility deps shared across php-wasm packages; not suspicious. | ai | |
| dependencies | unvetted-dep:minimisted | AI (dependencies): minimisted is also a phantom dep (not directly imported); stable pattern across this package's many versions. | ai | |
| phantom-deps | phantom-dep:fs-ext-extra-prebuilt | AI (phantom-deps): Platform-specific binary package declared as dep; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:sha.js | AI (phantom-deps): Same monorepo pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:express | AI (phantom-deps): Same monorepo pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:octokit | AI (phantom-deps): Same monorepo pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:async-lock | AI (phantom-deps): Same monorepo pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:minimisted | AI (phantom-deps): Same monorepo pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:simple-get | AI (phantom-deps): Same monorepo pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:ws | AI (phantom-deps): Monorepo bundle; deps declared for transitive/config use, not direct import. | ai | |
| phantom-deps | phantom-dep:clean-git-ref | AI (phantom-deps): Same monorepo pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:@zip.js/zip.js | AI (phantom-deps): Same monorepo pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:fast-xml-parser | AI (phantom-deps): Same monorepo pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:readable-stream | AI (phantom-deps): Same monorepo pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:wasm-feature-detect | AI (phantom-deps): Same monorepo pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:jsonc-parser | AI (phantom-deps): Same monorepo pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:ini | AI (phantom-deps): Same monorepo pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:pako | AI (phantom-deps): Same monorepo pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:pify | AI (phantom-deps): Same monorepo pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:diff3 | AI (phantom-deps): Same monorepo pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:yargs | AI (phantom-deps): Same monorepo pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:crc-32 | AI (phantom-deps): Same monorepo pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:ignore | AI (phantom-deps): Same monorepo pattern; stable false positive. | ai |
Versions (showing 52 of 52)
| Version | Deps | Published |
|---|---|---|
| 3.1.46 | 16 / 0 | |
| 3.1.45 | 16 / 0 | |
| 3.1.44 | 16 / 0 | |
| 3.1.43 | 16 / 0 | |
| 3.1.42 | 16 / 0 | |
| 3.1.41 | 16 / 0 | |
| 3.1.40 | 16 / 0 | |
| 3.1.39 | 16 / 0 | |
| 3.1.38 | 16 / 0 | |
| 3.1.36 | 16 / 0 | |
| 3.1.35 | 16 / 0 | |
| 3.1.34 | 16 / 0 | |
| 3.1.33 | 16 / 0 | |
| 3.1.32 | 16 / 0 | |
| 3.1.31 | 16 / 0 | |
| 3.1.30 | 16 / 0 | |
| 3.1.29 | 16 / 0 | |
| 3.1.28 | 38 / 0 | |
| 3.1.26 | 37 / 0 | |
| 3.1.25 | 36 / 0 | |
| 3.1.22 | 36 / 0 | |
| 3.1.21 | 36 / 0 | |
| 3.1.20 | 35 / 0 | |
| 3.1.19 | 35 / 0 | |
| 3.1.18 | 35 / 0 | |
| 3.1.17 | 35 / 0 | |
| 3.1.16 | 35 / 0 | |
| 3.1.15 | 35 / 0 | |
| 3.1.14 | 35 / 0 | |
| 3.1.12 | 35 / 0 | |
| 3.1.11 | 35 / 0 | |
| 3.1.10 | 35 / 0 | |
| 3.1.9 | 35 / 0 | |
| 3.1.8 | 35 / 0 | |
| 3.1.5 | 35 / 0 | |
| 3.1.3 | 35 / 0 | |
| 3.1.2 | 19 / 0 | |
| 3.1.1 | 19 / 0 | |
| 3.1.0 | 19 / 0 | |
| 3.0.54 | 19 / 0 | |
| 3.0.53 | 19 / 0 | |
| 3.0.52 | 19 / 0 | |
| 3.0.51 | 19 / 0 | |
| 3.0.46 | 19 / 0 | |
| 3.0.45 | 19 / 0 | |
| 3.0.44 | 19 / 0 | |
| 3.0.43 | 19 / 0 | |
| 3.0.41 | 21 / 0 | |
| 3.0.40 | 21 / 0 | |
| 3.0.39 | 21 / 0 | |
| 3.0.38 | 21 / 0 | |
| 3.0.37 | 21 / 0 |
v3.1.46
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.1.45
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.1.44
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.1.43
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.1.42
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.1.28
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.1.26
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.1.12
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.1.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.1.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.1.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.1.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.1.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.1.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.1.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.1.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.1.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.0.54
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.0.53
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.0.52
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.0.51
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.0.46
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.0.45
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.0.44
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.0.43
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.0.41
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.0.40
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.0.39
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.0.38
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.0.37
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.