← Home

@planetscale/database

26
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

planetscale-npmiamjasonlongdgrahamayrtonmattrobenoltffinknickvanw

Keywords

planetscaledatabasemysqlvitessserverlessvercellambda

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
maintainer-change maintainer-added AI (maintainer-change): Stale 2023 transfer, still live on npm, no takeover indicators. ai
maintainer-change maintainer-removed AI (maintainer-change): Same stale transfer event, consistent with legitimate handoff. ai
provenance publisher-changed-stale AI (provenance): Publisher change is 949 days old and unremoved, inconsistent with compromise. ai

Versions (showing 26 of 26)

Version Deps Published
1.20.1 0 / 14
1.20.0 0 / 14
1.19.0 0 / 14
1.18.0 0 / 14
1.17.0 0 / 14
1.16.0 0 / 14
1.15.0 0 / 14
1.14.0 0 / 14
1.13.0 0 / 14
1.12.0 0 / 14
1.11.0 0 / 14
1.10.0 0 / 14
1.9.0 0 / 14
1.8.0 0 / 14
1.7.0 0 / 14
1.6.0 0 / 14
1.5.0 0 / 14
1.4.1 0 / 14
1.4.0 0 / 14
1.3.0 0 / 14
1.2.1 0 / 14
1.2.0 0 / 14
1.1.0 0 / 14
1.0.2 0 / 14
1.0.1 0 / 14
1.0.0 0 / 14

v1.19.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.18.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.17.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.16.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.15.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.14.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.13.0

2 findings
MEDIUM Publisher changed: iheanyi → ayrton (on 2023-12-14, unremoved on npm for 949d) provenance

This version was published by a different npm account (ayrton) than the most recent previously approved version (iheanyi) on 2023-12-14. It has since remained available on npm for 949 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.12.0

2 findings
MEDIUM Publisher changed: iheanyi → ayrton (on 2023-12-14, unremoved on npm for 949d) provenance

This version was published by a different npm account (ayrton) than the most recent previously approved version (iheanyi) on 2023-12-14. It has since remained available on npm for 949 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.11.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.10.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: dgraham → iheanyi (on 2023-07-25, known maintainer) provenance

This version was published by a different npm account (iheanyi) than the most recent previously approved version (dgraham) on 2023-07-25, but iheanyi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.9.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.8.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: dgraham → iheanyi (on 2023-06-29, known maintainer) provenance

This version was published by a different npm account (iheanyi) than the most recent previously approved version (dgraham) on 2023-06-29, but iheanyi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.7.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: iheanyi → dgraham (on 2023-04-06, known maintainer) provenance

This version was published by a different npm account (dgraham) than the most recent previously approved version (iheanyi) on 2023-04-06, but dgraham is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.2

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: iheanyi → dgraham (on 2022-08-23, known maintainer) provenance

This version was published by a different npm account (dgraham) than the most recent previously approved version (iheanyi) on 2022-08-23, but dgraham is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.