← Home

@powersync/node

39
Versions
License
Yes
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

journeyapps-platformjourneyapps-admin

Keywords

data syncoffline-firstsqlitereal-time data streamlive data

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
install-behavior install-behavior:native-compile AI (install-behavior): Downloads pinned prebuilt binary from project's own GitHub releases; standard native-binding install. ai
dependencies unvetted-dep:@powersync/better-sqlite3 AI (dependencies): Sibling package from same PowerSync org. ai
publish-pattern new-deps-added AI (publish-pattern): New dep is first-party split from same monorepo, not third-party. ai
dependencies unvetted-dep:@powersync/shared-internals AI (dependencies): First-party PowerSync-scoped package, same publishing org. ai
semgrep semgrep:toplevel-fetch AI (semgrep): Fetch is in download_core.js pulling from github.com/powersync-ja releases; part of documented binary install flow. ai
install-scripts install-script:install AI (install-scripts): Documented prebuilt binary download for native SQLite binding; stable pattern across all versions of this package. ai
npm-metadata bundled-binaries AI (npm-metadata): Platform-specific native core libraries are the expected distribution mechanism for this SQLite sync SDK. ai
semgrep semgrep:dynamic-require AI (semgrep): Dynamic require in a CJS interop shim (modules_commonjs.js) for ESM/CJS bundling; standard pattern. ai
semgrep semgrep:base64-decode AI (semgrep): Base64 decode used for file encoding conversion in filesystem adapter; not a payload obfuscation pattern. ai
typosquat typosquat.levenshtein:zod AI (typosquat): Scoped package @powersync/node is not a typosquat of zod; edit-distance match is coincidental. ai

Versions (showing 39 of 39)

Version Deps Published
0.20.0 4 / 8
0.19.4 3 / 9
0.19.3 3 / 9
0.19.2 3 / 9
0.19.1 3 / 9
0.19.0 3 / 9
0.18.8 3 / 11
0.18.7 3 / 11
0.18.6 3 / 11
0.18.5 3 / 11
0.18.4 4 / 9
0.18.3 4 / 9
0.18.2 4 / 9
0.18.1 5 / 9
0.18.0 5 / 9
0.17.1 5 / 9
0.17.0 5 / 9
0.16.0 5 / 9
0.15.2 5 / 7
0.15.1 5 / 7
0.15.0 5 / 7
0.14.3 5 / 7
0.14.2 5 / 7
0.14.1 5 / 7
0.14.0 5 / 7
0.13.0 5 / 8
0.12.0 5 / 8
0.11.1 6 / 6
0.11.0 6 / 6
0.10.2 6 / 6
0.10.0 6 / 6
0.9.0 6 / 6
0.8.1 6 / 6
0.8.0 6 / 6
0.6.0 6 / 6
0.4.3 8 / 6
0.4.2 8 / 6
0.4.0 8 / 6
0.2.1 5 / 6

v0.20.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.19.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.19.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.0

2 findings
HIGH Install script compiles native code with a raw toolchain install-behavior

Detected raw native compilation in install lifecycle script(s): 'install'.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.1

2 findings
HIGH Install script compiles native code with a raw toolchain install-behavior

Detected raw native compilation in install lifecycle script(s): 'install'.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.