← Home

@powersync/node

30
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

journeyapps-platformjourneyapps-admin

Keywords

data syncoffline-firstsqlitereal-time data streamlive data

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:toplevel-fetch AI (semgrep): Fetch is in download_core.js pulling from github.com/powersync-ja releases; part of documented binary install flow. ai
install-scripts install-script:install AI (install-scripts): Documented prebuilt binary download for native SQLite binding; stable pattern across all versions of this package. ai
npm-metadata bundled-binaries AI (npm-metadata): Platform-specific native core libraries are the expected distribution mechanism for this SQLite sync SDK. ai
typosquat typosquat.levenshtein:zod AI (typosquat): Scoped package @powersync/node is not a typosquat of zod; edit-distance match is coincidental. ai
semgrep semgrep:base64-decode AI (semgrep): Base64 decode used for file encoding conversion in filesystem adapter; not a payload obfuscation pattern. ai
semgrep semgrep:dynamic-require AI (semgrep): Dynamic require in a CJS interop shim (modules_commonjs.js) for ESM/CJS bundling; standard pattern. ai

Versions (showing 30 of 30)

Version Deps Published
0.18.7 3 / 11
0.18.6 3 / 11
0.18.5 3 / 11
0.18.4 4 / 9
0.18.3 4 / 9
0.18.2 4 / 9
0.18.1 5 / 9
0.18.0 5 / 9
0.17.1 5 / 9
0.17.0 5 / 9
0.16.0 5 / 9
0.15.2 5 / 7
0.15.1 5 / 7
0.15.0 5 / 7
0.14.3 5 / 7
0.14.2 5 / 7
0.14.1 5 / 7
0.14.0 5 / 7
0.13.0 5 / 8
0.12.0 5 / 8
0.11.1 6 / 6
0.11.0 6 / 6
0.10.2 6 / 6
0.10.0 6 / 6
0.9.0 6 / 6
0.8.1 6 / 6
0.6.0 6 / 6
0.4.3 8 / 6
0.4.2 8 / 6
0.4.0 8 / 6

v0.18.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.18.6

2 findings
HIGH Bundled binary files (10) npm-metadata

Package contains compiled binaries that could be backdoors: • lib/powersync_aarch64.dll • lib/powersync_x64.dll • lib/powersync_x86.dll • lib/libpowersync_aarch64.macos.dylib • lib/libpowersync_x64.macos.dylib • lib/libpowersync_aarch64.linux.so • lib/libpowersync_armv7.linux.so • lib/libpowersync_riscv64gc.linux.so • lib/libpowersync_x64.linux.so • lib/libpowersync_x86.linux.so

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.18.5

2 findings
HIGH Bundled binary files (10) npm-metadata

Package contains compiled binaries that could be backdoors: • lib/powersync_aarch64.dll • lib/powersync_x64.dll • lib/powersync_x86.dll • lib/libpowersync_aarch64.macos.dylib • lib/libpowersync_x64.macos.dylib • lib/libpowersync_aarch64.linux.so • lib/libpowersync_armv7.linux.so • lib/libpowersync_riscv64gc.linux.so • lib/libpowersync_x64.linux.so • lib/libpowersync_x86.linux.so

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.18.4

2 findings
HIGH Bundled binary files (10) npm-metadata

Package contains compiled binaries that could be backdoors: • lib/powersync_aarch64.dll • lib/powersync_x64.dll • lib/powersync_x86.dll • lib/libpowersync_aarch64.macos.dylib • lib/libpowersync_x64.macos.dylib • lib/libpowersync_aarch64.linux.so • lib/libpowersync_armv7.linux.so • lib/libpowersync_riscv64gc.linux.so • lib/libpowersync_x64.linux.so • lib/libpowersync_x86.linux.so

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.18.3

2 findings
HIGH Bundled binary files (10) npm-metadata

Package contains compiled binaries that could be backdoors: • lib/powersync_aarch64.dll • lib/powersync_x64.dll • lib/powersync_x86.dll • lib/libpowersync_aarch64.macos.dylib • lib/libpowersync_x64.macos.dylib • lib/libpowersync_aarch64.linux.so • lib/libpowersync_armv7.linux.so • lib/libpowersync_riscv64gc.linux.so • lib/libpowersync_x64.linux.so • lib/libpowersync_x86.linux.so

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.18.2

2 findings
HIGH Bundled binary files (10) npm-metadata

Package contains compiled binaries that could be backdoors: • lib/powersync_aarch64.dll • lib/powersync_x64.dll • lib/powersync_x86.dll • lib/libpowersync_aarch64.macos.dylib • lib/libpowersync_x64.macos.dylib • lib/libpowersync_aarch64.linux.so • lib/libpowersync_armv7.linux.so • lib/libpowersync_riscv64gc.linux.so • lib/libpowersync_x64.linux.so • lib/libpowersync_x86.linux.so

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.18.1

2 findings
HIGH Bundled binary files (10) npm-metadata

Package contains compiled binaries that could be backdoors: • lib/powersync_aarch64.dll • lib/powersync_x64.dll • lib/powersync_x86.dll • lib/libpowersync_aarch64.macos.dylib • lib/libpowersync_x64.macos.dylib • lib/libpowersync_aarch64.linux.so • lib/libpowersync_armv7.linux.so • lib/libpowersync_riscv64gc.linux.so • lib/libpowersync_x64.linux.so • lib/libpowersync_x86.linux.so

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.18.0

2 findings
HIGH Bundled binary files (10) npm-metadata

Package contains compiled binaries that could be backdoors: • lib/powersync_aarch64.dll • lib/powersync_x64.dll • lib/powersync_x86.dll • lib/libpowersync_aarch64.macos.dylib • lib/libpowersync_x64.macos.dylib • lib/libpowersync_aarch64.linux.so • lib/libpowersync_armv7.linux.so • lib/libpowersync_riscv64gc.linux.so • lib/libpowersync_x64.linux.so • lib/libpowersync_x86.linux.so

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.17.1

2 findings
HIGH Bundled binary files (10) npm-metadata

Package contains compiled binaries that could be backdoors: • lib/powersync_aarch64.dll • lib/powersync_x64.dll • lib/powersync_x86.dll • lib/libpowersync_aarch64.macos.dylib • lib/libpowersync_x64.macos.dylib • lib/libpowersync_aarch64.linux.so • lib/libpowersync_armv7.linux.so • lib/libpowersync_riscv64gc.linux.so • lib/libpowersync_x64.linux.so • lib/libpowersync_x86.linux.so

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.17.0

2 findings
HIGH Bundled binary files (10) npm-metadata

Package contains compiled binaries that could be backdoors: • lib/powersync_aarch64.dll • lib/powersync_x64.dll • lib/powersync_x86.dll • lib/libpowersync_aarch64.macos.dylib • lib/libpowersync_x64.macos.dylib • lib/libpowersync_aarch64.linux.so • lib/libpowersync_armv7.linux.so • lib/libpowersync_riscv64gc.linux.so • lib/libpowersync_x64.linux.so • lib/libpowersync_x86.linux.so

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.0

2 findings
HIGH Bundled binary files (10) npm-metadata

Package contains compiled binaries that could be backdoors: • lib/powersync_aarch64.dll • lib/powersync_x64.dll • lib/powersync_x86.dll • lib/libpowersync_aarch64.macos.dylib • lib/libpowersync_x64.macos.dylib • lib/libpowersync_aarch64.linux.so • lib/libpowersync_armv7.linux.so • lib/libpowersync_riscv64gc.linux.so • lib/libpowersync_x64.linux.so • lib/libpowersync_x86.linux.so

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.15.2

2 findings
HIGH Bundled binary files (10) npm-metadata

Package contains compiled binaries that could be backdoors: • lib/powersync_aarch64.dll • lib/powersync_x64.dll • lib/powersync_x86.dll • lib/libpowersync_aarch64.macos.dylib • lib/libpowersync_x64.macos.dylib • lib/libpowersync_aarch64.linux.so • lib/libpowersync_armv7.linux.so • lib/libpowersync_riscv64gc.linux.so • lib/libpowersync_x64.linux.so • lib/libpowersync_x86.linux.so

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.15.1

2 findings
HIGH Bundled binary files (10) npm-metadata

Package contains compiled binaries that could be backdoors: • lib/powersync_aarch64.dll • lib/powersync_x64.dll • lib/powersync_x86.dll • lib/libpowersync_aarch64.macos.dylib • lib/libpowersync_x64.macos.dylib • lib/libpowersync_aarch64.linux.so • lib/libpowersync_armv7.linux.so • lib/libpowersync_riscv64gc.linux.so • lib/libpowersync_x64.linux.so • lib/libpowersync_x86.linux.so

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.15.0

2 findings
HIGH Bundled binary files (10) npm-metadata

Package contains compiled binaries that could be backdoors: • lib/powersync_aarch64.dll • lib/powersync_x64.dll • lib/powersync_x86.dll • lib/libpowersync_aarch64.macos.dylib • lib/libpowersync_x64.macos.dylib • lib/libpowersync_aarch64.linux.so • lib/libpowersync_armv7.linux.so • lib/libpowersync_riscv64gc.linux.so • lib/libpowersync_x64.linux.so • lib/libpowersync_x86.linux.so

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.14.3

2 findings
HIGH Bundled binary files (10) npm-metadata

Package contains compiled binaries that could be backdoors: • lib/powersync_aarch64.dll • lib/powersync_x64.dll • lib/powersync_x86.dll • lib/libpowersync_aarch64.dylib • lib/libpowersync_x64.dylib • lib/libpowersync_aarch64.so • lib/libpowersync_armv7.so • lib/libpowersync_riscv64gc.so • lib/libpowersync_x64.so • lib/libpowersync_x86.so

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.14.2

2 findings
HIGH Bundled binary files (10) npm-metadata

Package contains compiled binaries that could be backdoors: • lib/powersync_aarch64.dll • lib/powersync_x64.dll • lib/powersync_x86.dll • lib/libpowersync_aarch64.dylib • lib/libpowersync_x64.dylib • lib/libpowersync_aarch64.so • lib/libpowersync_armv7.so • lib/libpowersync_riscv64gc.so • lib/libpowersync_x64.so • lib/libpowersync_x86.so

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.14.1

2 findings
HIGH Bundled binary files (10) npm-metadata

Package contains compiled binaries that could be backdoors: • lib/powersync_aarch64.dll • lib/powersync_x64.dll • lib/powersync_x86.dll • lib/libpowersync_aarch64.dylib • lib/libpowersync_x64.dylib • lib/libpowersync_aarch64.so • lib/libpowersync_armv7.so • lib/libpowersync_riscv64gc.so • lib/libpowersync_x64.so • lib/libpowersync_x86.so

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.14.0

2 findings
HIGH Bundled binary files (10) npm-metadata

Package contains compiled binaries that could be backdoors: • lib/powersync_aarch64.dll • lib/powersync_x64.dll • lib/powersync_x86.dll • lib/libpowersync_aarch64.dylib • lib/libpowersync_x64.dylib • lib/libpowersync_aarch64.so • lib/libpowersync_armv7.so • lib/libpowersync_riscv64gc.so • lib/libpowersync_x64.so • lib/libpowersync_x86.so

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.13.0

2 findings
HIGH Bundled binary files (10) npm-metadata

Package contains compiled binaries that could be backdoors: • lib/powersync_aarch64.dll • lib/powersync_x64.dll • lib/powersync_x86.dll • lib/libpowersync_aarch64.dylib • lib/libpowersync_x64.dylib • lib/libpowersync_aarch64.so • lib/libpowersync_armv7.so • lib/libpowersync_riscv64gc.so • lib/libpowersync_x64.so • lib/libpowersync_x86.so

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.12.0

2 findings
HIGH Bundled binary files (10) npm-metadata

Package contains compiled binaries that could be backdoors: • lib/powersync_aarch64.dll • lib/powersync_x64.dll • lib/powersync_x86.dll • lib/libpowersync_aarch64.dylib • lib/libpowersync_x64.dylib • lib/libpowersync_aarch64.so • lib/libpowersync_armv7.so • lib/libpowersync_riscv64gc.so • lib/libpowersync_x64.so • lib/libpowersync_x86.so

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.11.1

3 findings
HIGH Package has 'install' script install-scripts

Script: node download_core.js

HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • lib/libpowersync.so

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.11.0

3 findings
HIGH Package has 'install' script install-scripts

Script: node download_core.js

HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • lib/libpowersync.so

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.10.2

3 findings
HIGH Package has 'install' script install-scripts

Script: node download_core.js

HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • lib/libpowersync.so

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.10.0

3 findings
HIGH Package has 'install' script install-scripts

Script: node download_core.js

HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • lib/libpowersync.so

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.0

3 findings
HIGH Package has 'install' script install-scripts

Script: node download_core.js

HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • lib/libpowersync.so

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.8.1

3 findings
HIGH Package has 'install' script install-scripts

Script: node download_core.js

HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • lib/libpowersync.so

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.6.0

3 findings
HIGH Package has 'install' script install-scripts

Script: node download_core.js

HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • lib/libpowersync.so

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.4.3

3 findings
HIGH Package has 'install' script install-scripts

Script: node download_core.js

HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • lib/libpowersync.so

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.4.2

3 findings
HIGH Package has 'install' script install-scripts

Script: node download_core.js

HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • lib/libpowersync.so

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.4.0

3 findings
HIGH Package has 'install' script install-scripts

Script: node download_core.js

HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • lib/libpowersync.so

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.