@powersync/web
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/worker/websockets-Q8W_lerF.js | AI (source-diff): Bundled comlink/build output, not obfuscation; part of legit worker rebuild. | ai | |
| source-diff | obfuscated-file:dist/worker/worker.js | AI (source-diff): Comlink bundle, minified build output. | ai | |
| dependencies | unvetted-dep:@powersync/shared-internals | AI (dependencies): First-party PowerSync sibling package, same org/monorepo. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Expected growth from new webpack worker bundles/wasm assets. | ai | |
| source-diff | net-exec-file:dist/index.umd.js | AI (source-diff): Webpack UMD bundle of wa-sqlite/comlink; expected for this WASM SQLite sync SDK. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Diff spans 200+ unimported versions; size growth reflects normal build evolution. | ai | |
| source-diff | net-exec-file:dist/worker/SharedSyncImplementation.umd.js | AI (source-diff): Bundled worker build, not dropper code. | ai | |
| source-diff | net-exec-file:dist/worker/WASQLiteDB.umd.js | AI (source-diff): Bundled worker build, not dropper code. | ai | |
| npm-metadata | bundled-binaries | AI (npm-metadata): WASM SQLite binaries are core to this package's function. | ai |
Versions (showing 39 of 39)
| Version | Deps | Published |
|---|---|---|
| 2.0.0 | 4 / 13 | |
| 1.39.0 | 3 / 12 | |
| 1.38.7 | 3 / 12 | |
| 1.38.6 | 3 / 12 | |
| 1.38.5 | 3 / 12 | |
| 1.38.4 | 3 / 12 | |
| 1.38.3 | 3 / 12 | |
| 1.38.2 | 3 / 12 | |
| 1.38.1 | 3 / 12 | |
| 1.38.0 | 3 / 12 | |
| 1.37.2 | 4 / 14 | |
| 1.37.1 | 4 / 14 | |
| 1.37.0 | 4 / 14 | |
| 1.36.0 | 5 / 14 | |
| 1.35.0 | 5 / 14 | |
| 1.34.0 | 5 / 14 | |
| 1.33.0 | 5 / 14 | |
| 1.32.0 | 5 / 14 | |
| 1.31.0 | 5 / 15 | |
| 1.30.0 | 5 / 15 | |
| 1.29.1 | 5 / 15 | |
| 1.29.0 | 5 / 15 | |
| 1.28.2 | 5 / 15 | |
| 1.28.1 | 5 / 15 | |
| 1.7.0 | 6 / 17 | |
| 1.6.0 | 6 / 17 | |
| 1.5.1 | 6 / 17 | |
| 1.5.0 | 6 / 17 | |
| 1.4.0 | 6 / 17 | |
| 1.3.0 | 7 / 11 | |
| 1.2.4 | 7 / 11 | |
| 1.2.3 | 7 / 11 | |
| 1.2.2 | 7 / 11 | |
| 1.2.1 | 7 / 11 | |
| 1.2.0 | 7 / 11 | |
| 1.1.0 | 7 / 11 | |
| 1.0.2 | 7 / 11 | |
| 1.0.1 | 7 / 11 | |
| 1.0.0 | 7 / 11 |
v2.0.0
12 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.39.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/2075a31bb151adbb9767.wasm • dist/3322bc84de986b63c2cd.wasm • dist/8e97452e297be23b5e50.wasm • dist/fbc178b70d530e8ce02b.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.38.7
2 findingsPackage contains compiled binaries that could be backdoors: • dist/2075a31bb151adbb9767.wasm • dist/3322bc84de986b63c2cd.wasm • dist/8e97452e297be23b5e50.wasm • dist/fbc178b70d530e8ce02b.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.38.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.37.1
6 findingsPackage contains compiled binaries that could be backdoors: • dist/26d61ca9f5694d064635.wasm • dist/b4c6283dc473b6b3fd24.wasm • dist/c78985091a0b22aaef03.wasm • dist/ca59e199e1138b553fad.wasm
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (journeyapps-platform) on 2026-03-30, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v1.37.0
6 findingsPackage contains compiled binaries that could be backdoors: • dist/26d61ca9f5694d064635.wasm • dist/b4c6283dc473b6b3fd24.wasm • dist/c78985091a0b22aaef03.wasm • dist/ca59e199e1138b553fad.wasm
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (journeyapps-platform) on 2026-03-24, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v1.36.0
6 findingsPackage contains compiled binaries that could be backdoors: • dist/26d61ca9f5694d064635.wasm • dist/b4c6283dc473b6b3fd24.wasm • dist/c78985091a0b22aaef03.wasm • dist/ca59e199e1138b553fad.wasm
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (journeyapps-platform) on 2026-03-12, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v1.35.0
6 findingsPackage contains compiled binaries that could be backdoors: • dist/26d61ca9f5694d064635.wasm • dist/b4c6283dc473b6b3fd24.wasm • dist/c78985091a0b22aaef03.wasm • dist/ca59e199e1138b553fad.wasm
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (journeyapps-platform) on 2026-03-04, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v1.34.0
6 findingsPackage contains compiled binaries that could be backdoors: • dist/26d61ca9f5694d064635.wasm • dist/b4c6283dc473b6b3fd24.wasm • dist/c78985091a0b22aaef03.wasm • dist/ca59e199e1138b553fad.wasm
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (journeyapps-platform) on 2026-02-19, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v1.33.0
10 findingsPackage contains compiled binaries that could be backdoors: • dist/0b19af1befc07ce338dd.wasm • dist/2632c3bda9473da74fd5.wasm • dist/64f5351ba3784bfe2f3e.wasm • dist/9318ca94aac4d0fe0135.wasm
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (journeyapps-platform) on 2026-02-16, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v1.32.0
9 findingsPackage contains compiled binaries that could be backdoors: • dist/0b19af1befc07ce338dd.wasm • dist/2632c3bda9473da74fd5.wasm • dist/64f5351ba3784bfe2f3e.wasm • dist/9318ca94aac4d0fe0135.wasm
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.31.0
9 findingsPackage contains compiled binaries that could be backdoors: • dist/0b19af1befc07ce338dd.wasm • dist/2632c3bda9473da74fd5.wasm • dist/64f5351ba3784bfe2f3e.wasm • dist/9318ca94aac4d0fe0135.wasm
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.30.0
9 findingsPackage contains compiled binaries that could be backdoors: • dist/0b19af1befc07ce338dd.wasm • dist/2632c3bda9473da74fd5.wasm • dist/64f5351ba3784bfe2f3e.wasm • dist/9318ca94aac4d0fe0135.wasm
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.29.1
5 findingsPackage contains compiled binaries that could be backdoors: • dist/10072fe45f0a8fab0a0e.wasm • dist/6e435e51534839845554.wasm • dist/a730f7ca717b02234beb.wasm • dist/aa2f408d64445fed090e.wasm
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.29.0
5 findingsPackage contains compiled binaries that could be backdoors: • dist/10072fe45f0a8fab0a0e.wasm • dist/6e435e51534839845554.wasm • dist/a730f7ca717b02234beb.wasm • dist/aa2f408d64445fed090e.wasm
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.28.2
5 findingsPackage contains compiled binaries that could be backdoors: • dist/10072fe45f0a8fab0a0e.wasm • dist/6e435e51534839845554.wasm • dist/a730f7ca717b02234beb.wasm • dist/aa2f408d64445fed090e.wasm
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.28.1
5 findingsPackage contains compiled binaries that could be backdoors: • dist/10072fe45f0a8fab0a0e.wasm • dist/6e435e51534839845554.wasm • dist/a730f7ca717b02234beb.wasm • dist/aa2f408d64445fed090e.wasm
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.