@prettier/plugin-php
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| npm-metadata | url-dep:php-parser | AI (npm-metadata): Longstanding pin to upstream php-parser fork predating registry release; official prettier plugin. | ai | |
| npm-metadata | url-dep:prettier | AI (npm-metadata): Dev-only dependency on prettier's own repo, benign for this monorepo-era plugin. | ai | |
| email-domain | unclaimed-email:azz | AI (email-domain): Author field contains '@azz' as a Twitter handle, not a real email address; no actual email domain to hijack. | ai |
Versions (showing 17 of 17)
| Version | Deps | Published |
|---|---|---|
| 0.25.0 | 2 / 24 | |
| 0.24.0 | 2 / 24 | |
| 0.23.0 | 2 / 24 | |
| 0.22.4 | 2 / 24 | |
| 0.22.3 | 2 / 24 | |
| 0.10.0 | 2 / 10 | |
| 0.9.0 | 2 / 9 | |
| 0.8.0 | 2 / 9 | |
| 0.7.0 | 2 / 8 | |
| 0.6.0 | 2 / 8 | |
| 0.4.0 | 2 / 8 | |
| 0.3.1 | 2 / 8 | |
| 0.3.0 | 2 / 8 | |
| 0.2.2 | 1 / 8 | |
| 0.2.1 | 1 / 8 | |
| 0.2.0 | 1 / 8 | |
| 0.1.0 | 1 / 8 |
v0.22.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.22.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.10.0
3 findingsDependency 'php-parser' in `dependencies` points to 'github:glayzzle/php-parser#71485979b688d12fb130d3e853fdc00348671e00' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
This version was published by a different npm account (evilebottnawi) than the most recent previously approved version (czosel) on 2019-02-05. It has since remained available on npm for 2726 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.0
3 findingsDependency 'php-parser' in `dependencies` points to 'github:glayzzle/php-parser#ca007c812e9920bcf1ae9fd24f1a92f5d5906a5e' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
This version was published by a different npm account (evilebottnawi) than the most recent previously approved version (czosel) on 2018-10-15. It has since remained available on npm for 2839 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.0
3 findingsDependency 'php-parser' in `dependencies` points to 'github:glayzzle/php-parser#ca007c812e9920bcf1ae9fd24f1a92f5d5906a5e' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
This version was published by a different npm account (evilebottnawi) than the most recent previously approved version (czosel) on 2018-10-03. It has since remained available on npm for 2851 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.0
3 findingsDependency 'php-parser' in `dependencies` points to 'github:glayzzle/php-parser#85eb5e622fcd4ef1f70bf3b2529afe5e005bdd52' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
This version was published by a different npm account (evilebottnawi) than the most recent previously approved version (czosel) on 2018-09-19. It has since remained available on npm for 2865 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (czosel) than the most recent previously approved version (mgrip) on 2018-07-16, but czosel is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.3.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.0
2 findingsDependency 'php-parser' in `dependencies` points to 'github:glayzzle/php-parser#a8f10d8c9aacf8e90b283229f8bed76363b99fcf' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.