@prisma-next/migration-tools
On-disk migration persistence, attestation, and chain reconstruction for Prisma Next
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | source-size-tripled | AI (source-diff): Size increase corresponds to new aggregate export and related modules; backed by SLSA provenance. | ai | |
| source-diff | large-new-source-files | AI (source-diff): 66 new files match the new aggregate export surface area; no malicious indicators found. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Reflect.get used inside a Proxy handler for prototype-bound field forwarding — standard JS pattern, not obfuscation. | ai | |
| provenance | missing-githead | AI (provenance): SLSA attestation provides stronger integrity guarantee than gitHead; absence of gitHead is not a meaningful risk here. | ai | |
| phantom-deps | phantom-dep:@prisma-next/utils | AI (phantom-deps): Same-org workspace sibling; phantom-dep heuristic unreliable for monorepo packages. | ai |
Versions (showing 16 of 16)
| Version | Deps | Published |
|---|---|---|
| 0.12.0 | 6 / 6 | |
| 0.11.0 | 6 / 5 | |
| 0.10.0 | 6 / 5 | |
| 0.9.0 | 6 / 5 | |
| 0.8.0 | 6 / 5 | |
| 0.7.0 | 6 / 5 | |
| 0.6.1 | 6 / 5 | |
| 0.5.1 | 6 / 5 | |
| 0.5.0 | 6 / 5 | |
| 0.4.4 | 6 / 5 | |
| 0.4.3 | 6 / 5 | |
| 0.4.2 | 6 / 5 | |
| 0.4.1 | 6 / 5 | |
| 0.3.0 | 5 / 5 | |
| 0.0.2 | 5 / 5 | |
| 0.0.1 | 5 / 5 |
v0.12.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.10.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.9.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.4
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.3
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.