@prisma/client
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | encoded-string-file:runtime/query_compiler_small_bg.sqlserver.wasm-base64.mjs | AI (source-diff): Base64 WASM compiler bundle; benign. | ai | |
| source-diff | encoded-string-file:runtime/query_compiler_fast_bg.postgresql.wasm-base64.mjs | AI (source-diff): Base64 WASM compiler bundle; benign. | ai | |
| source-diff | encoded-string-file:runtime/query_compiler_fast_bg.sqlite.wasm-base64.js | AI (source-diff): Base64 WASM compiler bundle; benign. | ai | |
| source-diff | encoded-string-file:runtime/query_compiler_fast_bg.sqlite.wasm-base64.mjs | AI (source-diff): Base64 WASM compiler bundle; benign. | ai | |
| source-diff | encoded-string-file:runtime/query_compiler_fast_bg.sqlserver.wasm-base64.js | AI (source-diff): Base64 WASM compiler bundle; benign. | ai | |
| source-diff | encoded-string-file:runtime/query_compiler_fast_bg.sqlserver.wasm-base64.mjs | AI (source-diff): Base64 WASM compiler bundle; benign. | ai | |
| source-diff | encoded-string-file:runtime/query_compiler_small_bg.cockroachdb.wasm-base64.js | AI (source-diff): Base64 WASM compiler bundle; benign. | ai | |
| source-diff | encoded-string-file:runtime/query_compiler_small_bg.cockroachdb.wasm-base64.mjs | AI (source-diff): Base64 WASM compiler bundle; benign. | ai | |
| source-diff | encoded-string-file:runtime/query_compiler_small_bg.mysql.wasm-base64.js | AI (source-diff): Base64 WASM compiler bundle; benign. | ai | |
| source-diff | encoded-string-file:runtime/query_compiler_small_bg.mysql.wasm-base64.mjs | AI (source-diff): Base64 WASM compiler bundle; benign. | ai | |
| source-diff | encoded-string-file:runtime/query_compiler_small_bg.postgresql.wasm-base64.js | AI (source-diff): Base64 WASM compiler bundle; benign. | ai | |
| source-diff | encoded-string-file:runtime/query_compiler_small_bg.postgresql.wasm-base64.mjs | AI (source-diff): Base64 WASM compiler bundle; benign. | ai | |
| source-diff | encoded-string-file:runtime/query_compiler_small_bg.sqlite.wasm-base64.js | AI (source-diff): Base64 WASM compiler bundle; benign. | ai | |
| source-diff | encoded-string-file:runtime/query_compiler_small_bg.sqlite.wasm-base64.mjs | AI (source-diff): Base64 WASM compiler bundle; benign. | ai | |
| source-diff | encoded-string-file:runtime/query_compiler_small_bg.sqlserver.wasm-base64.js | AI (source-diff): Base64 WASM compiler bundle; benign. | ai | |
| source-diff | encoded-string-file:runtime/query_compiler_fast_bg.cockroachdb.wasm-base64.mjs | AI (source-diff): Base64-encoded WASM query-compiler bundle, core Prisma runtime artifact; stable per release. | ai | |
| source-diff | encoded-string-file:runtime/query_compiler_fast_bg.mysql.wasm-base64.js | AI (source-diff): Base64 WASM compiler bundle; benign. | ai | |
| source-diff | encoded-string-file:runtime/query_compiler_fast_bg.mysql.wasm-base64.mjs | AI (source-diff): Base64 WASM compiler bundle; benign. | ai | |
| source-diff | encoded-string-file:runtime/query_compiler_fast_bg.postgresql.wasm-base64.js | AI (source-diff): base64-encoded WASM query compiler; canonical Prisma runtime asset. | ai | |
| source-diff | encoded-string-file:runtime/query_compiler_fast_bg.cockroachdb.wasm-base64.js | AI (source-diff): base64-encoded WASM query compiler; canonical Prisma runtime asset, stable across versions. | ai | |
| semgrep | semgrep:eval-usage | AI (semgrep): eval-usage fires in minified engine-path error-message code; not dynamic eval of user input. Stable false positive for this bundled ORM package. | ai | |
| semgrep | semgrep:child-process-spawn | AI (semgrep): Postinstall spawns prisma generate; documented install flow for @prisma/client. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): Minified runtime reads env for DB connection config; standard ORM behavior, not secret exfiltration. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Reflect.get in WASM engine bindings generated by wasm-bindgen; not obfuscation. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Prisma ships bundled runtime and WASM query engine files; large file counts are inherent to the package architecture. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Prisma's documented postinstall runs code generation via `node scripts/postinstall.js`; stable for this package. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Prisma publishes across multiple major version branches; gaps on one branch while others are active is normal. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require in generator-build loads WASM bundles from controlled, known paths as part of Prisma's documented WASM query compiler build pipeline. Not arbitrary module loading. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): Prisma's generator legitimately uses child_process to invoke native engine binaries during schema generation. Expected behavior for a database ORM with native binary components. | ai | |
| semgrep | semgrep:hex-decode | AI (semgrep): False positive on minified runtime code; sample shows stack trace parsing regexes, not hex payload decoding. | ai | |
| dependencies | unvetted-dep:@prisma/client-runtime-utils | AI (dependencies): First-party Prisma monorepo package at matching version (7.8.0); not a third-party unvetted dependency. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Base64 decoding converts WASM binaries (stored as base64 JS files) back to .wasm during code generation — standard WASM distribution pattern for npm packages. | ai |
Versions (showing 19 of 19)
| Version | Deps | Published |
|---|---|---|
| 7.9.1 | 1 / 100 | |
| 7.9.0 | 1 / 100 | |
| 7.8.0 | 1 / 100 | |
| 7.7.0 | 1 / 100 | |
| 7.6.0 | 1 / 100 | |
| 7.5.0 | 1 / 100 | |
| 7.4.2 | 1 / 100 | |
| 7.4.1 | 1 / 100 | |
| 7.4.0 | 1 / 100 | |
| 7.3.0 | 1 / 98 | |
| 7.2.0 | 1 / 98 | |
| 7.1.0 | 1 / 98 | |
| 7.0.1 | 1 / 94 | |
| 7.0.0 | 1 / 94 | |
| 6.19.3 | 0 / 98 | |
| 6.19.2 | 0 / 98 | |
| 6.19.1 | 0 / 98 | |
| 6.19.0 | 0 / 98 | |
| 5.17.0 | 0 / 95 |
v7.9.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.9.0
21 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.5.0
19 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.4.1
19 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.