← Home

@prisma/client

19
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

prismabotaqrlnwmadden-prismartbenfield

Keywords

ORMPrismaprisma2Prisma Clientclientqueryquery-builderdatabasedbJavaScriptJSTypeScriptTSSQLSQLitepgPostgresPostgreSQLCockroachDBMySQLMariaDBMSSQLSQL ServerSQLServerMongoDB

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff encoded-string-file:runtime/query_compiler_small_bg.sqlserver.wasm-base64.mjs AI (source-diff): Base64 WASM compiler bundle; benign. ai
source-diff encoded-string-file:runtime/query_compiler_fast_bg.postgresql.wasm-base64.mjs AI (source-diff): Base64 WASM compiler bundle; benign. ai
source-diff encoded-string-file:runtime/query_compiler_fast_bg.sqlite.wasm-base64.js AI (source-diff): Base64 WASM compiler bundle; benign. ai
source-diff encoded-string-file:runtime/query_compiler_fast_bg.sqlite.wasm-base64.mjs AI (source-diff): Base64 WASM compiler bundle; benign. ai
source-diff encoded-string-file:runtime/query_compiler_fast_bg.sqlserver.wasm-base64.js AI (source-diff): Base64 WASM compiler bundle; benign. ai
source-diff encoded-string-file:runtime/query_compiler_fast_bg.sqlserver.wasm-base64.mjs AI (source-diff): Base64 WASM compiler bundle; benign. ai
source-diff encoded-string-file:runtime/query_compiler_small_bg.cockroachdb.wasm-base64.js AI (source-diff): Base64 WASM compiler bundle; benign. ai
source-diff encoded-string-file:runtime/query_compiler_small_bg.cockroachdb.wasm-base64.mjs AI (source-diff): Base64 WASM compiler bundle; benign. ai
source-diff encoded-string-file:runtime/query_compiler_small_bg.mysql.wasm-base64.js AI (source-diff): Base64 WASM compiler bundle; benign. ai
source-diff encoded-string-file:runtime/query_compiler_small_bg.mysql.wasm-base64.mjs AI (source-diff): Base64 WASM compiler bundle; benign. ai
source-diff encoded-string-file:runtime/query_compiler_small_bg.postgresql.wasm-base64.js AI (source-diff): Base64 WASM compiler bundle; benign. ai
source-diff encoded-string-file:runtime/query_compiler_small_bg.postgresql.wasm-base64.mjs AI (source-diff): Base64 WASM compiler bundle; benign. ai
source-diff encoded-string-file:runtime/query_compiler_small_bg.sqlite.wasm-base64.js AI (source-diff): Base64 WASM compiler bundle; benign. ai
source-diff encoded-string-file:runtime/query_compiler_small_bg.sqlite.wasm-base64.mjs AI (source-diff): Base64 WASM compiler bundle; benign. ai
source-diff encoded-string-file:runtime/query_compiler_small_bg.sqlserver.wasm-base64.js AI (source-diff): Base64 WASM compiler bundle; benign. ai
source-diff encoded-string-file:runtime/query_compiler_fast_bg.cockroachdb.wasm-base64.mjs AI (source-diff): Base64-encoded WASM query-compiler bundle, core Prisma runtime artifact; stable per release. ai
source-diff encoded-string-file:runtime/query_compiler_fast_bg.mysql.wasm-base64.js AI (source-diff): Base64 WASM compiler bundle; benign. ai
source-diff encoded-string-file:runtime/query_compiler_fast_bg.mysql.wasm-base64.mjs AI (source-diff): Base64 WASM compiler bundle; benign. ai
source-diff encoded-string-file:runtime/query_compiler_fast_bg.postgresql.wasm-base64.js AI (source-diff): base64-encoded WASM query compiler; canonical Prisma runtime asset. ai
source-diff encoded-string-file:runtime/query_compiler_fast_bg.cockroachdb.wasm-base64.js AI (source-diff): base64-encoded WASM query compiler; canonical Prisma runtime asset, stable across versions. ai
semgrep semgrep:eval-usage AI (semgrep): eval-usage fires in minified engine-path error-message code; not dynamic eval of user input. Stable false positive for this bundled ORM package. ai
semgrep semgrep:child-process-spawn AI (semgrep): Postinstall spawns prisma generate; documented install flow for @prisma/client. ai
semgrep semgrep:env-spread AI (semgrep): Minified runtime reads env for DB connection config; standard ORM behavior, not secret exfiltration. ai
semgrep semgrep:api-obfuscation-reflect AI (semgrep): Reflect.get in WASM engine bindings generated by wasm-bindgen; not obfuscation. ai
source-diff large-new-source-files AI (source-diff): Prisma ships bundled runtime and WASM query engine files; large file counts are inherent to the package architecture. ai
install-scripts install-script:postinstall AI (install-scripts): Prisma's documented postinstall runs code generation via `node scripts/postinstall.js`; stable for this package. ai
publish-pattern dormant-publish AI (publish-pattern): Prisma publishes across multiple major version branches; gaps on one branch while others are active is normal. ai
semgrep semgrep:dynamic-require AI (semgrep): Dynamic require in generator-build loads WASM bundles from controlled, known paths as part of Prisma's documented WASM query compiler build pipeline. Not arbitrary module loading. ai
semgrep semgrep:child-process-import AI (semgrep): Prisma's generator legitimately uses child_process to invoke native engine binaries during schema generation. Expected behavior for a database ORM with native binary components. ai
semgrep semgrep:hex-decode AI (semgrep): False positive on minified runtime code; sample shows stack trace parsing regexes, not hex payload decoding. ai
dependencies unvetted-dep:@prisma/client-runtime-utils AI (dependencies): First-party Prisma monorepo package at matching version (7.8.0); not a third-party unvetted dependency. ai
semgrep semgrep:base64-decode AI (semgrep): Base64 decoding converts WASM binaries (stored as base64 JS files) back to .wasm during code generation — standard WASM distribution pattern for npm packages. ai

Versions (showing 19 of 19)

Version Deps Published
7.9.1 1 / 100
7.9.0 1 / 100
7.8.0 1 / 100
7.7.0 1 / 100
7.6.0 1 / 100
7.5.0 1 / 100
7.4.2 1 / 100
7.4.1 1 / 100
7.4.0 1 / 100
7.3.0 1 / 98
7.2.0 1 / 98
7.1.0 1 / 98
7.0.1 1 / 94
7.0.0 1 / 94
6.19.3 0 / 98
6.19.2 0 / 98
6.19.1 0 / 98
6.19.0 0 / 98
5.17.0 0 / 95

v7.9.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.9.0

21 findings
HIGH Long encoded string in modified file: runtime/query_compiler_fast_bg.cockroachdb.wasm-base64.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_fast_bg.cockroachdb.wasm-base64.mjs source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_fast_bg.mysql.wasm-base64.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_fast_bg.mysql.wasm-base64.mjs source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_fast_bg.postgresql.wasm-base64.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_fast_bg.postgresql.wasm-base64.mjs source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_fast_bg.sqlite.wasm-base64.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_fast_bg.sqlite.wasm-base64.mjs source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_fast_bg.sqlserver.wasm-base64.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_fast_bg.sqlserver.wasm-base64.mjs source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_small_bg.cockroachdb.wasm-base64.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_small_bg.cockroachdb.wasm-base64.mjs source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_small_bg.mysql.wasm-base64.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_small_bg.mysql.wasm-base64.mjs source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_small_bg.postgresql.wasm-base64.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_small_bg.postgresql.wasm-base64.mjs source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_small_bg.sqlite.wasm-base64.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_small_bg.sqlite.wasm-base64.mjs source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_small_bg.sqlserver.wasm-base64.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_small_bg.sqlserver.wasm-base64.mjs source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.5.0

19 findings
HIGH Long encoded string in modified file: runtime/query_compiler_fast_bg.cockroachdb.wasm-base64.mjs source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_fast_bg.mysql.wasm-base64.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_fast_bg.mysql.wasm-base64.mjs source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_fast_bg.postgresql.wasm-base64.mjs source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_fast_bg.sqlite.wasm-base64.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_fast_bg.sqlite.wasm-base64.mjs source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_fast_bg.sqlserver.wasm-base64.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_fast_bg.sqlserver.wasm-base64.mjs source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_small_bg.cockroachdb.wasm-base64.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_small_bg.cockroachdb.wasm-base64.mjs source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_small_bg.mysql.wasm-base64.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_small_bg.mysql.wasm-base64.mjs source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_small_bg.postgresql.wasm-base64.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_small_bg.postgresql.wasm-base64.mjs source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_small_bg.sqlite.wasm-base64.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_small_bg.sqlite.wasm-base64.mjs source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_small_bg.sqlserver.wasm-base64.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_small_bg.sqlserver.wasm-base64.mjs source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.4.1

19 findings
HIGH Long encoded string in modified file: runtime/query_compiler_fast_bg.cockroachdb.wasm-base64.mjs source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_fast_bg.mysql.wasm-base64.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_fast_bg.mysql.wasm-base64.mjs source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_fast_bg.postgresql.wasm-base64.mjs source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_fast_bg.sqlite.wasm-base64.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_fast_bg.sqlite.wasm-base64.mjs source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_fast_bg.sqlserver.wasm-base64.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_fast_bg.sqlserver.wasm-base64.mjs source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_small_bg.cockroachdb.wasm-base64.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_small_bg.cockroachdb.wasm-base64.mjs source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_small_bg.mysql.wasm-base64.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_small_bg.mysql.wasm-base64.mjs source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_small_bg.postgresql.wasm-base64.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_small_bg.postgresql.wasm-base64.mjs source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_small_bg.sqlite.wasm-base64.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_small_bg.sqlite.wasm-base64.mjs source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_small_bg.sqlserver.wasm-base64.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: runtime/query_compiler_small_bg.sqlserver.wasm-base64.mjs source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.