← Home

@prisma/client-common

This package is intended for Prisma's internal use

18
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

prismabotaqrlntylerhogarthankur-datta-007

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Prisma migrated publishing to GitHub Actions CI with SLSA attestation; this is the expected new publisher for all future versions. ai
publish-pattern dormant-publish AI (publish-pattern): Dormancy reflects major version development cycle (v6→v7); SLSA provenance confirms legitimate CI publish. ai
phantom-deps phantom-dep:@prisma/internals AI (phantom-deps): Same-org internal dependency; phantom-dep heuristic is a stable false positive for this Prisma monorepo package. ai
bogus-package bogus-package AI (bogus-package): Intentionally internal package; sparse README and no keywords are expected and stable across versions. ai

Versions (showing 18 of 18)

Version Deps Published
7.9.1 6 / 0
7.9.0 6 / 0
7.8.0 6 / 0
7.7.0 6 / 0
7.6.0 6 / 0
7.5.0 6 / 0
7.4.2 6 / 0
7.4.1 6 / 0
7.4.0 6 / 0
7.3.0 5 / 0
7.2.0 5 / 0
7.1.0 5 / 0
7.0.1 5 / 0
7.0.0 5 / 0
6.19.3 5 / 0
6.19.2 5 / 0
6.19.1 5 / 0
6.19.0 5 / 0

v7.9.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.9.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.