← Home

@prisma/debug

20
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

prismabotaqrlnwmadden-prismartbenfield

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Prisma migrated publishing from prismabot to GitHub Actions with SLSA attestation; this is a documented org-level transition, not a compromise. ai
maintainer-change maintainer-removed AI (maintainer-change): Maintainer removals are consistent with Prisma's org restructuring to CI-based publishing; SLSA attestation confirms official repo origin. ai
publish-pattern dormant-publish AI (publish-pattern): Internal Prisma packages may not be published independently for long periods; SLSA attestation and official repo confirm legitimacy. ai

Versions (showing 20 of 20)

Version Deps Published
7.9.1 0 / 3
7.9.0 0 / 3
7.8.0 0 / 3
7.7.0 0 / 3
7.6.0 0 / 3
7.5.0 0 / 3
7.4.2 0 / 6
7.4.1 0 / 6
7.4.0 0 / 6
7.3.0 0 / 6
7.2.0 0 / 6
7.1.0 0 / 6
7.0.1 0 / 6
7.0.0 0 / 6
6.19.3 0 / 6
6.19.2 0 / 6
6.19.1 0 / 6
6.19.0 0 / 6
5.22.0 0 / 8
5.17.0 0 / 8

v7.9.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.9.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.22.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.