← Home

@prisma/dev

51
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

prismabotaqrlntylerhogarthankur-datta-007

Keywords

prismapostgresacceleratelocaldevelopmentdevtesting

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/accelerate-HWGEFOM5.js AI (source-diff): tsup-bundled output, readable first-party code; not obfuscation. ai
source-diff obfuscated-file:dist/engine-YTEOPVUP.js AI (source-diff): tsup ESM bundle output, not obfuscation; Prisma query-engine logic. ai
source-diff obfuscated-file:dist/accelerate-45DUGMGZ.js AI (source-diff): tsup ESM bundle output, not obfuscation; legitimate Prisma accelerate logic. ai
npm-metadata bundled-binaries AI (npm-metadata): pglite.wasm is the embedded Postgres runtime, expected for this package. ai
install-scripts install-script:postinstall AI (install-scripts): Local asset-generation script for PGlite/bun runtime; consistent with package function. ai
npm-metadata suspicious-initial-version AI (npm-metadata): Prisma uses 0.0.0 as a placeholder version convention across many packages; not a malware signal here. ai
module-system module-system:dual AI (module-system): Dual module system is intentional for this package. ai
provenance missing-githead AI (provenance): Large org CI pipeline change; scoped @prisma package with extensive history. ai
phantom-deps phantom-dep:valibot AI (phantom-deps): Declared dep; phantom-dep heuristic fires on bundled packages. ai
source-diff obfuscated-file:dist/accelerate-5FDEK4T6.js AI (source-diff): tsup-bundled output for hono/valibot accelerate proxy; readable imports, no obfuscation. ai
source-diff obfuscated-file:dist/engine-XP6YJ63T.js AI (source-diff): tsup-bundled query-engine wrapper; readable imports, spawns prisma engine binary as expected. ai
phantom-deps phantom-dep:pglite-server AI (phantom-deps): Referenced in config files as expected for this local Postgres dev-server package. ai
phantom-deps phantom-dep:@electric-sql/pglite AI (phantom-deps): Runtime dep used via config/dynamic wiring; stable false positive for this package. ai
phantom-deps phantom-dep:@prisma/get-platform AI (phantom-deps): Same-org dep; stable false positive for Prisma packages. ai
phantom-deps phantom-dep:foreground-child AI (phantom-deps): Declared runtime dep; bundled output pattern. ai
phantom-deps phantom-dep:@hono/node-server AI (phantom-deps): Declared runtime dep; bundled output pattern. ai
phantom-deps phantom-dep:http-status-codes AI (phantom-deps): Declared runtime dep; bundled output pattern. ai
phantom-deps phantom-dep:hono AI (phantom-deps): Declared runtime dep; bundled ESM package may not show direct imports to static analyzer. ai
phantom-deps phantom-dep:pako AI (phantom-deps): Declared runtime dep; bundled output pattern. ai
phantom-deps phantom-dep:pathe AI (phantom-deps): Declared runtime dep; bundled output pattern. ai
phantom-deps phantom-dep:std-env AI (phantom-deps): Declared runtime dep; bundled output pattern. ai
phantom-deps phantom-dep:env-paths AI (phantom-deps): Declared runtime dep; bundled output pattern. ai
phantom-deps phantom-dep:proper-lockfile AI (phantom-deps): Declared runtime dep; bundled output pattern. ai
phantom-deps phantom-dep:@electric-sql/pglite-tools AI (phantom-deps): Declared runtime dep; bundled output pattern. ai
phantom-deps phantom-dep:@electric-sql/pglite-socket AI (phantom-deps): Declared runtime dep; bundled output pattern. ai
phantom-deps phantom-dep:read-last-lines-ts AI (phantom-deps): Package is a declared runtime dep used indirectly via bundled dist; phantom-dep heuristic is a false positive here. ai
publish-pattern dormant-publish AI (publish-pattern): @prisma scoped package with 830 versions; dormancy is normal release cadence variation. ai
source-diff obfuscated-file:dist/accelerate-UHQZHRYG.js AI (source-diff): Minified tsup bundle output with readable imports; not obfuscation. Stable for this package. ai
source-diff obfuscated-file:dist/accelerate-EEKAFGN3.js AI (source-diff): Minified ESM bundle from tsup; content is readable and matches declared deps. Normal for this package. ai
source-diff obfuscated-file:dist/accelerate-ZET2GIPN.js AI (source-diff): Minified ESM bundle output from tsup; readable imports confirm legitimate build artifact, not obfuscation. ai
source-diff obfuscated-file:dist/accelerate-HABH6RJU.js AI (source-diff): Standard tsup/esbuild bundle output; sample shows legitimate Prisma/Hono imports, not obfuscation. ai
typosquat typosquat.levenshtein:ajv AI (typosquat): Scoped @prisma package; Levenshtein match to 'ajv' is a false positive with no semantic relationship. ai

Versions (showing 51 of 52)

View all versions
Version Deps Published
0.24.14 15 / 13
0.24.13 17 / 13
0.24.12 17 / 13
0.24.11 17 / 13
0.24.10 17 / 13
0.24.9 17 / 13
0.24.8 17 / 13
0.24.7 17 / 13
0.24.6 17 / 13
0.24.5 17 / 12
0.24.4 17 / 12
0.24.3 17 / 12
0.24.2 17 / 12
0.24.1 17 / 12
0.24.0 17 / 12
0.23.1 17 / 12
0.23.0 17 / 12
0.22.3 17 / 12
0.22.2 17 / 12
0.22.1 17 / 12
0.22.0 17 / 12
0.21.0 17 / 12
0.20.0 17 / 10
0.19.1 17 / 10
0.19.0 17 / 10
0.18.0 17 / 10
0.17.0 17 / 10
0.16.1 17 / 10
0.16.0 17 / 10
0.15.0 17 / 10
0.14.0 17 / 10
0.13.0 17 / 10
0.12.0 18 / 10
0.11.1 17 / 10
0.11.0 16 / 10
0.10.0 15 / 10
0.9.0 17 / 10
0.8.0 15 / 10
0.7.1 15 / 10
0.7.0 15 / 10
0.6.1 15 / 10
0.6.0 16 / 9
0.5.0 16 / 9
0.4.0 15 / 9
0.3.0 15 / 9
0.2.0 14 / 8
0.1.1 8 / 7
0.1.0 8 / 7
0.0.3 4 / 5
0.0.2 4 / 5
0.0.1 3 / 5

v0.24.14

3 findings
HIGH New obfuscated file: dist/accelerate-45DUGMGZ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/engine-YTEOPVUP.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.24.2

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/runtime-assets/initdb.wasm • dist/runtime-assets/pglite.wasm

HIGH New obfuscated file: dist/accelerate-HWGEFOM5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.24.1

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/runtime-assets/initdb.wasm • dist/runtime-assets/pglite.wasm

HIGH New obfuscated file: dist/accelerate-HWGEFOM5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.24.0

3 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/runtime-assets/initdb.wasm • dist/runtime-assets/pglite.wasm

HIGH New obfuscated file: dist/accelerate-HWGEFOM5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.23.1

2 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/runtime-assets/initdb.wasm • dist/runtime-assets/pglite.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.23.0

3 findings
HIGH Package has 'postinstall' script install-scripts

Script: node -e "const { existsSync } = require('fs'); const { execFileSync } = require('child_process'); if (existsSync('./scripts/generate-bun-runtime-assets.mjs')) { execFileSync(process.execPath, ['./scripts/generate-bun-runtime-assets.mjs'], { stdio: 'inherit' }); }"

HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/runtime-assets/initdb.wasm • dist/runtime-assets/pglite.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.22.3

3 findings
HIGH Package has 'postinstall' script install-scripts

Script: node ./scripts/generate-bun-runtime-assets.mjs

HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/runtime-assets/pglite.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.