← Home

@prisma/migrate

18
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

prismabotaqrlnwmadden-prismartbenfield

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff encoded-string-file:dist/utils/setupMongo.js AI (source-diff): Gzip-compressed saslprep code-points data bundled from node_modules, not a hidden payload. ai
maintainer-change maintainer-added AI (maintainer-change): New maintainers are Prisma-affiliated (wmadden-prisma) in official monorepo package. ai
dependencies unvetted-dep:@prisma/engines-version AI (dependencies): Standard internal Prisma engines versioning package; stable dependency across all @prisma/* releases. ai
phantom-deps phantom-dep:@prisma/get-platform AI (phantom-deps): Same-org sibling dep in Prisma monorepo; phantom-dep heuristic is a stable false positive here. ai
phantom-deps phantom-dep:@prisma/client-generator-registry AI (phantom-deps): Same-org sibling dep in Prisma monorepo; phantom-dep heuristic is a stable false positive here. ai

Versions (showing 18 of 18)

Version Deps Published
7.9.1 9 / 28
7.9.0 9 / 28
7.8.0 9 / 28
7.7.0 9 / 28
7.6.0 9 / 28
7.5.0 9 / 28
7.4.2 9 / 28
7.4.1 9 / 28
7.4.0 9 / 28
7.3.0 9 / 28
7.2.0 9 / 28
7.1.0 9 / 28
7.0.1 9 / 28
7.0.0 9 / 28
6.19.3 9 / 28
6.19.2 9 / 28
6.19.1 9 / 28
6.19.0 9 / 28

v7.9.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.9.0

2 findings
HIGH Long encoded string in modified file: dist/utils/setupMongo.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.6.0

2 findings
HIGH Long encoded string in modified file: dist/utils/setupMongo.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.5.0

2 findings
HIGH Long encoded string in modified file: dist/utils/setupMongo.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.4.2

2 findings
HIGH Long encoded string in modified file: dist/utils/setupMongo.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.4.1

2 findings
HIGH Long encoded string in modified file: dist/utils/setupMongo.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.4.0

2 findings
HIGH Long encoded string in modified file: dist/utils/setupMongo.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.3.0

2 findings
HIGH Long encoded string in modified file: dist/utils/setupMongo.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.19.2

2 findings
HIGH Long encoded string in modified file: dist/utils/setupMongo.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.19.1

2 findings
HIGH Long encoded string in modified file: dist/utils/setupMongo.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.19.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.