@prisma/studio-core
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/data/sqlite-core/index.js | AI (source-diff): tsup esm bundle; benign. | ai | |
| source-diff | obfuscated-file:dist/data/postgresjs/index.cjs | AI (source-diff): esbuild bundle output; benign. | ai | |
| source-diff | obfuscated-file:dist/data/ppg/index.cjs | AI (source-diff): esbuild bundle; base64 is Prisma schema, not payload. | ai | |
| source-diff | obfuscated-file:dist/data/mysql-core/index.js | AI (source-diff): tsup esm bundle with chunk imports; benign. | ai | |
| source-diff | obfuscated-file:dist/data/mysql2/index.js | AI (source-diff): tsup esm bundle; benign. | ai | |
| source-diff | obfuscated-file:dist/data/node-sqlite/index.js | AI (source-diff): tsup esm bundle; benign. | ai | |
| source-diff | obfuscated-file:dist/data/postgresjs/index.js | AI (source-diff): tsup esm bundle; benign. | ai | |
| source-diff | obfuscated-file:dist/data/ppg/index.js | AI (source-diff): tsup esm bundle; benign. | ai | |
| source-diff | obfuscated-file:dist/data/sqljs/index.cjs | AI (source-diff): tsup bundled sqljs executor, sourcemap-backed. | ai | |
| source-diff | obfuscated-file:dist/data/mysql2/index.cjs | AI (source-diff): tsup bundled DB executor, sourcemap-backed, not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/data/node-sqlite/index.cjs | AI (source-diff): tsup bundled SQLite executor with inline sourcemap. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Vendored DB adapter bundles inflate dist; expected for this package. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Bundled adapter files; benign build artifacts. | ai | |
| source-diff | obfuscated-file:dist/data/mysql-core/index.cjs | AI (source-diff): tsup/esbuild-minified bundle with source maps; build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/data/sqlite-core/index.cjs | AI (source-diff): Minified esbuild bundle, legible named exports; build output. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Scoped official Prisma package with huge download count; metadata gaps are cosmetic. | ai | |
| phantom-deps | phantom-dep:typescript | AI (phantom-deps): Used for typecheck/build, not direct import. | ai | |
| npm-metadata | suspicious-initial-version | AI (npm-metadata): Official @prisma package; 0.0.0 is a monorepo placeholder version, not throwaway malware. | ai | |
| phantom-deps | phantom-dep:tsx | AI (phantom-deps): Build tool used via config, not direct import. | ai | |
| source-diff | encoded-string-file:dist/ui/index.js | AI (source-diff): Radix UI warning strings in bundled output; not obfuscated payloads. | ai | |
| phantom-deps | phantom-dep:d3-array | AI (phantom-deps): Transitive of @visx deps, bundled at build time. | ai | |
| phantom-deps | phantom-dep:d3-shape | AI (phantom-deps): Transitive of @visx deps, bundled at build time. | ai | |
| phantom-deps | phantom-dep:@visx/grid | AI (phantom-deps): Bundled by tsup; declared for peer/transitive resolution. | ai | |
| phantom-deps | phantom-dep:@visx/curve | AI (phantom-deps): Bundled by tsup; declared for peer/transitive resolution. | ai | |
| phantom-deps | phantom-dep:@visx/event | AI (phantom-deps): Bundled by tsup; declared for peer/transitive resolution. | ai | |
| phantom-deps | phantom-dep:@visx/group | AI (phantom-deps): Bundled by tsup; declared for peer/transitive resolution. | ai | |
| phantom-deps | phantom-dep:@visx/scale | AI (phantom-deps): Bundled by tsup; declared for peer/transitive resolution. | ai | |
| phantom-deps | phantom-dep:@visx/shape | AI (phantom-deps): Bundled by tsup; declared for peer/transitive resolution. | ai | |
| phantom-deps | phantom-dep:@visx/responsive | AI (phantom-deps): Bundled by tsup; declared for peer/transitive resolution. | ai | |
| phantom-deps | phantom-dep:@radix-ui/react-toggle | AI (phantom-deps): Bundled by tsup; declared as runtime dep. | ai | |
| source-diff | encoded-string-file:dist/ui/index.cjs | AI (source-diff): Radix UI warning strings in bundled output; not obfuscated payloads. | ai | |
| phantom-deps | phantom-dep:elkjs | AI (phantom-deps): Bundled by tsup at build time; declared for downstream resolution. | ai | |
| phantom-deps | phantom-dep:next-themes | AI (phantom-deps): Used in UI components; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@radix-ui/react-dialog | AI (phantom-deps): Core UI component; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@radix-ui/react-select | AI (phantom-deps): Core UI component; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@radix-ui/react-checkbox | AI (phantom-deps): Core UI component; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:zod | AI (phantom-deps): Used in data validation; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:dayjs | AI (phantom-deps): Used in data modules; stable pattern for this package. | ai |
Versions (showing 17 of 17)
| Version | Deps | Published |
|---|---|---|
| 0.33.0 | 11 / 87 | |
| 0.32.0 | 11 / 87 | |
| 0.31.2 | 11 / 86 | |
| 0.31.1 | 11 / 86 | |
| 0.31.0 | 11 / 86 | |
| 0.30.0 | 11 / 86 | |
| 0.29.0 | 11 / 86 | |
| 0.28.0 | 11 / 86 | |
| 0.27.3 | 2 / 82 | |
| 0.26.0 | 1 / 81 | |
| 0.25.2 | 1 / 81 | |
| 0.25.0 | 0 / 78 | |
| 0.10.0 | 0 / 59 | |
| 0.6.0 | 0 / 57 | |
| 0.2.0 | 24 / 21 | |
| 0.1.0 | 21 / 21 | |
| 0.0.0 | 3 / 0 |
v0.33.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.32.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.26.0
14 findingsThis version was published by a different npm account than previous versions on 2026-03-19. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.25.2
14 findingsThis version was published by a different npm account than previous versions on 2026-03-18. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.25.0
14 findingsThis version was published by a different npm account than previous versions on 2026-03-12. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.10.0
14 findingsThis version was published by a different npm account than previous versions on 2025-12-24. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.0
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.