← Home

@rightcapital/phpdoc-parser

TypeScript version of PHPDoc parser with support for intersection types and generics

6
Versions
MIT
License
Yes
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

rainxrighthao.zhengrightcapital-npm-publisher

Keywords

PHPPHPDocPHPDoc ParserParserTypeScriptPHPStanASTLexer

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@types/node AI (phantom-deps): TypeScript package; @types/node is a conventional type declaration, not a runtime import. ai
install-scripts install-script:preinstall AI (install-scripts): only-allow pnpm is a benign package-manager enforcement pattern; stable for this package. ai
phantom-deps phantom-dep:lodash AI (phantom-deps): lodash is explicitly declared as a runtime dependency in package.json; stable false positive. ai

Versions (showing 6 of 6)

Version Deps Published
0.6.2 1 / 19
0.6.1 1 / 18
0.6.0 1 / 18
0.5.3 3 / 16
0.5.0 3 / 16
0.4.133 3 / 16

v0.6.2

2 findings
HIGH Package has 'preinstall' script install-scripts

Script: npx only-allow pnpm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.4.133

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.