@supabase/pg-parser
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| npm-metadata | bundled-binaries | AI (npm-metadata): WASM build artifacts from documented libpg_query build pipeline, not opaque binaries. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Supabase team roster change, consistent with org-owned package. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Supabase team roster change, consistent with org-owned package. | ai |
Versions (showing 8 of 8)
| Version | Deps | Published |
|---|---|---|
| 0.1.7 | 0 / 16 | |
| 0.1.6 | 0 / 16 | |
| 0.1.5 | 0 / 16 | |
| 0.1.4 | 0 / 16 | |
| 0.1.3 | 1 / 15 | |
| 0.1.2 | 1 / 15 | |
| 0.1.1 | 1 / 15 | |
| 0.1.0 | 1 / 15 |
v0.1.5
3 findingsPackage contains compiled binaries that could be backdoors: • wasm/17/pg-parser.min.wasm • wasm/15/pg-parser.wasm • wasm/16/pg-parser.wasm • wasm/17/pg-parser.wasm
This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: gregnr.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.4
3 findingsPackage contains compiled binaries that could be backdoors: • wasm/17/pg-parser.min.wasm • wasm/15/pg-parser.wasm • wasm/16/pg-parser.wasm • wasm/17/pg-parser.wasm
This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: gregnr.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.0
2 findingsPackage contains compiled binaries that could be backdoors: • wasm/15/pg-parser.wasm • wasm/16/pg-parser.wasm • wasm/17/pg-parser.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.