@tursodatabase/sync
<p align="center"> <h1 align="center">Turso Database for JavaScript in Node</h1> </p>
15
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
penbergglaubercosta
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| typosquat | typosquat.levenshtein:async | AI (typosquat): @tursodatabase/sync is a native binding for Turso DB, not a typosquat of 'async'; scoped name makes impersonation implausible. | ai | |
| semgrep | semgrep:child-process-execsync | AI (semgrep): Standard napi-rs musl detection pattern using 'ldd --version'; hardcoded command, not user-controlled. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): child_process used only for musl detection via hardcoded ldd command; stable pattern for this native binding. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): NAPI_RS_NATIVE_LIBRARY_PATH override is a documented napi-rs escape hatch for custom native library paths. | ai |
Versions (showing 15 of 15)
| Version | Deps | Published |
|---|---|---|
| 0.7.1 | 2 / 4 | |
| 0.7.0 | 2 / 4 | |
| 0.6.1 | 2 / 4 | |
| 0.6.0 | 2 / 4 | |
| 0.5.3 | 2 / 4 | |
| 0.5.2 | 2 / 4 | |
| 0.4.1 | 2 / 4 | |
| 0.3.2 | 2 / 4 | |
| 0.3.1 | 2 / 4 | |
| 0.3.0 | 2 / 4 | |
| 0.2.2 | 2 / 4 | |
| 0.2.1 | 2 / 4 | |
| 0.2.0 | 2 / 4 | |
| 0.1.5 | 1 / 5 | |
| 0.1.4 | 1 / 5 |
v0.7.1
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.0
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.