← Home

@wp-playground/storage

Bindings for storing WordPress Playground on different backends.

31
Versions
GPL-2.0-or-later
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

bgrgicakadamzielbrandonpayton-a8csejasdanielbachhuberyannickdecatjanjakesakirk

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:isomorphic-git-internals-oTG5Z0SU.cjs AI (source-diff): Bundled git library code, base64/network utility functions, no fetch-exec malware behavior. ai
source-diff obfuscated-file:isomorphic-git-internals-oTG5Z0SU.cjs AI (source-diff): Minified bundle output (vite/rollup), not true obfuscation; matches isomorphic-git internals. ai
phantom-deps phantom-dep:isomorphic-git AI (phantom-deps): isomorphic-git is used internally via bundled internals, referenced not directly imported. ai
source-diff net-exec-file:isomorphic-git-internals-DwkB8rfP.js AI (source-diff): Same bundled isomorphic-git internals; no concrete malicious behavior shown. ai
phantom-deps phantom-dep:selfsigned AI (phantom-deps): Newly added runtime dep; config-referenced pattern consistent with package. ai
phantom-deps phantom-dep:fs-ext AI (phantom-deps): Optional platform-specific dependency; stable for this package. ai
phantom-deps phantom-dep:yargs AI (phantom-deps): Config-referenced dependency; stable pattern for this package. ai
phantom-deps phantom-dep:ws AI (phantom-deps): Config-referenced dependency; stable pattern for this package. ai
phantom-deps phantom-dep:wasm-feature-detect AI (phantom-deps): Config-referenced dependency; stable pattern for this package. ai
phantom-deps phantom-dep:@php-wasm/universal AI (phantom-deps): Platform-specific binary package; stable for this package. ai
phantom-deps phantom-dep:@php-wasm/web AI (phantom-deps): Platform-specific binary package; stable for this package. ai
phantom-deps phantom-dep:express AI (phantom-deps): Config-referenced dependency; stable pattern for this package. ai
dependencies unvetted-dep:minimisted AI (dependencies): minimisted is a phantom dep (not directly imported); stable false positive for this package. ai
semgrep semgrep:hex-decode AI (semgrep): Fires on minified bundle; snippet shows git object parsing, not actual hex decoding of a payload. ai
phantom-deps phantom-dep:readable-stream AI (phantom-deps): Bundled monorepo package; deps are bundled into index.cjs and may not appear as direct imports. ai
phantom-deps phantom-dep:clean-git-ref AI (phantom-deps): Bundled monorepo package; deps are bundled into index.cjs and may not appear as direct imports. ai
phantom-deps phantom-dep:simple-get AI (phantom-deps): Bundled monorepo package; deps are bundled into index.cjs and may not appear as direct imports. ai
phantom-deps phantom-dep:minimisted AI (phantom-deps): Bundled monorepo package; deps are bundled into index.cjs and may not appear as direct imports. ai
phantom-deps phantom-dep:async-lock AI (phantom-deps): Bundled monorepo package; deps are bundled into index.cjs and may not appear as direct imports. ai
phantom-deps phantom-dep:sha.js AI (phantom-deps): Bundled monorepo package; deps are bundled into index.cjs and may not appear as direct imports. ai
phantom-deps phantom-dep:ignore AI (phantom-deps): Bundled monorepo package; deps are bundled into index.cjs and may not appear as direct imports. ai
phantom-deps phantom-dep:diff3 AI (phantom-deps): Bundled monorepo package; deps are bundled into index.cjs and may not appear as direct imports. ai
phantom-deps phantom-dep:pify AI (phantom-deps): Bundled monorepo package; deps are bundled into index.cjs and may not appear as direct imports. ai
phantom-deps phantom-dep:ini AI (phantom-deps): Bundled monorepo package; deps are bundled into index.cjs and may not appear as direct imports. ai
bogus-package bogus-package AI (bogus-package): Official WordPress monorepo package; sparse README/keywords are expected for a scoped utility package. ai

Versions (showing 31 of 31)

Version Deps Published
3.1.47 8 / 0
3.1.46 8 / 0
3.1.45 8 / 0
3.1.44 8 / 0
3.1.43 7 / 0
3.1.42 7 / 0
3.1.41 7 / 0
3.1.40 7 / 0
3.1.39 7 / 0
3.1.38 7 / 0
3.1.36 7 / 0
3.1.35 7 / 0
3.1.34 7 / 0
3.1.33 7 / 0
3.1.32 7 / 0
3.1.31 7 / 0
3.1.30 7 / 0
3.1.29 7 / 0
3.1.22 17 / 0
3.1.21 17 / 0
3.1.20 17 / 0
3.1.19 17 / 0
3.1.18 17 / 0
3.1.15 17 / 0
3.1.14 17 / 0
3.0.54 23 / 0
3.0.32 23 / 0
3.0.17 23 / 0
3.0.13 23 / 0
3.0.2 23 / 0
3.0.1 23 / 0

v3.1.47

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.46

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.45

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.44

4 findings
HIGH New obfuscated file: isomorphic-git-internals-oTG5Z0SU.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: isomorphic-git-internals-oTG5Z0SU.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: isomorphic-git-internals-DwkB8rfP.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.43

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.