@wp-playground/storage
Bindings for storing WordPress Playground on different backends.
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:isomorphic-git-internals-oTG5Z0SU.cjs | AI (source-diff): Bundled git library code, base64/network utility functions, no fetch-exec malware behavior. | ai | |
| source-diff | obfuscated-file:isomorphic-git-internals-oTG5Z0SU.cjs | AI (source-diff): Minified bundle output (vite/rollup), not true obfuscation; matches isomorphic-git internals. | ai | |
| phantom-deps | phantom-dep:isomorphic-git | AI (phantom-deps): isomorphic-git is used internally via bundled internals, referenced not directly imported. | ai | |
| source-diff | net-exec-file:isomorphic-git-internals-DwkB8rfP.js | AI (source-diff): Same bundled isomorphic-git internals; no concrete malicious behavior shown. | ai | |
| phantom-deps | phantom-dep:selfsigned | AI (phantom-deps): Newly added runtime dep; config-referenced pattern consistent with package. | ai | |
| phantom-deps | phantom-dep:fs-ext | AI (phantom-deps): Optional platform-specific dependency; stable for this package. | ai | |
| phantom-deps | phantom-dep:yargs | AI (phantom-deps): Config-referenced dependency; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:ws | AI (phantom-deps): Config-referenced dependency; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:wasm-feature-detect | AI (phantom-deps): Config-referenced dependency; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@php-wasm/universal | AI (phantom-deps): Platform-specific binary package; stable for this package. | ai | |
| phantom-deps | phantom-dep:@php-wasm/web | AI (phantom-deps): Platform-specific binary package; stable for this package. | ai | |
| phantom-deps | phantom-dep:express | AI (phantom-deps): Config-referenced dependency; stable pattern for this package. | ai | |
| dependencies | unvetted-dep:minimisted | AI (dependencies): minimisted is a phantom dep (not directly imported); stable false positive for this package. | ai | |
| semgrep | semgrep:hex-decode | AI (semgrep): Fires on minified bundle; snippet shows git object parsing, not actual hex decoding of a payload. | ai | |
| phantom-deps | phantom-dep:readable-stream | AI (phantom-deps): Bundled monorepo package; deps are bundled into index.cjs and may not appear as direct imports. | ai | |
| phantom-deps | phantom-dep:clean-git-ref | AI (phantom-deps): Bundled monorepo package; deps are bundled into index.cjs and may not appear as direct imports. | ai | |
| phantom-deps | phantom-dep:simple-get | AI (phantom-deps): Bundled monorepo package; deps are bundled into index.cjs and may not appear as direct imports. | ai | |
| phantom-deps | phantom-dep:minimisted | AI (phantom-deps): Bundled monorepo package; deps are bundled into index.cjs and may not appear as direct imports. | ai | |
| phantom-deps | phantom-dep:async-lock | AI (phantom-deps): Bundled monorepo package; deps are bundled into index.cjs and may not appear as direct imports. | ai | |
| phantom-deps | phantom-dep:sha.js | AI (phantom-deps): Bundled monorepo package; deps are bundled into index.cjs and may not appear as direct imports. | ai | |
| phantom-deps | phantom-dep:ignore | AI (phantom-deps): Bundled monorepo package; deps are bundled into index.cjs and may not appear as direct imports. | ai | |
| phantom-deps | phantom-dep:diff3 | AI (phantom-deps): Bundled monorepo package; deps are bundled into index.cjs and may not appear as direct imports. | ai | |
| phantom-deps | phantom-dep:pify | AI (phantom-deps): Bundled monorepo package; deps are bundled into index.cjs and may not appear as direct imports. | ai | |
| phantom-deps | phantom-dep:ini | AI (phantom-deps): Bundled monorepo package; deps are bundled into index.cjs and may not appear as direct imports. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Official WordPress monorepo package; sparse README/keywords are expected for a scoped utility package. | ai |
Versions (showing 31 of 31)
| Version | Deps | Published |
|---|---|---|
| 3.1.47 | 8 / 0 | |
| 3.1.46 | 8 / 0 | |
| 3.1.45 | 8 / 0 | |
| 3.1.44 | 8 / 0 | |
| 3.1.43 | 7 / 0 | |
| 3.1.42 | 7 / 0 | |
| 3.1.41 | 7 / 0 | |
| 3.1.40 | 7 / 0 | |
| 3.1.39 | 7 / 0 | |
| 3.1.38 | 7 / 0 | |
| 3.1.36 | 7 / 0 | |
| 3.1.35 | 7 / 0 | |
| 3.1.34 | 7 / 0 | |
| 3.1.33 | 7 / 0 | |
| 3.1.32 | 7 / 0 | |
| 3.1.31 | 7 / 0 | |
| 3.1.30 | 7 / 0 | |
| 3.1.29 | 7 / 0 | |
| 3.1.22 | 17 / 0 | |
| 3.1.21 | 17 / 0 | |
| 3.1.20 | 17 / 0 | |
| 3.1.19 | 17 / 0 | |
| 3.1.18 | 17 / 0 | |
| 3.1.15 | 17 / 0 | |
| 3.1.14 | 17 / 0 | |
| 3.0.54 | 23 / 0 | |
| 3.0.32 | 23 / 0 | |
| 3.0.17 | 23 / 0 | |
| 3.0.13 | 23 / 0 | |
| 3.0.2 | 23 / 0 | |
| 3.0.1 | 23 / 0 |
v3.1.47
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.1.46
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.1.45
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.1.44
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.1.43
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.