@wxn0brp/db
A modular, embedded database for developers who want control over their data storage.
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@wxn0brp/db-plugin-dir | AI (dependencies): First-party sub-package from same publisher's monorepo split, not third-party. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): Local admin GUI query evaluator, not remote/unrelated exfil target. | ai | |
| dependencies | unvetted-dep:@wxn0brp/db-resolver | AI (dependencies): Sibling package under same author/org, part of modular db toolkit. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): Internal monorepo split, not a third-party supply-chain addition. | ai | |
| typosquat | typosquat.levenshtein:qs | AI (typosquat): Scoped package @wxn0brp/db; Levenshtein match to 'qs' is a false positive with no impersonation intent. | ai | |
| phantom-deps | phantom-dep:json5 | AI (phantom-deps): json5 is a declared runtime dependency used in config parsing; phantom-dep heuristic misfires here. | ai | |
| typosquat | typosquat.levenshtein:pg | AI (typosquat): Scoped package @wxn0brp/db; Levenshtein match to 'pg' is a false positive with no impersonation intent. | ai |
Versions (showing 51 of 62)
| Version | Deps | Published |
|---|---|---|
| 0.112.0 | 5 / 3 | |
| 0.111.0 | 4 / 3 | |
| 0.110.0 | 4 / 3 | |
| 0.100.2 | 4 / 3 | |
| 0.100.1 | 3 / 3 | |
| 0.100.0 | 3 / 3 | |
| 0.90.1 | 3 / 3 | |
| 0.90.0 | 3 / 3 | |
| 0.80.0 | 3 / 3 | |
| 0.70.0 | 3 / 3 | |
| 0.60.0 | 3 / 3 | |
| 0.50.0 | 3 / 3 | |
| 0.42.0 | 3 / 3 | |
| 0.41.1 | 3 / 3 | |
| 0.41.0 | 3 / 3 | |
| 0.40.3 | 3 / 3 | |
| 0.40.2 | 3 / 3 | |
| 0.40.1 | 3 / 3 | |
| 0.40.0 | 3 / 3 | |
| 0.30.1 | 3 / 3 | |
| 0.30.0 | 3 / 3 | |
| 0.20.2 | 3 / 3 | |
| 0.20.1 | 3 / 3 | |
| 0.10.0 | 2 / 3 | |
| 0.9.1 | 2 / 3 | |
| 0.9.0 | 2 / 3 | |
| 0.8.2 | 2 / 3 | |
| 0.8.1 | 2 / 3 | |
| 0.8.0 | 3 / 3 | |
| 0.7.6 | 3 / 3 | |
| 0.7.5 | 3 / 3 | |
| 0.7.4 | 3 / 3 | |
| 0.7.3 | 3 / 3 | |
| 0.7.2 | 3 / 3 | |
| 0.7.1 | 3 / 3 | |
| 0.7.0 | 3 / 3 | |
| 0.6.0 | 3 / 3 | |
| 0.5.7 | 3 / 3 | |
| 0.5.6 | 3 / 3 | |
| 0.5.5 | 3 / 3 | |
| 0.5.4 | 3 / 3 | |
| 0.5.3 | 3 / 3 | |
| 0.5.2 | 3 / 3 | |
| 0.5.1 | 3 / 3 | |
| 0.4.2 | 3 / 3 | |
| 0.4.1 | 3 / 3 | |
| 0.4.0 | 3 / 3 | |
| 0.3.3 | 3 / 3 | |
| 0.3.2 | 3 / 3 | |
| 0.3.1 | 3 / 3 | |
| 0.3.0 | 3 / 3 |
v0.112.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.111.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.