← Home

libsql

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

penberg

Keywords

libsql

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern new-deps-added AI (publish-pattern): Same-org platform optional binaries for native module, not third-party deps. ai
phantom-deps phantom-dep:@libsql/win32-arm64-msvc AI (phantom-deps): Platform-specific optional binary loaded via dynamic require, not static import. ai
dependencies unvetted-dep:@libsql/win32-arm64-msvc AI (dependencies): Official neon-rs platform binary package, same org/version as main package. ai
dependencies unvetted-dep:@libsql/darwin-arm64 AI (dependencies): Official platform binary sibling package. ai
dependencies unvetted-dep:@libsql/linux-x64-gnu AI (dependencies): Official platform binary sibling package. ai
dependencies unvetted-dep:@libsql/linux-x64-musl AI (dependencies): Official platform binary sibling package. ai
dependencies unvetted-dep:@libsql/linux-arm64-gnu AI (dependencies): Official platform binary sibling package. ai
phantom-deps phantom-dep:@libsql/darwin-x64 AI (phantom-deps): Platform-specific optional binary, loaded dynamically not imported. ai
phantom-deps phantom-dep:@libsql/darwin-arm64 AI (phantom-deps): Platform-specific optional binary. ai
phantom-deps phantom-dep:@libsql/linux-x64-gnu AI (phantom-deps): Platform-specific optional binary. ai
phantom-deps phantom-dep:@libsql/linux-x64-musl AI (phantom-deps): Platform-specific optional binary. ai
phantom-deps phantom-dep:@libsql/win32-x64-msvc AI (phantom-deps): Platform-specific optional binary. ai
phantom-deps phantom-dep:@libsql/linux-arm64-gnu AI (phantom-deps): Platform-specific optional binary. ai
phantom-deps phantom-dep:libsql AI (phantom-deps): Referenced via config, expected for this monorepo package. ai
phantom-deps phantom-dep:@libsql/linux-arm64-musl AI (phantom-deps): Platform-specific optional binary. ai
dependencies unvetted-dep:@libsql/darwin-x64 AI (dependencies): Official platform binary sibling package, standard neon-rs pattern. ai
semgrep semgrep:dynamic-require AI (semgrep): Dynamic require resolves platform-specific prebuilt binary packages from a fixed enumerated set of @libsql/* targets — standard Neon native binding pattern, not arbitrary module loading. ai
dependencies unvetted-dep:@neon-rs/load AI (dependencies): @neon-rs/load is the Neon framework's standard loader for native bindings; expected dependency for this package. ai
dependencies unvetted-dep:detect-libc AI (dependencies): detect-libc is a standard utility for native Node.js bindings to detect glibc vs musl; expected and appropriate for this package. ai

Versions (showing 51 of 58)

View all versions
Version Deps Published
0.5.29 2 / 2
0.5.28 2 / 2
0.5.26 2 / 2
0.5.22 2 / 2
0.5.21 2 / 2
0.5.20 2 / 2
0.5.19 2 / 2
0.5.18 2 / 2
0.5.17 2 / 2
0.5.16 2 / 2
0.5.15 2 / 2
0.5.14 2 / 2
0.5.13 2 / 2
0.5.12 2 / 2
0.5.11 2 / 2
0.5.10 2 / 2
0.5.9 2 / 2
0.5.8 2 / 2
0.5.7 2 / 2
0.5.6 2 / 2
0.5.5 2 / 2
0.5.4 2 / 2
0.5.3 2 / 2
0.5.1 2 / 2
0.5.0 2 / 2
0.4.7 2 / 2
0.4.6 2 / 2
0.4.5 2 / 2
0.4.4 2 / 2
0.4.3 3 / 2
0.4.1 3 / 2
0.4.0 3 / 2
0.3.19 3 / 2
0.3.18 10 / 1
0.3.17 10 / 1
0.3.14 9 / 1
0.3.13 9 / 1
0.3.12 9 / 1
0.1.21 7 / 1
0.1.19 8 / 1
0.1.18 5 / 1
0.1.17 5 / 1
0.1.16 5 / 1
0.1.15 5 / 1
0.1.14 5 / 1
0.1.13 5 / 1
0.1.12 5 / 1
0.1.11 5 / 1
0.1.10 5 / 1
0.1.9 5 / 1
0.1.8 4 / 1

v0.5.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.3.19

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.3.18

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.3.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.3.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.21

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.19

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.18

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.16

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.