← Home

pgpm

PostgreSQL Package Manager - Database migration and package management CLI

51
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

pyramationluca608phatg

Keywords

clicommand-linetoolpostgrespostgresqlmigrationpackage-managerdatabasepgpgsql

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@launchql/server-utils AI (phantom-deps): Config-file reference only; stable false positive for this CLI package. ai
dependencies unvetted-dep:@launchql/env AI (dependencies): Same org/publisher as pgpm; stable false positive for this package. ai
dependencies unvetted-dep:@launchql/core AI (dependencies): Same org/publisher as pgpm; stable false positive for this package. ai
dependencies unvetted-dep:@launchql/types AI (dependencies): Same org/publisher as pgpm; stable false positive for this package. ai
dependencies unvetted-dep:@launchql/logger AI (dependencies): Same org/publisher as pgpm; stable false positive for this package. ai
dependencies unvetted-dep:@launchql/server AI (dependencies): Same org/publisher as pgpm; stable false positive for this package. ai
dependencies unvetted-dep:@launchql/explorer AI (dependencies): Same org/publisher as pgpm; stable false positive for this package. ai
dependencies unvetted-dep:@launchql/templatizer AI (dependencies): Same org/publisher as pgpm; stable false positive for this package. ai
dependencies unvetted-dep:@launchql/server-utils AI (dependencies): Same org/publisher as pgpm; stable false positive for this package. ai
phantom-deps phantom-dep:find-and-require-package-json AI (phantom-deps): Config-referenced utility; stable pattern for this package. ai
phantom-deps phantom-dep:appstash AI (phantom-deps): Config-referenced utility; stable pattern for this package. ai
phantom-deps phantom-dep:yanse AI (phantom-deps): Config-referenced utility; stable pattern for this package. ai
phantom-deps phantom-dep:pgsql-deparser AI (phantom-deps): Config-referenced utility; stable pattern for this package. ai
phantom-deps phantom-dep:js-yaml AI (phantom-deps): Config-referenced utility; stable pattern for this package. ai
phantom-deps phantom-dep:shelljs AI (phantom-deps): Config-referenced utility; stable pattern for this package. ai
semgrep semgrep:child-process-import AI (semgrep): CLI deploy tool legitimately uses child_process for executing database/system commands. ai
semgrep semgrep:env-spread AI (semgrep): Spreading process.env is standard for passing environment variables to child processes in a deployment CLI. ai
typosquat typosquat.levenshtein:pg AI (typosquat): pgpm is a distinct PostgreSQL package manager CLI, not a typosquat of pg. ai

Versions (showing 51 of 189)

View all versions
Version Deps Published
4.28.0 18 / 10
4.27.0 18 / 10
4.26.4 18 / 10
4.26.3 18 / 10
4.26.2 18 / 10
4.26.1 18 / 10
4.26.0 18 / 10
4.25.4 18 / 10
4.25.3 18 / 10
4.25.2 18 / 10
4.25.1 18 / 10
4.25.0 18 / 10
4.24.6 18 / 10
4.24.5 18 / 10
4.24.4 18 / 10
4.24.3 18 / 10
4.24.2 18 / 10
4.24.1 18 / 10
4.24.0 18 / 10
4.23.9 18 / 10
4.23.8 18 / 10
4.23.7 18 / 10
4.23.6 18 / 10
4.23.5 18 / 10
4.23.4 18 / 10
4.23.3 18 / 10
4.23.2 18 / 10
4.23.0 18 / 10
4.22.7 18 / 10
4.22.6 18 / 10
4.22.5 18 / 10
4.22.4 18 / 10
4.22.3 18 / 10
4.22.2 18 / 10
4.22.1 18 / 10
4.22.0 18 / 10
4.21.2 18 / 10
4.21.1 18 / 10
4.21.0 18 / 10
4.20.4 18 / 10
4.20.3 18 / 10
4.20.2 18 / 10
4.20.1 18 / 10
4.20.0 18 / 10
4.19.4 18 / 10
4.19.3 18 / 10
4.19.2 18 / 10
4.19.1 18 / 10
4.19.0 18 / 10
4.18.1 18 / 10
4.18.0 18 / 10

v4.28.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.27.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.26.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.26.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.26.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.26.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.26.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.25.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.25.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.25.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.25.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.25.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.24.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.24.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.24.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.24.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.24.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.24.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.24.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.23.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.23.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.23.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.23.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.23.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.23.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.23.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.23.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.23.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.22.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.22.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.22.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.22.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.22.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.22.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.22.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.22.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.21.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.21.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.21.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.20.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.20.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.20.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.20.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.20.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.19.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.19.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.19.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.19.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.19.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.18.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.18.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.