tree-sitter-php
3
Versions
—
License
Yes
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
maxbrunsfeldjoshveraben3eeeatom-teamaymannadeem
Keywords
incrementalparsingtree-sitterphp
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:node-addon-api | AI (phantom-deps): node-addon-api is referenced in native build config files, not imported at runtime; false positive for this package. | ai | |
| install-scripts | install-script:install | AI (install-scripts): node-gyp-build install script is the standard pattern for tree-sitter native bindings shipping prebuilt .node files; stable for this package. | ai | |
| npm-metadata | bundled-binaries | AI (npm-metadata): Prebuilt .node binaries for multiple platforms are the expected distribution mechanism for tree-sitter grammar native bindings. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require is constrained to process.platform/arch for loading the correct prebuilt .node file — not arbitrary module loading. | ai |