← Home

leveldown

A low-level Node.js LevelDB binding

91
Versions
MIT
License
Yes
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

vweeversrvaggralphtheninja

Keywords

leveldblevel

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
maintainer-change maintainer-removed AI (maintainer-change): juliangruber's removal reflects the Level org's known maintainer transition to vweevers; no new unknown maintainer added, no takeover signal. ai
publish-pattern new-deps-added AI (publish-pattern): napi-macros and node-gyp-build are well-known N-API ecosystem packages added as part of a legitimate nan→N-API migration. ai
provenance no-provenance AI (provenance): leveldown is a long-established native binding with a trusted publisher; lack of Sigstore provenance is not a security risk for this package. ai
dependencies unvetted-dep:node-gyp-build AI (dependencies): node-gyp-build is a well-known, widely-used utility for native Node.js addons; its use here is standard and expected. ai
install-scripts install-script:install AI (install-scripts): leveldown is a native LevelDB binding; node-gyp-build install script is the standard mechanism for selecting prebuilt binaries. Stable and expected for this package. ai
phantom-deps phantom-dep:napi-macros AI (phantom-deps): napi-macros is a C header used at compile time; intentionally excluded from JS import checks as documented in the dependency-check script. ai
npm-metadata bundled-binaries AI (npm-metadata): Prebuilt .node binaries are leveldown's documented distribution mechanism via prebuildify, covering multiple platforms. Expected for this native addon. ai

Versions (showing 91 of 91)

Version Deps Published
6.1.1 3 / 21
6.1.0 3 / 21
6.0.3 3 / 21
6.0.1 3 / 21
6.0.0 3 / 23
5.4.1 3 / 22
5.4.0 3 / 22
5.3.0 3 / 22
5.1.1 3 / 21
5.1.0 4 / 24
5.0.2 4 / 23
5.0.0 4 / 22
4.0.2 5 / 18
4.0.1 5 / 18
4.0.0 5 / 18
3.0.2 5 / 18
3.0.1 5 / 18
3.0.0 5 / 17
2.1.1 5 / 17
2.1.0 5 / 17
2.0.2 5 / 17
2.0.1 5 / 17
2.0.0 5 / 17
1.9.0 5 / 16
1.8.0 5 / 16
1.7.2 5 / 16
1.7.1 5 / 16
1.7.0 5 / 16
1.6.0 5 / 16
1.5.3 5 / 15
1.5.2 5 / 15
1.5.1 5 / 15
1.5.0 5 / 12
1.4.6 5 / 12
1.4.5 5 / 12
1.4.4 5 / 12
1.4.3 5 / 12
1.4.2 5 / 12
1.4.1 5 / 12
1.4.0 5 / 12
1.3.0 5 / 13
1.2.2 5 / 13
1.2.1 5 / 13
1.2.0 4 / 13
1.1.0 4 / 13
1.0.7 4 / 13
1.0.6 4 / 11
1.0.5 4 / 11
1.0.4 4 / 11
1.0.3 4 / 11
1.0.2 4 / 7
1.0.1 4 / 7
1.0.0 4 / 7
0.10.6 2 / 8
0.10.5 2 / 8
0.10.4 2 / 8
0.10.3 2 / 8
0.10.2 2 / 8
0.10.1 2 / 7
0.10.0 2 / 7
0.9.2 2 / 7
0.9.1 2 / 7
0.9.0 2 / 7
0.8.3 2 / 7
0.8.2 2 / 7
0.8.1 2 / 7
0.8.0 2 / 7
0.7.0 1 / 7
0.6.2 1 / 7
0.6.1 1 / 7
0.6.0 1 / 7
0.5.0 1 / 5
0.4.4 1 / 5
0.4.3 1 / 5
0.4.2 1 / 5
0.4.1 1 / 5
0.4.0 1 / 5
0.3.1 1 / 5
0.3.0 1 / 5
0.2.4 1 / 5
0.2.3 1 / 5
0.2.1 1 / 4
0.2.0 1 / 4
0.1.4 1 / 2
0.1.3 1 / 2
0.1.2 1 / 2
0.1.1 1 / 2
0.1.0 1 / 2
0.0.2 1 / 1
0.0.1 1 / 1
0.0.0 1 / 1

v6.1.1

3 findings
HIGH Package has 'install' script install-scripts

Script: node-gyp-build

HIGH Bundled binary files (9) npm-metadata

Package contains compiled binaries that could be backdoors: • prebuilds/linux-arm/node.napi.armv6.node • prebuilds/android-arm/node.napi.armv7.node • prebuilds/linux-arm/node.napi.armv7.node • prebuilds/android-arm64/node.napi.armv8.node • prebuilds/linux-arm64/node.napi.armv8.node • prebuilds/linux-x64/node.napi.glibc.node • prebuilds/linux-x64/node.napi.musl.node • prebuilds/win32-ia32/node.napi.node • prebuilds/win32-x64/node.napi.node

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.4.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.4.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.3.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.1.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.1.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.0.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.0.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.