@baseplate-dev/project-builder-common
Holds common packages for plugins and generators
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@baseplate-dev/plugin-payments | AI (dependencies): Same-org monorepo package, versioned in lockstep; not an external third-party dependency. | ai | |
| phantom-deps | phantom-dep:prettier | AI (phantom-deps): prettier referenced in config files, not directly imported — standard tooling pattern. | ai | |
| phantom-deps | phantom-dep:@baseplate-dev/plugin-ai | AI (phantom-deps): Same-org monorepo plugin; re-exported or used indirectly, not a phantom dep concern. | ai | |
| phantom-deps | phantom-dep:@baseplate-dev/plugin-auth | AI (phantom-deps): Same-org monorepo plugin; re-exported or used indirectly. | ai | |
| phantom-deps | phantom-dep:@baseplate-dev/plugin-email | AI (phantom-deps): Same-org monorepo plugin; re-exported or used indirectly. | ai | |
| phantom-deps | phantom-dep:eslint | AI (phantom-deps): eslint referenced in config files, not directly imported — standard tooling pattern. | ai | |
| phantom-deps | phantom-dep:@baseplate-dev/plugin-storage | AI (phantom-deps): Same-org monorepo plugin; re-exported or used indirectly. | ai | |
| phantom-deps | phantom-dep:@baseplate-dev/plugin-payments | AI (phantom-deps): Same-org monorepo plugin; re-exported or used indirectly. | ai | |
| phantom-deps | phantom-dep:@baseplate-dev/plugin-rate-limit | AI (phantom-deps): Same-org monorepo plugin; re-exported or used indirectly. | ai | |
| phantom-deps | phantom-dep:@baseplate-dev/plugin-observability | AI (phantom-deps): Same-org monorepo plugin; re-exported or used indirectly. | ai | |
| phantom-deps | phantom-dep:@baseplate-dev/plugin-queue | AI (phantom-deps): Same-org monorepo plugin; re-exported or used indirectly. | ai |
Versions (showing 39 of 39)
| Version | Deps | Published |
|---|---|---|
| 1.0.7 | 12 / 2 | |
| 0.6.9 | 13 / 2 | |
| 0.6.8 | 13 / 2 | |
| 0.6.7 | 13 / 2 | |
| 0.6.6 | 13 / 2 | |
| 0.6.5 | 13 / 2 | |
| 0.6.4 | 12 / 2 | |
| 0.6.3 | 12 / 2 | |
| 0.6.2 | 10 / 1 | |
| 0.6.1 | 10 / 1 | |
| 0.6.0 | 10 / 1 | |
| 0.5.3 | 10 / 1 | |
| 0.5.2 | 10 / 1 | |
| 0.5.1 | 9 / 1 | |
| 0.5.0 | 8 / 1 | |
| 0.4.4 | 8 / 1 | |
| 0.4.3 | 8 / 1 | |
| 0.4.2 | 8 / 1 | |
| 0.4.1 | 8 / 1 | |
| 0.4.0 | 8 / 1 | |
| 0.3.8 | 8 / 1 | |
| 0.3.7 | 8 / 1 | |
| 0.3.6 | 8 / 1 | |
| 0.3.5 | 8 / 1 | |
| 0.3.4 | 8 / 1 | |
| 0.3.3 | 8 / 1 | |
| 0.3.2 | 8 / 1 | |
| 0.3.1 | 8 / 1 | |
| 0.3.0 | 7 / 1 | |
| 0.2.6 | 7 / 1 | |
| 0.2.5 | 7 / 1 | |
| 0.2.4 | 7 / 1 | |
| 0.2.3 | 7 / 1 | |
| 0.2.2 | 7 / 1 | |
| 0.2.1 | 7 / 1 | |
| 0.2.0 | 7 / 1 | |
| 0.1.3 | 7 / 1 | |
| 0.1.2 | 7 / 1 | |
| 0.1.1 | 7 / 1 |
v1.0.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.