@powerhousedao/builder-tools
A comprehensive toolkit for building and managing Powerhouse DAO applications. This package provides essential tools and utilities for development, including document model editing, connection management, and various editor utilities.
25
Versions
AGPL-3.0-only
License
No
Install Scripts
Attested
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation (unverified)
npm registry signatures
No source commit
Maintainers
acaldas.powerhousememo.devryanwolhuterprometheus-phph-thegoldenmulecallme-tfroidliberuum
Keywords
powerhousevetradocument-modellocal-firstevent-sourcingvitetypescriptbuildeditortooling
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): memo.dev is an established publisher (36 approved) within the same Powerhouse org; transition appears legitimate. | ai | |
| license | copyleft-license:AGPL-3.0-only | AI (license): Intentional AGPL license; stable for this package. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): read-pkg is a well-known, benign utility; addition is consistent with builder-tools functionality. | ai | |
| dependencies | unvetted-dep:@tailwindcss/cli | AI (dependencies): Official Tailwind CSS CLI; no malware indicators. | ai | |
| dependencies | unvetted-dep:@theguild/editor | AI (dependencies): Known The Guild editor package; no malware indicators. | ai | |
| dependencies | unvetted-dep:@radix-ui/react-select | AI (dependencies): Official Radix UI component; no malware indicators. | ai | |
| dependencies | unvetted-dep:constrained-editor-plugin | AI (dependencies): Monaco/CodeMirror plugin; no malware indicators. | ai | |
| dependencies | unvetted-dep:vite-plugin-node-polyfills | AI (dependencies): Common Vite plugin; no malware indicators. | ai | |
| dependencies | unvetted-dep:dspot-powerhouse-components | AI (dependencies): Powerhouse ecosystem component; consistent with publisher org. | ai | |
| dependencies | unvetted-dep:esbuild-plugins-node-modules-polyfill | AI (dependencies): Common esbuild plugin; no malware indicators. | ai | |
| dependencies | unvetted-dep:thememirror | AI (dependencies): Known CodeMirror theme package; no malware indicators. | ai | |
| dependencies | unvetted-dep:vite-envs | AI (dependencies): Legitimate Vite plugin; no malware indicators. | ai | |
| phantom-deps | phantom-dep:@radix-ui/react-select | AI (phantom-deps): Builder-tools package legitimately declares config-level deps not directly imported in source; expected pattern for tooling packages. | ai | |
| phantom-deps | phantom-dep:@radix-ui/react-checkbox | AI (phantom-deps): Builder-tools package legitimately declares config-level deps not directly imported in source; expected pattern for tooling packages. | ai | |
| phantom-deps | phantom-dep:constrained-editor-plugin | AI (phantom-deps): Builder-tools package legitimately declares config-level deps not directly imported in source; expected pattern for tooling packages. | ai | |
| phantom-deps | phantom-dep:postcss | AI (phantom-deps): Builder-tools package legitimately declares config-level deps not directly imported in source; expected pattern for tooling packages. | ai | |
| phantom-deps | phantom-dep:@codemirror/lang-javascript | AI (phantom-deps): Builder-tools package legitimately declares config-level deps not directly imported in source; expected pattern for tooling packages. | ai | |
| phantom-deps | phantom-dep:@radix-ui/react-radio-group | AI (phantom-deps): Builder-tools package legitimately declares config-level deps not directly imported in source; expected pattern for tooling packages. | ai | |
| phantom-deps | phantom-dep:dspot-powerhouse-components | AI (phantom-deps): Builder-tools package legitimately declares config-level deps not directly imported in source; expected pattern for tooling packages. | ai | |
| phantom-deps | phantom-dep:@codemirror/theme-one-dark | AI (phantom-deps): Builder-tools package legitimately declares config-level deps not directly imported in source; expected pattern for tooling packages. | ai | |
| phantom-deps | phantom-dep:tailwindcss | AI (phantom-deps): Builder-tools package legitimately declares config-level deps not directly imported in source; expected pattern for tooling packages. | ai | |
| phantom-deps | phantom-dep:@tailwindcss/cli | AI (phantom-deps): Builder-tools package legitimately declares config-level deps not directly imported in source; expected pattern for tooling packages. | ai | |
| phantom-deps | phantom-dep:@tailwindcss/postcss | AI (phantom-deps): Builder-tools package legitimately declares config-level deps not directly imported in source; expected pattern for tooling packages. | ai | |
| phantom-deps | phantom-dep:commander | AI (phantom-deps): Builder-tools package legitimately declares config-level deps not directly imported in source; expected pattern for tooling packages. | ai | |
| phantom-deps | phantom-dep:date-fns | AI (phantom-deps): Builder-tools package legitimately declares config-level deps not directly imported in source; expected pattern for tooling packages. | ai | |
| phantom-deps | phantom-dep:es-toolkit | AI (phantom-deps): Builder-tools package legitimately declares config-level deps not directly imported in source; expected pattern for tooling packages. | ai | |
| phantom-deps | phantom-dep:copy-anything | AI (phantom-deps): Builder-tools package legitimately declares config-level deps not directly imported in source; expected pattern for tooling packages. | ai | |
| phantom-deps | phantom-dep:@prettier/sync | AI (phantom-deps): Builder-tools package legitimately declares config-level deps not directly imported in source; expected pattern for tooling packages. | ai | |
| phantom-deps | phantom-dep:@theguild/editor | AI (phantom-deps): Builder-tools package legitimately declares config-level deps not directly imported in source; expected pattern for tooling packages. | ai | |
| phantom-deps | phantom-dep:@graphql-tools/schema | AI (phantom-deps): Builder-tools package legitimately declares config-level deps not directly imported in source; expected pattern for tooling packages. | ai | |
| phantom-deps | phantom-dep:@radix-ui/react-icons | AI (phantom-deps): Builder-tools package legitimately declares config-level deps not directly imported in source; expected pattern for tooling packages. | ai | |
| provenance | slsa-provenance | AI (provenance): Package consistently published via CI/CD with Sigstore SLSA provenance attestation; stable supply chain integrity signal for this org's packages. | ai |
Versions (showing 25 of 25)
| Version | Deps | Published |
|---|---|---|
| 6.2.1 | 9 / 6 | |
| 6.2.0 | 9 / 6 | |
| 6.1.0 | 7 / 4 | |
| 6.0.0 | 7 / 4 | |
| 5.3.6 | 61 / 27 | |
| 5.3.5 | 61 / 27 | |
| 5.3.4 | 61 / 27 | |
| 5.3.3 | 61 / 27 | |
| 5.3.2 | 61 / 27 | |
| 5.3.1 | 61 / 27 | |
| 5.3.0 | 61 / 27 | |
| 5.1.0 | 62 / 26 | |
| 5.0.12 | 62 / 26 | |
| 5.0.11 | 62 / 26 | |
| 5.0.10 | 62 / 26 | |
| 5.0.9 | 62 / 26 | |
| 5.0.8 | 62 / 26 | |
| 5.0.7 | 62 / 26 | |
| 5.0.6 | 62 / 26 | |
| 5.0.5 | 62 / 26 | |
| 5.0.4 | 62 / 26 | |
| 5.0.3 | 61 / 26 | |
| 5.0.2 | 61 / 26 | |
| 5.0.1 | 61 / 26 | |
| 5.0.0 | 61 / 26 |
v6.2.1
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.2.0
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.