@powerhousedao/codegen
A powerful code generation toolkit for the Powerhouse ecosystem, designed to automate and standardize code generation across different document models and types.
25
Versions
AGPL-3.0-only
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
acaldas.powerhousememo.devryanwolhuterprometheus-phph-thegoldenmulecallme-tfroidliberuum
Keywords
powerhousevetradocument-modellocal-firstevent-sourcingcodegengraphqltypescriptgeneratorscaffold
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@graphql-codegen/add | AI (phantom-deps): Codegen plugin referenced via config, expected pattern for this tool. | ai | |
| source-diff | obfuscated-file:dist/file-builders-DlSc6UWM.mjs | AI (source-diff): Bundled build output (tsdown), long minified lines not obfuscation; no malicious payload. | ai | |
| source-diff | obfuscated-file:dist/file-builders-Btk4MK1I.mjs | AI (source-diff): Bundled build output with source map, not true obfuscation. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Consistent with active org publishing via CI provenance. | ai | |
| source-diff | obfuscated-file:dist/src/templates/index.mjs | AI (source-diff): Standard bundler output; sample shows template export re-exports, consistent with codegen tooling. | ai | |
| source-diff | obfuscated-file:dist/src/templates/index.d.mts | AI (source-diff): Type declaration file with long lines from bundled .d.ts output; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/file-builders-DRZQa7Vq.mjs | AI (source-diff): Standard tsdown/rollup bundle output; samples show readable imports and legitimate codegen logic, not malicious obfuscation. | ai | |
| dependencies | unvetted-dep:@tmpl/core | AI (dependencies): JSR-bridged template dep used consistently in this package; no malicious indicators. | ai | |
| provenance | slsa-provenance | AI (provenance): Package consistently published via CI/CD with Sigstore attestation; stable signal for this package. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): read-pkg is a well-known, benign utility; no malicious history. | ai | |
| dependencies | unvetted-dep:@anatine/zod-mock | AI (dependencies): Well-known zod mock utility; stable dependency in this codegen package across versions. | ai | |
| dependencies | unvetted-dep:@acaldas/graphql-codegen-typescript-validation-schema | AI (dependencies): Author-scoped dep matching package publisher; stable pattern across many versions of this package. | ai | |
| phantom-deps | phantom-dep:@powerhousedao/design-system | AI (phantom-deps): Same org scope; declared for downstream codegen consumers, not directly imported by this package's runtime code. Stable pattern for this monorepo package. | ai | |
| license | copyleft-license:AGPL-3.0-only | AI (license): AGPL-3.0-only is a legal/licensing concern, not a security risk. This package has consistently used this license across its 721 versions. | ai | |
| phantom-deps | phantom-dep:@powerhousedao/reactor-browser | AI (phantom-deps): Same org scope; declared for downstream codegen consumers, not directly imported. Stable pattern for this monorepo package. | ai | |
| phantom-deps | phantom-dep:@acaldas/graphql-codegen-typescript-validation-schema | AI (phantom-deps): Referenced in config files for codegen tooling, not directly imported. Expected pattern for a code generation package. | ai | |
| phantom-deps | phantom-dep:kysely | AI (phantom-deps): Codegen tool that generates kysely-compatible code; declaring kysely as a dep for downstream generated code is expected pattern for this package. | ai | |
| phantom-deps | phantom-dep:graphql-codegen-typescript-validation-schema | AI (phantom-deps): GraphQL codegen plugin; referenced in config files as expected for this tool. | ai | |
| phantom-deps | phantom-dep:@graphql-codegen/typescript | AI (phantom-deps): GraphQL codegen plugin; referenced in config files as expected for this tool. | ai | |
| phantom-deps | phantom-dep:package-json-validator | AI (phantom-deps): Referenced in config/utility files; consistent with codegen tool that validates generated package.json files. | ai | |
| phantom-deps | phantom-dep:@powerhousedao/common | AI (phantom-deps): Same org monorepo package; phantom detection is expected for intra-monorepo deps. | ai | |
| phantom-deps | phantom-dep:@graphql-codegen/core | AI (phantom-deps): GraphQL codegen plugin dependency; referenced in config files as expected for this tool. | ai | |
| phantom-deps | phantom-dep:@anatine/zod-mock | AI (phantom-deps): Used in generated mock code; consistent with codegen tool pattern. | ai | |
| phantom-deps | phantom-dep:@faker-js/faker | AI (phantom-deps): Used in generated mock code; codegen tools commonly declare deps used in generated output. | ai | |
| phantom-deps | phantom-dep:kysely-pglite | AI (phantom-deps): Referenced in config files for generated code; consistent with codegen tool pattern. | ai | |
| phantom-deps | phantom-dep:@types/node | AI (phantom-deps): Framework-scoped type package; standard pattern for TypeScript packages. | ai | |
| phantom-deps | phantom-dep:graphql | AI (phantom-deps): GraphQL codegen tool; graphql is a peer/config dependency used by codegen plugins, not directly imported in source. | ai |
Versions (showing 25 of 25)
| Version | Deps | Published |
|---|---|---|
| 6.2.1 | 20 / 6 | |
| 6.2.0 | 20 / 6 | |
| 6.1.0 | 20 / 6 | |
| 6.0.0 | 20 / 6 | |
| 5.3.6 | 29 / 11 | |
| 5.3.5 | 29 / 11 | |
| 5.3.4 | 29 / 11 | |
| 5.3.3 | 29 / 11 | |
| 5.3.2 | 29 / 11 | |
| 5.3.1 | 29 / 11 | |
| 5.3.0 | 29 / 11 | |
| 5.1.0 | 23 / 12 | |
| 5.0.12 | 23 / 12 | |
| 5.0.11 | 23 / 12 | |
| 5.0.10 | 23 / 12 | |
| 5.0.9 | 23 / 12 | |
| 5.0.8 | 23 / 12 | |
| 5.0.7 | 23 / 12 | |
| 5.0.6 | 23 / 12 | |
| 5.0.5 | 23 / 12 | |
| 5.0.4 | 23 / 12 | |
| 5.0.3 | 22 / 12 | |
| 5.0.2 | 22 / 12 | |
| 5.0.1 | 22 / 12 | |
| 5.0.0 | 22 / 12 |
v6.2.1
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.2.0
2 findings
HIGH
New obfuscated file: dist/file-builders-Btk4MK1I.mjs
source-diff
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.