← Home

@powerhousedao/codegen

A powerful code generation toolkit for the Powerhouse ecosystem, designed to automate and standardize code generation across different document models and types.

22
Versions
AGPL-3.0-only
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

acaldas.powerhousememo.devryanwolhuterprometheus-phcallme-tfroidliberuum

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/src/templates/index.d.mts AI (source-diff): Type declaration file with long lines from bundled .d.ts output; not obfuscation. ai
source-diff obfuscated-file:dist/src/templates/index.mjs AI (source-diff): Standard bundler output; sample shows template export re-exports, consistent with codegen tooling. ai
source-diff obfuscated-file:dist/file-builders-DRZQa7Vq.mjs AI (source-diff): Standard tsdown/rollup bundle output; samples show readable imports and legitimate codegen logic, not malicious obfuscation. ai
dependencies unvetted-dep:@tmpl/core AI (dependencies): JSR-bridged template dep used consistently in this package; no malicious indicators. ai
provenance slsa-provenance AI (provenance): Package consistently published via CI/CD with Sigstore attestation; stable signal for this package. ai
publish-pattern new-deps-added AI (publish-pattern): read-pkg is a well-known, benign utility; no malicious history. ai
dependencies unvetted-dep:@anatine/zod-mock AI (dependencies): Well-known zod mock utility; stable dependency in this codegen package across versions. ai
dependencies unvetted-dep:@acaldas/graphql-codegen-typescript-validation-schema AI (dependencies): Author-scoped dep matching package publisher; stable pattern across many versions of this package. ai
phantom-deps phantom-dep:@acaldas/graphql-codegen-typescript-validation-schema AI (phantom-deps): Referenced in config files for codegen tooling, not directly imported. Expected pattern for a code generation package. ai
license copyleft-license:AGPL-3.0-only AI (license): AGPL-3.0-only is a legal/licensing concern, not a security risk. This package has consistently used this license across its 721 versions. ai
phantom-deps phantom-dep:@powerhousedao/design-system AI (phantom-deps): Same org scope; declared for downstream codegen consumers, not directly imported by this package's runtime code. Stable pattern for this monorepo package. ai
phantom-deps phantom-dep:@powerhousedao/reactor-browser AI (phantom-deps): Same org scope; declared for downstream codegen consumers, not directly imported. Stable pattern for this monorepo package. ai
phantom-deps phantom-dep:@faker-js/faker AI (phantom-deps): Used in generated mock code; codegen tools commonly declare deps used in generated output. ai
phantom-deps phantom-dep:kysely-pglite AI (phantom-deps): Referenced in config files for generated code; consistent with codegen tool pattern. ai
phantom-deps phantom-dep:@types/node AI (phantom-deps): Framework-scoped type package; standard pattern for TypeScript packages. ai
phantom-deps phantom-dep:@anatine/zod-mock AI (phantom-deps): Used in generated mock code; consistent with codegen tool pattern. ai
phantom-deps phantom-dep:graphql AI (phantom-deps): GraphQL codegen tool; graphql is a peer/config dependency used by codegen plugins, not directly imported in source. ai
phantom-deps phantom-dep:@graphql-codegen/core AI (phantom-deps): GraphQL codegen plugin dependency; referenced in config files as expected for this tool. ai
phantom-deps phantom-dep:@powerhousedao/common AI (phantom-deps): Same org monorepo package; phantom detection is expected for intra-monorepo deps. ai
phantom-deps phantom-dep:package-json-validator AI (phantom-deps): Referenced in config/utility files; consistent with codegen tool that validates generated package.json files. ai
phantom-deps phantom-dep:@graphql-codegen/typescript AI (phantom-deps): GraphQL codegen plugin; referenced in config files as expected for this tool. ai
phantom-deps phantom-dep:graphql-codegen-typescript-validation-schema AI (phantom-deps): GraphQL codegen plugin; referenced in config files as expected for this tool. ai
phantom-deps phantom-dep:kysely AI (phantom-deps): Codegen tool that generates kysely-compatible code; declaring kysely as a dep for downstream generated code is expected pattern for this package. ai

Versions (showing 22 of 22)

Version Deps Published
6.0.0 20 / 6
5.3.6 29 / 11
5.3.5 29 / 11
5.3.4 29 / 11
5.3.3 29 / 11
5.3.2 29 / 11
5.3.1 29 / 11
5.3.0 29 / 11
5.1.0 23 / 12
5.0.12 23 / 12
5.0.11 23 / 12
5.0.10 23 / 12
5.0.9 23 / 12
5.0.8 23 / 12
5.0.7 23 / 12
5.0.6 23 / 12
5.0.5 23 / 12
5.0.4 23 / 12
5.0.3 22 / 12
5.0.2 22 / 12
5.0.1 22 / 12
5.0.0 22 / 12

v6.0.0

5 findings
HIGH Publisher changed: acaldas.powerhouse → memo.dev (on 2026-05-21) provenance

This version was published by a different npm account than previous versions on 2026-05-21. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/file-builders-DRZQa7Vq.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/templates/index.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/templates/index.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.3.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.3.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.3.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.3.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.3.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.