← Home

@powerhousedao/registry

Express-based server that serves Powerhouse packages (ESM bundles) for dynamic loading via `import()` in browsers and Node.js.

2
Versions
ISC
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

acaldas.powerhousememo.devryanwolhuterprometheus-phcallme-tfroidliberuum

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:verdaccio-aws-s3-storage AI (phantom-deps): Storage plugin referenced in config files only; not directly imported is expected for a Verdaccio plugin dependency. ai
phantom-deps phantom-dep:@powerhousedao/shared AI (phantom-deps): Same-org sibling package; phantom-dep false positive common for monorepo shared utilities. ai

Versions (showing 2 of 2)

Version Deps Published
6.1.0 9 / 6
6.0.0 9 / 6

v6.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.