@powerlines/core
An internal core package for Powerlines - please use the `powerlines` package for public usage.
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@jridgewell/sourcemap-codec | AI (phantom-deps): Referenced in config files; phantom-dep heuristic false positive for this package. | ai | |
| phantom-deps | phantom-dep:birpc | AI (phantom-deps): Referenced in config files; phantom-dep heuristic false positive for this package. | ai | |
| phantom-deps | phantom-dep:oxc-resolver | AI (phantom-deps): Referenced in config files; phantom-dep heuristic false positive for this package. | ai | |
| phantom-deps | phantom-dep:locate-character | AI (phantom-deps): Referenced in config files; phantom-dep heuristic false positive for this package. | ai | |
| phantom-deps | phantom-dep:@cacheable/memory | AI (phantom-deps): Referenced in config files; phantom-dep heuristic false positive for this package. | ai | |
| provenance | publisher-changed | AI (provenance): stormie-bot is Storm Software's CI bot with 2775 approved packages; transition from GitHub Actions is a legitimate org-level CI change. | ai | |
| source-diff | obfuscated-file:dist/lib/context-helpers.d.cts | AI (source-diff): Long lines are TypeScript generic type expansion in .d.cts declaration files, not obfuscation — stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@stryke/json | AI (phantom-deps): @stryke/json is a declared runtime dependency in the @stryke ecosystem used throughout this package; phantom-dep detection is a false positive here. | ai | |
| phantom-deps | phantom-dep:@stryke/unique-id | AI (phantom-deps): @stryke/unique-id is a declared runtime dependency in the @stryke ecosystem used throughout this package; phantom-dep detection is a false positive here. | ai | |
| typosquat | typosquat.levenshtein:cors | AI (typosquat): @powerlines/core is a scoped internal core library for the Powerlines project by Storm Software, not a typosquat of the cors middleware. The name similarity is purely coincidental. | ai |
Versions (showing 51 of 256)
| Version | Deps | Published |
|---|---|---|
| 0.48.49 | 37 / 11 | |
| 0.48.48 | 37 / 11 | |
| 0.48.47 | 37 / 11 | |
| 0.48.46 | 37 / 11 | |
| 0.48.45 | 37 / 11 | |
| 0.48.44 | 37 / 11 | |
| 0.48.43 | 37 / 11 | |
| 0.48.42 | 37 / 11 | |
| 0.48.41 | 37 / 11 | |
| 0.48.40 | 37 / 11 | |
| 0.48.39 | 37 / 11 | |
| 0.48.38 | 37 / 11 | |
| 0.48.37 | 37 / 11 | |
| 0.48.36 | 37 / 11 | |
| 0.48.35 | 37 / 11 | |
| 0.48.34 | 37 / 11 | |
| 0.48.33 | 37 / 11 | |
| 0.48.28 | 37 / 11 | |
| 0.48.27 | 37 / 11 | |
| 0.48.26 | 37 / 11 | |
| 0.48.25 | 37 / 11 | |
| 0.48.24 | 37 / 11 | |
| 0.48.22 | 37 / 11 | |
| 0.48.21 | 37 / 11 | |
| 0.48.20 | 37 / 11 | |
| 0.48.19 | 37 / 11 | |
| 0.48.18 | 37 / 11 | |
| 0.48.17 | 37 / 11 | |
| 0.48.16 | 37 / 11 | |
| 0.48.15 | 37 / 11 | |
| 0.48.14 | 37 / 11 | |
| 0.48.13 | 37 / 11 | |
| 0.48.12 | 37 / 11 | |
| 0.48.11 | 37 / 11 | |
| 0.48.10 | 37 / 11 | |
| 0.48.9 | 37 / 11 | |
| 0.48.8 | 37 / 11 | |
| 0.48.7 | 37 / 11 | |
| 0.48.6 | 37 / 11 | |
| 0.48.5 | 37 / 11 | |
| 0.48.4 | 37 / 11 | |
| 0.48.3 | 37 / 11 | |
| 0.48.2 | 37 / 11 | |
| 0.48.1 | 37 / 11 | |
| 0.47.4 | 23 / 8 | |
| 0.47.3 | 23 / 8 | |
| 0.47.2 | 23 / 8 | |
| 0.47.1 | 23 / 8 | |
| 0.47.0 | 23 / 8 | |
| 0.46.6 | 23 / 8 | |
| 0.46.5 | 23 / 8 |
v0.48.49
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.48
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.47
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.46
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.45
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.44
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.43
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.42
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.41
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.40
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.39
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.38
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.37
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.36
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.35
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.34
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.33
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.28
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.27
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.26
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.25
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.24
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.22
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.21
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.20
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.19
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.18
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.17
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.16
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.15
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.14
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.13
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.12
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.1
2 findingsThis version was published by a different npm account than previous versions on 2026-05-21. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.47.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.47.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.47.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.47.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.47.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.46.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.46.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.