@powerlines/core
An internal core package for Powerlines - please use the `powerlines` package for public usage.
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@jridgewell/sourcemap-codec | AI (phantom-deps): Referenced in config files; phantom-dep heuristic false positive for this package. | ai | |
| phantom-deps | phantom-dep:birpc | AI (phantom-deps): Referenced in config files; phantom-dep heuristic false positive for this package. | ai | |
| phantom-deps | phantom-dep:oxc-resolver | AI (phantom-deps): Referenced in config files; phantom-dep heuristic false positive for this package. | ai | |
| phantom-deps | phantom-dep:locate-character | AI (phantom-deps): Referenced in config files; phantom-dep heuristic false positive for this package. | ai | |
| phantom-deps | phantom-dep:@cacheable/memory | AI (phantom-deps): Referenced in config files; phantom-dep heuristic false positive for this package. | ai | |
| provenance | publisher-changed | AI (provenance): stormie-bot is Storm Software's CI bot with 2775 approved packages; transition from GitHub Actions is a legitimate org-level CI change. | ai | |
| source-diff | obfuscated-file:dist/lib/context-helpers.d.cts | AI (source-diff): Long lines are TypeScript generic type expansion in .d.cts declaration files, not obfuscation — stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@stryke/json | AI (phantom-deps): @stryke/json is a declared runtime dependency in the @stryke ecosystem used throughout this package; phantom-dep detection is a false positive here. | ai | |
| phantom-deps | phantom-dep:@stryke/unique-id | AI (phantom-deps): @stryke/unique-id is a declared runtime dependency in the @stryke ecosystem used throughout this package; phantom-dep detection is a false positive here. | ai | |
| typosquat | typosquat.levenshtein:cors | AI (typosquat): @powerlines/core is a scoped internal core library for the Powerlines project by Storm Software, not a typosquat of the cors middleware. The name similarity is purely coincidental. | ai |
Versions (showing 51 of 290)
| Version | Deps | Published |
|---|---|---|
| 0.48.84 | 39 / 12 | |
| 0.48.83 | 39 / 12 | |
| 0.48.82 | 39 / 12 | |
| 0.48.81 | 39 / 12 | |
| 0.48.80 | 39 / 12 | |
| 0.48.79 | 39 / 12 | |
| 0.48.78 | 39 / 12 | |
| 0.48.77 | 39 / 12 | |
| 0.48.76 | 39 / 12 | |
| 0.48.75 | 39 / 12 | |
| 0.48.74 | 39 / 12 | |
| 0.48.73 | 39 / 12 | |
| 0.48.72 | 39 / 12 | |
| 0.48.71 | 39 / 12 | |
| 0.48.70 | 39 / 12 | |
| 0.48.68 | 39 / 12 | |
| 0.48.67 | 39 / 12 | |
| 0.48.66 | 39 / 12 | |
| 0.48.65 | 39 / 12 | |
| 0.48.64 | 39 / 12 | |
| 0.48.63 | 39 / 12 | |
| 0.48.62 | 39 / 12 | |
| 0.48.61 | 39 / 12 | |
| 0.48.60 | 39 / 12 | |
| 0.48.59 | 39 / 12 | |
| 0.48.58 | 39 / 12 | |
| 0.48.57 | 39 / 12 | |
| 0.48.56 | 39 / 12 | |
| 0.48.55 | 39 / 12 | |
| 0.48.54 | 39 / 12 | |
| 0.48.53 | 37 / 11 | |
| 0.48.52 | 37 / 11 | |
| 0.48.51 | 37 / 11 | |
| 0.48.50 | 37 / 11 | |
| 0.48.49 | 37 / 11 | |
| 0.48.48 | 37 / 11 | |
| 0.48.47 | 37 / 11 | |
| 0.48.46 | 37 / 11 | |
| 0.48.45 | 37 / 11 | |
| 0.48.44 | 37 / 11 | |
| 0.48.43 | 37 / 11 | |
| 0.48.42 | 37 / 11 | |
| 0.48.41 | 37 / 11 | |
| 0.48.40 | 37 / 11 | |
| 0.48.39 | 37 / 11 | |
| 0.48.38 | 37 / 11 | |
| 0.48.37 | 37 / 11 | |
| 0.48.36 | 37 / 11 | |
| 0.48.35 | 37 / 11 | |
| 0.48.34 | 37 / 11 | |
| 0.48.33 | 37 / 11 |
v0.48.84
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.83
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.82
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.81
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.80
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.79
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.78
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.77
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.76
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.75
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.74
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.73
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.72
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.71
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.70
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.68
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.67
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.66
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.65
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.64
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.63
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.62
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.61
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.