← Home

@powerlines/core

An internal core package for Powerlines - please use the `powerlines` package for public usage.

51
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

stormie-botsullivanpj

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@jridgewell/sourcemap-codec AI (phantom-deps): Referenced in config files; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:birpc AI (phantom-deps): Referenced in config files; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:oxc-resolver AI (phantom-deps): Referenced in config files; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:locate-character AI (phantom-deps): Referenced in config files; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:@cacheable/memory AI (phantom-deps): Referenced in config files; phantom-dep heuristic false positive for this package. ai
provenance publisher-changed AI (provenance): stormie-bot is Storm Software's CI bot with 2775 approved packages; transition from GitHub Actions is a legitimate org-level CI change. ai
source-diff obfuscated-file:dist/lib/context-helpers.d.cts AI (source-diff): Long lines are TypeScript generic type expansion in .d.cts declaration files, not obfuscation — stable pattern for this package. ai
phantom-deps phantom-dep:@stryke/json AI (phantom-deps): @stryke/json is a declared runtime dependency in the @stryke ecosystem used throughout this package; phantom-dep detection is a false positive here. ai
phantom-deps phantom-dep:@stryke/unique-id AI (phantom-deps): @stryke/unique-id is a declared runtime dependency in the @stryke ecosystem used throughout this package; phantom-dep detection is a false positive here. ai
typosquat typosquat.levenshtein:cors AI (typosquat): @powerlines/core is a scoped internal core library for the Powerlines project by Storm Software, not a typosquat of the cors middleware. The name similarity is purely coincidental. ai

Versions (showing 51 of 290)

View all versions
Version Deps Published
0.48.84 39 / 12
0.48.83 39 / 12
0.48.82 39 / 12
0.48.81 39 / 12
0.48.80 39 / 12
0.48.79 39 / 12
0.48.78 39 / 12
0.48.77 39 / 12
0.48.76 39 / 12
0.48.75 39 / 12
0.48.74 39 / 12
0.48.73 39 / 12
0.48.72 39 / 12
0.48.71 39 / 12
0.48.70 39 / 12
0.48.68 39 / 12
0.48.67 39 / 12
0.48.66 39 / 12
0.48.65 39 / 12
0.48.64 39 / 12
0.48.63 39 / 12
0.48.62 39 / 12
0.48.61 39 / 12
0.48.60 39 / 12
0.48.59 39 / 12
0.48.58 39 / 12
0.48.57 39 / 12
0.48.56 39 / 12
0.48.55 39 / 12
0.48.54 39 / 12
0.48.53 37 / 11
0.48.52 37 / 11
0.48.51 37 / 11
0.48.50 37 / 11
0.48.49 37 / 11
0.48.48 37 / 11
0.48.47 37 / 11
0.48.46 37 / 11
0.48.45 37 / 11
0.48.44 37 / 11
0.48.43 37 / 11
0.48.42 37 / 11
0.48.41 37 / 11
0.48.40 37 / 11
0.48.39 37 / 11
0.48.38 37 / 11
0.48.37 37 / 11
0.48.36 37 / 11
0.48.35 37 / 11
0.48.34 37 / 11
0.48.33 37 / 11

v0.48.84

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.48.83

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.48.82

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.48.81

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.48.80

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.48.79

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.48.78

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.48.77

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.48.76

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.48.75

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.48.74

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.48.73

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.48.72

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.48.71

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.48.70

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.48.68

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.48.67

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.48.66

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.48.65

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.48.64

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.48.63

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.48.62

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.48.61

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.