← Home

@powerlines/engine

An internal package containing the core engine modules for Powerlines.

87
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

stormie-botsullivanpj

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:jiti AI (phantom-deps): Config-file reference pattern; stable false positive for this package. ai
source-diff source-size-dropped AI (source-diff): Size drop reflects dep removal refactor, not stub replacement; consistent with diff showing many deps removed. ai
source-diff large-new-source-files AI (source-diff): Active monorepo with frequent large refactors; SLSA provenance confirms CI/CD build integrity. ai
publish-pattern new-deps-added AI (publish-pattern): tinypool is a legitimate worker-pool lib replacing piscina; no malicious history. ai
phantom-deps phantom-dep:@stryke/http AI (phantom-deps): Part of the @stryke/* ecosystem used by this package; likely referenced via config/re-export pattern. ai
phantom-deps phantom-dep:ua-parser-modern AI (phantom-deps): Legitimate dep used indirectly via config; stable false positive for this package. ai
phantom-deps phantom-dep:@stryke/json AI (phantom-deps): Part of the @stryke/* ecosystem used by this package; likely referenced via config/re-export pattern. ai
phantom-deps phantom-dep:@stryke/hash AI (phantom-deps): Part of the @stryke/* ecosystem used by this package; likely referenced via config/re-export pattern. ai
phantom-deps phantom-dep:structured-clone-es AI (phantom-deps): Same bundled build pattern; stable false positive for this package. ai
phantom-deps phantom-dep:birpc AI (phantom-deps): Bundled build artifact; phantom-dep heuristic fires on bundled deps not directly imported in source. ai
phantom-deps phantom-dep:unplugin AI (phantom-deps): Build tool dependency referenced in config files; common pattern in monorepo packages and does not indicate supply chain risk. ai
phantom-deps phantom-dep:@stryke/async AI (phantom-deps): Phantom dependency pattern is expected in monorepo build tools; declared but referenced only in config files, not directly imported. ai
phantom-deps phantom-dep:@jridgewell/sourcemap-codec AI (phantom-deps): Declared runtime dep referenced in config files. Standard pattern for this build-tool package. ai
phantom-deps phantom-dep:@storm-software/config AI (phantom-deps): First-party Storm Software dep referenced in config files. Standard pattern for this ecosystem. ai
phantom-deps phantom-dep:locate-character AI (phantom-deps): locate-character is a declared runtime dep referenced in config files. Standard pattern for this build-tool package. ai
phantom-deps phantom-dep:oxc-resolver AI (phantom-deps): oxc-resolver is a declared runtime dep referenced in config files. Standard pattern for this build-tool package. ai
phantom-deps phantom-dep:unimport AI (phantom-deps): unimport is a declared runtime dep used in build config files, not directly imported. Consistent pattern for this build-tool package. ai
phantom-deps phantom-dep:@cacheable/memory AI (phantom-deps): Declared runtime dep referenced in config files. Standard pattern for this build-tool package. ai
dependencies unvetted-dep:@powerlines/core AI (dependencies): Sibling package from the same Storm Software / Powerlines org; consistent with the package's stated purpose. ai
bogus-package bogus-package AI (bogus-package): Minor quality signals (off-topic README content, no keywords) with no security implications for this legitimate Storm Software package. ai
dependencies unvetted-dep:handlebars AI (dependencies): Handlebars is a well-known templating library; ^4.7.9 targets a patched version. No security concern for this package. ai

Versions (showing 87 of 87)

Version Deps Published
0.49.90 29 / 4
0.49.89 29 / 4
0.49.88 29 / 4
0.49.87 29 / 4
0.49.86 29 / 4
0.49.85 29 / 4
0.49.84 29 / 4
0.49.83 29 / 4
0.49.82 29 / 4
0.49.81 29 / 4
0.49.80 29 / 4
0.49.79 29 / 4
0.49.78 29 / 4
0.49.77 29 / 4
0.49.76 29 / 4
0.49.75 29 / 4
0.49.74 29 / 4
0.49.73 29 / 4
0.49.72 29 / 4
0.49.70 29 / 4
0.49.69 29 / 4
0.49.68 29 / 4
0.49.67 29 / 4
0.49.66 29 / 4
0.49.34 29 / 4
0.49.33 29 / 4
0.49.20 29 / 4
0.49.19 29 / 4
0.49.14 30 / 4
0.49.13 30 / 4
0.49.5 30 / 4
0.47.2 38 / 8
0.47.1 38 / 8
0.46.6 37 / 8
0.46.5 35 / 8
0.46.4 35 / 8
0.46.3 35 / 8
0.46.2 35 / 8
0.46.0 35 / 8
0.45.3 35 / 8
0.45.2 35 / 8
0.45.0 35 / 8
0.44.12 35 / 8
0.44.11 35 / 8
0.44.8 35 / 8
0.44.7 35 / 8
0.44.4 35 / 8
0.44.2 35 / 8
0.44.1 35 / 8
0.44.0 35 / 8
0.43.31 35 / 8
0.43.30 35 / 8
0.43.29 35 / 8
0.43.28 34 / 8
0.43.27 34 / 8
0.43.26 34 / 8
0.43.25 34 / 8
0.15.20 30 / 4
0.15.14 29 / 4
0.15.9 29 / 4
0.15.1 29 / 4
0.15.0 34 / 8
0.14.5 34 / 8
0.14.4 34 / 8
0.8.67 29 / 4
0.0.25 34 / 8
0.0.24 34 / 8
0.0.23 34 / 8
0.0.22 34 / 8
0.0.21 34 / 8
0.0.20 34 / 8
0.0.19 34 / 8
0.0.18 34 / 8
0.0.17 34 / 8
0.0.16 34 / 8
0.0.15 34 / 8
0.0.14 34 / 8
0.0.13 34 / 8
0.0.11 34 / 8
0.0.10 34 / 8
0.0.9 34 / 8
0.0.8 34 / 8
0.0.6 34 / 8
0.0.5 34 / 8
0.0.4 34 / 8
0.0.3 34 / 8
0.0.2 34 / 8

v0.49.90

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.49.89

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.49.88

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.49.87

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.49.86

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.49.85

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.49.84

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.49.83

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.49.82

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.49.81

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.49.80

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.49.79

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.49.78

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.49.77

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.49.76

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.49.75

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.49.74

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.49.73

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.49.72

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.49.70

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.49.69

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.49.68

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.49.67

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.49.66

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.