@powerlines/nx
A Nx plugin to support Powerlines development in Nx monorepos.
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): stormie-bot is the established bot publisher for storm-software org packages with strong track record; transition from GH Actions is expected CI automation change. | ai | |
| phantom-deps | phantom-dep:@storm-software/build-tools | AI (phantom-deps): @storm-software/build-tools is used in config files for this build tooling package; not directly imported in source but legitimately referenced. Stable false positive for this package. | ai | |
| typosquat | typosquat.levenshtein:knex | AI (typosquat): @powerlines/nx is a scoped Nx plugin package, not a typosquat of 'knex'. The name is meaningful and intentional. | ai | |
| typosquat | typosquat.levenshtein:pg | AI (typosquat): @powerlines/nx is a scoped Nx plugin package, not a typosquat of 'pg'. The name is meaningful and intentional. | ai | |
| typosquat | typosquat.levenshtein:next | AI (typosquat): @powerlines/nx is a scoped Nx plugin package, not a typosquat of 'next'. The name is meaningful and intentional. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Package is a legitimate Nx plugin with SLSA provenance, 432 versions, and 1.1k weekly downloads. Cosmetic README/keyword issues are not security concerns. | ai | |
| typosquat | typosquat.levenshtein:qs | AI (typosquat): @powerlines/nx is a scoped Nx plugin package, not a typosquat of 'qs'. The name is meaningful and intentional. | ai | |
| typosquat | typosquat.levenshtein:nuxt | AI (typosquat): @powerlines/nx is a scoped Nx plugin package, not a typosquat of 'nuxt'. The name is meaningful and intentional. | ai |
Versions (showing 51 of 627)
| Version | Deps | Published |
|---|---|---|
| 0.13.204 | 15 / 11 | |
| 0.13.203 | 15 / 11 | |
| 0.13.202 | 15 / 11 | |
| 0.13.201 | 15 / 11 | |
| 0.13.200 | 15 / 11 | |
| 0.13.199 | 15 / 11 | |
| 0.13.198 | 15 / 11 | |
| 0.13.197 | 15 / 11 | |
| 0.13.196 | 15 / 11 | |
| 0.13.195 | 15 / 11 | |
| 0.13.194 | 15 / 11 | |
| 0.13.193 | 15 / 11 | |
| 0.13.192 | 15 / 11 | |
| 0.13.191 | 15 / 11 | |
| 0.13.190 | 15 / 11 | |
| 0.13.189 | 15 / 11 | |
| 0.13.188 | 15 / 11 | |
| 0.13.186 | 15 / 11 | |
| 0.13.185 | 15 / 11 | |
| 0.13.184 | 15 / 11 | |
| 0.13.183 | 15 / 11 | |
| 0.13.182 | 15 / 11 | |
| 0.13.181 | 15 / 11 | |
| 0.13.180 | 15 / 11 | |
| 0.13.179 | 15 / 11 | |
| 0.13.178 | 15 / 10 | |
| 0.13.177 | 15 / 10 | |
| 0.13.176 | 15 / 10 | |
| 0.13.175 | 15 / 10 | |
| 0.13.174 | 15 / 10 | |
| 0.13.173 | 15 / 10 | |
| 0.13.172 | 15 / 10 | |
| 0.13.171 | 15 / 10 | |
| 0.13.170 | 15 / 10 | |
| 0.13.169 | 15 / 10 | |
| 0.13.168 | 15 / 10 | |
| 0.13.167 | 15 / 10 | |
| 0.13.166 | 15 / 10 | |
| 0.13.165 | 15 / 10 | |
| 0.13.164 | 15 / 10 | |
| 0.13.163 | 15 / 10 | |
| 0.13.162 | 15 / 10 | |
| 0.13.161 | 15 / 10 | |
| 0.13.160 | 15 / 10 | |
| 0.13.159 | 15 / 10 | |
| 0.13.158 | 15 / 10 | |
| 0.13.157 | 15 / 10 | |
| 0.13.156 | 15 / 10 | |
| 0.13.155 | 15 / 10 | |
| 0.13.154 | 15 / 10 | |
| 0.13.153 | 15 / 10 |
v0.13.204
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.203
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.202
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.201
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.200
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.199
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.198
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.197
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.196
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.195
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.194
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.193
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.192
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.191
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.190
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.189
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.188
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.186
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.185
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.184
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.183
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.182
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.181
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.180
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.179
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.178
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.