← Home

@powerlines/plugin-asyncapi

A Powerlines plugin to generate project code from AsyncAPI specifications.

51
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

stormie-botsullivanpj

Keywords

asyncapipowerlinesstorm-softwarepowerlines-plugin

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@power-plant/core AI (dependencies): Sibling package in same publisher's monorepo ecosystem. ai
phantom-deps phantom-dep:@power-plant/core AI (phantom-deps): Likely used via bundled build output; no behavior signal. ai
dependencies unvetted-dep:@power-plant/asyncapi AI (dependencies): Sibling package in same publisher's monorepo ecosystem. ai
dependencies unvetted-dep:@powerlines/plugin-power-plant AI (dependencies): Sibling package in same publisher's monorepo ecosystem. ai
provenance publisher-changed AI (provenance): stormie-bot is the established bot publisher for storm-software packages with strong track record; SLSA attestation confirms CI/CD origin. ai
source-diff source-size-dropped AI (source-diff): Normal refactoring in active plugin package; no malicious indicators. ai
dependencies unvetted-dep:@asyncapi/generator AI (dependencies): @asyncapi/generator is the official AsyncAPI Initiative code generator; its use is expected and appropriate for a package whose sole purpose is AsyncAPI code generation. ai
phantom-deps phantom-dep:@asyncapi/generator AI (phantom-deps): AsyncAPI generator is the core tool this plugin wraps; indirect/config-level usage is expected for a plugin package. ai
phantom-deps phantom-dep:defu AI (phantom-deps): Plugin package; dependencies used at runtime/config level rather than direct imports. Stable pattern for this package. ai
phantom-deps phantom-dep:@stryke/fs AI (phantom-deps): Part of the stryke ecosystem used by this plugin; referenced in config/runtime context, not direct imports. Expected pattern. ai
phantom-deps phantom-dep:powerlines AI (phantom-deps): This is a Powerlines plugin; powerlines is the host framework dependency used at runtime, not via direct import. ai
phantom-deps phantom-dep:@stryke/path AI (phantom-deps): Part of the stryke ecosystem; referenced in config/runtime context. Expected pattern for this plugin package. ai
phantom-deps phantom-dep:@asyncapi/parser AI (phantom-deps): AsyncAPI parser is a runtime dependency for AsyncAPI code generation; indirect usage via generator is expected. ai
phantom-deps phantom-dep:@stryke/http AI (phantom-deps): Part of the @stryke/* utility ecosystem used by this publisher; declared as dep for transitive/config use. Not a security concern. ai
phantom-deps phantom-dep:@stryke/convert AI (phantom-deps): Part of the @stryke/* utility ecosystem used by this publisher; declared as dep for transitive/config use. Not a security concern. ai

Versions (showing 51 of 585)

View all versions
Version Deps Published
0.1.610 7 / 2
0.1.609 7 / 2
0.1.608 7 / 2
0.1.607 7 / 2
0.1.606 7 / 2
0.1.605 7 / 2
0.1.604 7 / 2
0.1.603 7 / 2
0.1.602 7 / 2
0.1.601 7 / 2
0.1.600 7 / 2
0.1.599 7 / 2
0.1.598 7 / 2
0.1.597 7 / 2
0.1.596 7 / 2
0.1.595 7 / 2
0.1.594 7 / 2
0.1.593 7 / 2
0.1.592 7 / 2
0.1.591 7 / 2
0.1.590 7 / 2
0.1.589 7 / 2
0.1.588 7 / 2
0.1.587 7 / 2
0.1.586 7 / 2
0.1.585 7 / 2
0.1.584 7 / 2
0.1.583 7 / 2
0.1.582 7 / 2
0.1.581 7 / 2
0.1.580 7 / 2
0.1.579 7 / 2
0.1.578 7 / 2
0.1.577 7 / 2
0.1.576 7 / 2
0.1.575 7 / 2
0.1.574 7 / 2
0.1.573 7 / 2
0.1.572 7 / 2
0.1.571 7 / 2
0.1.570 7 / 2
0.1.569 7 / 2
0.1.568 7 / 2
0.1.567 7 / 2
0.1.566 7 / 2
0.1.565 7 / 2
0.1.564 7 / 2
0.1.563 7 / 2
0.1.562 7 / 2
0.1.561 7 / 2
0.1.560 7 / 2

v0.1.610

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.609

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.608

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.607

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.606

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.605

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.604

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.