← Home

@powerlines/plugin-biome

A package containing a Powerlines plugin for running Biome linting on the codebase.

51
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

stormie-botsullivanpj

Keywords

biomepowerlinesstorm-softwarepowerlines-plugin

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/index.mjs AI (source-diff): dist/index.mjs is standard bundler (tsup) minified output — fully readable logic, no malicious patterns. False positive for this package's build pipeline. ai
source-diff obfuscated-file:dist/index.cjs AI (source-diff): dist/index.cjs is standard tsup-minified output for this plugin package; code is fully readable and benign. Not obfuscation. ai
source-diff obfuscated-file:dist/index.js AI (source-diff): dist/index.js is standard tsup-minified output for this plugin package; code is fully readable and benign. Not obfuscation. ai
provenance publisher-changed AI (provenance): Publisher changed from stormie-bot to GitHub Actions, consistent with org migration to automated CI/CD. SLSA provenance attestation confirms controlled publish pipeline for Storm Software. ai
phantom-deps phantom-dep:@stryke/path AI (phantom-deps): @stryke/path is a legitimate dependency used by the plugin; declared in package.json. ai
phantom-deps phantom-dep:@stryke/convert AI (phantom-deps): @stryke/convert is a legitimate dependency used by the plugin; declared in package.json. ai
phantom-deps phantom-dep:defu AI (phantom-deps): defu is a legitimate dependency used in the plugin's runtime; declared and properly managed. ai
phantom-deps phantom-dep:@storm-software/config-tools AI (phantom-deps): @storm-software/config-tools is a legitimate dependency used by the plugin; declared in package.json. ai
phantom-deps phantom-dep:@stryke/fs AI (phantom-deps): @stryke/fs is a legitimate dependency used by the plugin; declared in package.json. ai
phantom-deps phantom-dep:powerlines AI (phantom-deps): powerlines is the core framework this plugin extends; legitimate dependency. ai
phantom-deps phantom-dep:@stryke/cli AI (phantom-deps): @stryke/cli is a legitimate dependency used by the plugin; declared in package.json. ai

Versions (showing 51 of 471)

View all versions
Version Deps Published
0.2.630 7 / 3
0.2.629 7 / 3
0.2.628 7 / 3
0.2.627 7 / 3
0.2.626 7 / 3
0.2.625 7 / 3
0.2.624 7 / 3
0.2.623 7 / 3
0.2.622 7 / 3
0.2.621 7 / 3
0.2.620 7 / 3
0.2.619 7 / 3
0.2.618 7 / 3
0.2.617 7 / 3
0.2.616 7 / 3
0.2.614 7 / 3
0.2.613 7 / 3
0.2.612 7 / 3
0.2.611 7 / 3
0.2.610 7 / 3
0.2.609 7 / 3
0.2.608 7 / 3
0.2.607 7 / 3
0.2.606 7 / 2
0.2.605 7 / 2
0.2.604 7 / 2
0.2.603 7 / 2
0.2.602 7 / 2
0.2.601 7 / 2
0.2.600 7 / 2
0.2.599 7 / 2
0.2.598 7 / 2
0.2.597 7 / 2
0.2.596 7 / 2
0.2.595 7 / 2
0.2.594 7 / 2
0.2.593 7 / 2
0.2.592 7 / 2
0.2.591 7 / 2
0.2.590 7 / 2
0.2.589 7 / 2
0.2.588 7 / 2
0.2.587 7 / 2
0.2.586 7 / 2
0.2.585 7 / 2
0.2.584 7 / 2
0.2.583 7 / 2
0.2.582 7 / 2
0.2.581 7 / 2
0.2.580 7 / 2
0.2.579 7 / 2

v0.2.630

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.629

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.628

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.627

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.626

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.625

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.624

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.623

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.622

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.621

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.620

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.619

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.618

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.617

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.616

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.614

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.613

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.612

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.611

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.610

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.609

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.608

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.607

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.