← Home

@powerlines/plugin-biome

A package containing a Powerlines plugin for running Biome linting on the codebase.

100
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

stormie-botsullivanpj

Keywords

biomepowerlinesstorm-softwarepowerlines-plugin

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/index.mjs AI (source-diff): dist/index.mjs is standard bundler (tsup) minified output — fully readable logic, no malicious patterns. False positive for this package's build pipeline. ai
source-diff obfuscated-file:dist/index.cjs AI (source-diff): dist/index.cjs is standard tsup-minified output for this plugin package; code is fully readable and benign. Not obfuscation. ai
source-diff obfuscated-file:dist/index.js AI (source-diff): dist/index.js is standard tsup-minified output for this plugin package; code is fully readable and benign. Not obfuscation. ai
provenance publisher-changed AI (provenance): Publisher changed from stormie-bot to GitHub Actions, consistent with org migration to automated CI/CD. SLSA provenance attestation confirms controlled publish pipeline for Storm Software. ai
phantom-deps phantom-dep:@stryke/path AI (phantom-deps): @stryke/path is a legitimate dependency used by the plugin; declared in package.json. ai
phantom-deps phantom-dep:@stryke/convert AI (phantom-deps): @stryke/convert is a legitimate dependency used by the plugin; declared in package.json. ai
phantom-deps phantom-dep:defu AI (phantom-deps): defu is a legitimate dependency used in the plugin's runtime; declared and properly managed. ai
phantom-deps phantom-dep:@storm-software/config-tools AI (phantom-deps): @storm-software/config-tools is a legitimate dependency used by the plugin; declared in package.json. ai
phantom-deps phantom-dep:@stryke/fs AI (phantom-deps): @stryke/fs is a legitimate dependency used by the plugin; declared in package.json. ai
phantom-deps phantom-dep:powerlines AI (phantom-deps): powerlines is the core framework this plugin extends; legitimate dependency. ai
phantom-deps phantom-dep:@stryke/cli AI (phantom-deps): @stryke/cli is a legitimate dependency used by the plugin; declared in package.json. ai

Versions (showing 100 of 471)

Version Deps Published
0.2.630 7 / 3
0.2.629 7 / 3
0.2.628 7 / 3
0.2.627 7 / 3
0.2.626 7 / 3
0.2.625 7 / 3
0.2.624 7 / 3
0.2.623 7 / 3
0.2.622 7 / 3
0.2.621 7 / 3
0.2.620 7 / 3
0.2.619 7 / 3
0.2.618 7 / 3
0.2.617 7 / 3
0.2.616 7 / 3
0.2.614 7 / 3
0.2.613 7 / 3
0.2.612 7 / 3
0.2.611 7 / 3
0.2.610 7 / 3
0.2.609 7 / 3
0.2.608 7 / 3
0.2.607 7 / 3
0.2.606 7 / 2
0.2.605 7 / 2
0.2.604 7 / 2
0.2.603 7 / 2
0.2.602 7 / 2
0.2.601 7 / 2
0.2.600 7 / 2
0.2.599 7 / 2
0.2.598 7 / 2
0.2.597 7 / 2
0.2.596 7 / 2
0.2.595 7 / 2
0.2.594 7 / 2
0.2.593 7 / 2
0.2.592 7 / 2
0.2.591 7 / 2
0.2.590 7 / 2
0.2.589 7 / 2
0.2.588 7 / 2
0.2.587 7 / 2
0.2.586 7 / 2
0.2.585 7 / 2
0.2.584 7 / 2
0.2.583 7 / 2
0.2.582 7 / 2
0.2.581 7 / 2
0.2.580 7 / 2
0.2.579 7 / 2
0.2.578 7 / 2
0.2.577 7 / 2
0.2.576 7 / 2
0.2.575 7 / 2
0.2.574 7 / 2
0.2.573 7 / 2
0.2.572 7 / 2
0.2.571 7 / 2
0.2.570 7 / 2
0.2.569 7 / 2
0.2.568 7 / 2
0.2.567 7 / 2
0.2.566 7 / 2
0.2.565 7 / 2
0.2.564 7 / 2
0.2.563 7 / 2
0.2.562 7 / 2
0.2.561 7 / 2
0.2.560 7 / 2
0.2.559 7 / 2
0.2.558 7 / 2
0.2.557 7 / 2
0.2.556 7 / 2
0.2.555 7 / 2
0.2.554 7 / 2
0.2.553 7 / 2
0.2.552 7 / 2
0.2.551 7 / 2
0.2.550 7 / 2
0.2.548 7 / 2
0.2.547 7 / 2
0.2.546 7 / 2
0.2.545 7 / 2
0.2.544 7 / 2
0.2.543 7 / 2
0.2.542 7 / 2
0.2.541 7 / 2
0.2.540 7 / 2
0.2.539 7 / 2
0.2.538 7 / 2
0.2.537 7 / 2
0.2.536 7 / 2
0.2.535 7 / 2
0.2.534 7 / 2
0.2.533 7 / 2
0.2.532 7 / 2
0.2.531 7 / 2
0.2.530 7 / 2
0.2.529 7 / 2
Showing 100 of 471 Next page →

v0.2.630

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.629

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.628

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.627

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.626

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.625

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.624

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.623

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.622

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.621

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.620

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.619

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.618

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.617

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.616

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.614

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.613

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.612

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.611

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.610

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.609

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.608

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.607

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.