@powerlines/plugin-content-collections
A Powerlines plugin to generate project code using Content Collections.
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): stormie-bot is the established bot publisher for storm-software packages with strong approval history; transition from GH Actions is expected. | ai | |
| phantom-deps | phantom-dep:defu | AI (phantom-deps): Declared in dependencies; referenced in config files. Stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:pluralize | AI (phantom-deps): Declared in dependencies; referenced in config files. Stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@stryke/fs | AI (phantom-deps): Declared in dependencies; referenced in config files. Stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:powerlines | AI (phantom-deps): Declared in dependencies; referenced in config files. Stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@standard-schema/spec | AI (phantom-deps): Declared in dependencies; referenced in config files. Stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@stryke/string-format | AI (phantom-deps): Declared in dependencies; referenced in config files. Stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@stryke/path | AI (phantom-deps): Declared in dependencies; referenced in config files. Stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@stryke/types | AI (phantom-deps): Declared in dependencies; referenced in config files. Stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@stryke/type-checks | AI (phantom-deps): @stryke/type-checks is part of the same Storm Software ecosystem; declared as a dep for type utilities used in config/types, not a security concern for this package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Signals are minor quality issues (boilerplate README, secondary empty export path). Not indicative of spam or malicious intent given the established publisher and SLSA provenance. | ai |
Versions (showing 51 of 553)
| Version | Deps | Published |
|---|---|---|
| 0.1.588 | 9 / 4 | |
| 0.1.587 | 9 / 4 | |
| 0.1.586 | 9 / 4 | |
| 0.1.585 | 9 / 4 | |
| 0.1.584 | 9 / 4 | |
| 0.1.583 | 9 / 4 | |
| 0.1.582 | 9 / 4 | |
| 0.1.581 | 9 / 4 | |
| 0.1.580 | 9 / 4 | |
| 0.1.579 | 9 / 4 | |
| 0.1.578 | 9 / 4 | |
| 0.1.577 | 9 / 4 | |
| 0.1.576 | 9 / 4 | |
| 0.1.575 | 9 / 4 | |
| 0.1.574 | 9 / 4 | |
| 0.1.573 | 9 / 4 | |
| 0.1.572 | 9 / 4 | |
| 0.1.571 | 9 / 4 | |
| 0.1.570 | 9 / 4 | |
| 0.1.569 | 9 / 4 | |
| 0.1.568 | 9 / 4 | |
| 0.1.567 | 9 / 4 | |
| 0.1.566 | 9 / 4 | |
| 0.1.565 | 9 / 4 | |
| 0.1.564 | 9 / 4 | |
| 0.1.563 | 9 / 4 | |
| 0.1.562 | 9 / 4 | |
| 0.1.561 | 9 / 4 | |
| 0.1.549 | 9 / 4 | |
| 0.1.548 | 9 / 4 | |
| 0.1.547 | 9 / 4 | |
| 0.1.546 | 9 / 4 | |
| 0.1.545 | 9 / 4 | |
| 0.1.544 | 9 / 4 | |
| 0.1.542 | 9 / 4 | |
| 0.1.541 | 9 / 4 | |
| 0.1.540 | 9 / 4 | |
| 0.1.539 | 9 / 4 | |
| 0.1.538 | 9 / 4 | |
| 0.1.537 | 9 / 4 | |
| 0.1.536 | 9 / 4 | |
| 0.1.535 | 9 / 4 | |
| 0.1.534 | 9 / 4 | |
| 0.1.533 | 9 / 4 | |
| 0.1.532 | 9 / 4 | |
| 0.1.531 | 9 / 4 | |
| 0.1.530 | 9 / 4 | |
| 0.1.529 | 9 / 4 | |
| 0.1.528 | 9 / 4 | |
| 0.1.527 | 9 / 4 | |
| 0.1.526 | 9 / 4 |
v0.1.588
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.587
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.586
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.585
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.584
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.583
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.582
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.581
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.580
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.579
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.578
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.577
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.576
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.575
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.574
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.573
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.572
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.571
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.570
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.569
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.568
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.567
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.566
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.565
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.564
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.563
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.562
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.561
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.549
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.548
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.547
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.546
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.545
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.544
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.542
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.541
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.540
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.539
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.538
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.537
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.536
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.535
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.534
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.533
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.532
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.531
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.530
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.529
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.528
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.527
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.526
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.