@powerlines/plugin-crypto
A Powerlines plugin that provides unique identifier generation capabilities at runtime by adding the `id` builtin module.
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@alloy-js/markdown | AI (phantom-deps): Sibling ecosystem package; consistent with prior accepted phantom-dep pattern for this package. | ai | |
| phantom-deps | phantom-dep:@alloy-js/json | AI (phantom-deps): Sibling ecosystem package; consistent with prior accepted phantom-dep pattern for this package. | ai | |
| phantom-deps | phantom-dep:@powerlines/plugin-env | AI (phantom-deps): Used in bundled dist sub-modules; phantom dep detection is a false positive for rolldown-bundled packages in this ecosystem. | ai | |
| phantom-deps | phantom-dep:defu | AI (phantom-deps): Used in bundled dist sub-modules; phantom dep detection is a false positive for rolldown-bundled packages in this ecosystem. | ai | |
| phantom-deps | phantom-dep:powerlines | AI (phantom-deps): Used in bundled dist sub-modules; phantom dep detection is a false positive for rolldown-bundled packages in this ecosystem. | ai | |
| provenance | publisher-changed | AI (provenance): Publisher changed from stormie-bot to GitHub Actions CI/CD — a legitimate automation transition confirmed by SLSA provenance attestation. Stable for this package. | ai | |
| source-diff | obfuscated-file:dist/plugin-env/src/helpers/reflect.cjs | AI (source-diff): Minified rolldown bundle for reflection helpers; standard TypeScript reflection logic. No malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/deepkit/schemas/reflection2.cjs | AI (source-diff): Minified rolldown bundle; variant of reflection schema with same safe patterns. No malicious content. | ai | |
| source-diff | obfuscated-file:dist/alloy/src/typescript/components/tsdoc.cjs | AI (source-diff): Minified rolldown bundle for TSDoc component; standard build artifact. No malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/alloy/src/typescript/components/typescript-file.cjs | AI (source-diff): Minified rolldown bundle for TypeScript file component; standard build artifact. No malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/deepkit/schemas/reflection.cjs | AI (source-diff): Minified rolldown bundle for Cap'n Proto schema definitions; standard struct accessor patterns. No malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/deepkit/src/capnp.cjs | AI (source-diff): Minified rolldown bundle output for Cap'n Proto serialization logic; no obfuscation, no malicious patterns. Standard build artifact for this package. | ai | |
| source-diff | obfuscated-file:dist/alloy/src/create-plugin.cjs | AI (source-diff): Minified rolldown bundle; implements plugin creation logic using @alloy-js/core. No malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/plugin-env/src/components/env.cjs | AI (source-diff): Minified rolldown bundle for env component rendering; uses standard JSX/alloy patterns. No malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/plugin-env/src/index.cjs | AI (source-diff): Minified rolldown bundle for plugin-env entry point; standard plugin configuration logic. No malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/plugin-env/src/helpers/persistence.cjs | AI (source-diff): Minified rolldown bundle for Cap'n Proto persistence helpers; uses @stryke/capnp and node:fs. No malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/index.mjs | AI (source-diff): dist/index.mjs is standard bundled ESM output from a monorepo build pipeline. Long lines are minification artifacts, not obfuscation. Imports are from well-known packages consistent with the package's stated purpose. | ai | |
| phantom-deps | phantom-dep:@stryke/path | AI (phantom-deps): Monorepo package from Storm Software ecosystem; declared for config tooling, not direct import. Consistent pattern across all versions. | ai | |
| phantom-deps | phantom-dep:@storm-software/config-tools | AI (phantom-deps): Monorepo package from Storm Software ecosystem; declared for config tooling, not direct import. Consistent pattern across all versions. | ai |
Versions (showing 51 of 695)
| Version | Deps | Published |
|---|---|---|
| 0.10.675 | 12 / 2 | |
| 0.10.674 | 12 / 2 | |
| 0.10.673 | 6 / 2 | |
| 0.10.672 | 6 / 2 | |
| 0.10.671 | 6 / 2 | |
| 0.10.670 | 6 / 2 | |
| 0.10.669 | 6 / 2 | |
| 0.10.668 | 6 / 2 | |
| 0.10.667 | 6 / 2 | |
| 0.10.666 | 6 / 2 | |
| 0.10.665 | 6 / 2 | |
| 0.10.664 | 6 / 2 | |
| 0.10.663 | 6 / 2 | |
| 0.10.662 | 6 / 2 | |
| 0.10.660 | 6 / 2 | |
| 0.10.659 | 6 / 2 | |
| 0.10.658 | 6 / 2 | |
| 0.10.657 | 6 / 2 | |
| 0.10.656 | 6 / 2 | |
| 0.10.655 | 6 / 2 | |
| 0.10.654 | 6 / 2 | |
| 0.10.653 | 6 / 2 | |
| 0.10.652 | 6 / 2 | |
| 0.10.651 | 6 / 2 | |
| 0.10.650 | 6 / 2 | |
| 0.10.649 | 6 / 2 | |
| 0.10.648 | 6 / 2 | |
| 0.10.647 | 6 / 2 | |
| 0.10.646 | 6 / 2 | |
| 0.10.645 | 6 / 2 | |
| 0.10.644 | 6 / 2 | |
| 0.10.643 | 6 / 2 | |
| 0.10.642 | 6 / 2 | |
| 0.10.641 | 6 / 2 | |
| 0.10.640 | 6 / 2 | |
| 0.10.639 | 6 / 2 | |
| 0.10.638 | 6 / 2 | |
| 0.10.637 | 6 / 2 | |
| 0.10.636 | 6 / 2 | |
| 0.10.635 | 6 / 2 | |
| 0.10.634 | 6 / 2 | |
| 0.10.633 | 6 / 2 | |
| 0.10.632 | 6 / 2 | |
| 0.10.631 | 6 / 2 | |
| 0.10.630 | 6 / 2 | |
| 0.10.629 | 6 / 2 | |
| 0.10.628 | 6 / 2 | |
| 0.10.627 | 6 / 2 | |
| 0.10.626 | 6 / 2 | |
| 0.10.625 | 6 / 2 | |
| 0.10.624 | 6 / 2 |
v0.10.675
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.10.674
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.10.673
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.10.672
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.10.671
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.10.670
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.10.669
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.10.668
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.10.667
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.10.666
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.10.665
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.10.664
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.10.663
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.10.662
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.10.660
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.10.659
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.10.658
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.10.657
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.10.656
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.10.655
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.10.654
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.10.653
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.