← Home

@powerlines/plugin-date

A package containing a Powerlines plugin for injecting static .env configuration values to the code so that they're accessible at runtime.

62
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

stormie-botsullivanpj

Keywords

powerlinesstorm-softwarepowerlines-plugin

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Publisher changed from stormie-bot to GitHub Actions with SLSA provenance attestation — this is a supply chain improvement (CI/CD automation), not a compromise indicator. ai
source-diff obfuscated-file:dist/deepkit/src/capnp.cjs AI (source-diff): Minified rolldown bundle output, not obfuscated malware. Code handles Cap'n Proto serialization for type reflection — legitimate build artifact for this package. ai
source-diff obfuscated-file:dist/alloy/src/create-plugin.cjs AI (source-diff): Minified rolldown bundle output. Code implements plugin creation with @alloy-js code generation — consistent with package purpose. ai
source-diff obfuscated-file:dist/plugin-env/src/components/env.cjs AI (source-diff): Minified rolldown bundle output. Code generates TypeScript env interfaces — legitimate build artifact. ai
source-diff obfuscated-file:dist/plugin-env/src/index.cjs AI (source-diff): Minified rolldown bundle output. Code implements env plugin configuration — legitimate build artifact. ai
source-diff obfuscated-file:dist/plugin-env/src/helpers/persistence.cjs AI (source-diff): Minified rolldown bundle output. Code handles Cap'n Proto serialization for env type persistence — legitimate build artifact. ai
source-diff obfuscated-file:dist/plugin-env/src/helpers/reflect.cjs AI (source-diff): Minified rolldown bundle output. Code creates reflection classes for env/secrets configuration — legitimate build artifact. ai
source-diff obfuscated-file:dist/deepkit/schemas/reflection.cjs AI (source-diff): Minified rolldown bundle output. Code defines Cap'n Proto struct classes for type reflection schemas — legitimate build artifact. ai
source-diff obfuscated-file:dist/deepkit/schemas/reflection2.cjs AI (source-diff): Minified rolldown bundle output. Code defines Cap'n Proto struct classes (updated version) — legitimate build artifact. ai
phantom-deps phantom-dep:@stryke/path AI (phantom-deps): Declared dependency referenced in config files; typical for monorepo build tooling. ai
phantom-deps phantom-dep:@powerlines/plugin-env AI (phantom-deps): Same-org scoped dependency; legitimate for plugin ecosystem integration. ai
phantom-deps phantom-dep:@storm-software/config-tools AI (phantom-deps): Declared dependency referenced in config files; expected for Storm Software monorepo packages. ai
phantom-deps phantom-dep:powerlines AI (phantom-deps): Legitimate dependency for Powerlines plugin; referenced in config and used indirectly through plugin system. ai
dependencies unvetted-dep:powerlines AI (dependencies): Part of the same Storm Software/Powerlines monorepo ecosystem; sibling package not yet greenflagged, not an independent risk. ai
dependencies unvetted-dep:@powerlines/plugin-env AI (dependencies): Sibling package in the same @powerlines monorepo; unvetted only because it hasn't been greenflagged yet, not due to independent risk. ai
dependencies unvetted-dep:@storm-software/config-tools AI (dependencies): Storm Software ecosystem package; consistent organizational identity across all findings, not an independent risk signal. ai
dependencies unvetted-dep:@stryke/path AI (dependencies): Storm Software ecosystem package (@stryke scope); consistent organizational identity, not an independent risk signal. ai

Versions (showing 62 of 373)

Version Deps Published
0.12.45 4 / 3
0.12.44 4 / 3
0.12.43 4 / 3
0.12.42 4 / 3
0.12.41 4 / 3
0.12.40 4 / 3
0.12.39 4 / 3
0.12.38 4 / 3
0.12.37 4 / 3
0.12.36 4 / 3
0.12.35 4 / 3
0.12.33 4 / 3
0.12.32 4 / 3
0.12.31 4 / 3
0.12.30 4 / 3
0.12.29 4 / 3
0.12.28 4 / 3
0.12.25 4 / 3
0.12.24 4 / 3
0.12.23 4 / 3
0.12.22 4 / 3
0.12.21 4 / 3
0.12.20 4 / 3
0.12.19 4 / 3
0.12.18 4 / 3
0.12.17 4 / 3
0.12.16 4 / 3
0.12.15 4 / 3
0.12.14 4 / 3
0.12.13 4 / 3
0.12.12 4 / 3
0.12.11 4 / 3
0.12.10 4 / 3
0.12.9 4 / 3
0.12.8 4 / 3
0.12.7 4 / 3
0.12.6 4 / 3
0.12.5 4 / 3
0.12.4 4 / 3
0.12.3 4 / 3
0.12.2 4 / 3
0.12.1 4 / 3
0.12.0 4 / 3
0.11.3 4 / 3
0.11.2 4 / 3
0.11.1 4 / 3
0.11.0 4 / 3
0.10.0 4 / 3
0.9.1 4 / 3
0.9.0 4 / 3
0.8.2 4 / 3
0.8.1 4 / 3
0.8.0 4 / 3
0.7.0 4 / 3
0.6.1 4 / 3
0.6.0 4 / 3
0.5.0 4 / 3
0.4.0 4 / 3
0.3.0 4 / 3
0.2.0 4 / 4
0.1.1 4 / 4
0.1.0 4 / 4

v0.12.45

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.44

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.42

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.41

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.40

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.39

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.38

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.37

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.36

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.33

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.32

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.31

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.30

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.29

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.25

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.24

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.23

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.11.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.11.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.11.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.11.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.10.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.9.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.9.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.