@powerlines/plugin-deepkit
A package containing a Powerlines plugin to assist in developing other Powerlines plugins.
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:defu | AI (phantom-deps): Config-referenced dependency; stable pattern for this plugin package. | ai | |
| phantom-deps | phantom-dep:@storm-software/config-tools | AI (phantom-deps): Config-referenced dependency; stable pattern for this plugin package. | ai | |
| phantom-deps | phantom-dep:@stryke/type-checks | AI (phantom-deps): Config-referenced dependency; stable pattern for this plugin package. | ai | |
| phantom-deps | phantom-dep:@stryke/types | AI (phantom-deps): Config-referenced dependency; stable pattern for this plugin package. | ai | |
| phantom-deps | phantom-dep:@stryke/path | AI (phantom-deps): Config-referenced dependency; stable pattern for this plugin package. | ai | |
| phantom-deps | phantom-dep:@stryke/fs | AI (phantom-deps): Config-referenced dependency; stable pattern for this plugin package. | ai | |
| phantom-deps | phantom-dep:unplugin | AI (phantom-deps): Config-referenced dependency; stable pattern for this plugin package. | ai | |
| phantom-deps | phantom-dep:chalk | AI (phantom-deps): Config-referenced dependency; stable pattern for this plugin package. | ai | |
| phantom-deps | phantom-dep:jiti | AI (phantom-deps): Config-referenced dependency; stable pattern for this plugin package. | ai | |
| source-diff | obfuscated-file:dist/index.cjs | AI (source-diff): Minified build output from CI/CD pipeline with SLSA provenance. Code is readable path utilities + plugin wiring, not obfuscated. Stable pattern for this package. | ai | |
| source-diff | obfuscated-file:dist/index.mjs | AI (source-diff): Minified build output from CI/CD pipeline with SLSA provenance. Code is readable path utilities + plugin wiring, not obfuscated. Stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@powerlines/deepkit | AI (phantom-deps): Same org scope sibling dependency in a monorepo plugin; referenced in config files, not a direct import risk. | ai | |
| phantom-deps | phantom-dep:powerlines | AI (phantom-deps): Monorepo plugin package; powerlines is a peer/config-level dependency not directly imported in plugin code. Stable pattern for this package. | ai | |
| provenance | publisher-changed | AI (provenance): Publisher changed from stormie-bot to GitHub Actions — a legitimate CI/CD migration. SLSA provenance attestation confirms builds are from the verified GitHub Actions environment. | ai | |
| phantom-deps | phantom-dep:@powerlines/plugin-tsc | AI (phantom-deps): Same org scope sibling dependency in a monorepo plugin; referenced in config files, not a direct import risk. | ai | |
| dependencies | unvetted-dep:@powerlines/deepkit | AI (dependencies): First-party Storm Software (@powerlines scope) sibling package; consistent with the publisher's monorepo ecosystem. | ai | |
| dependencies | unvetted-dep:@stryke/json | AI (dependencies): First-party Storm Software (@stryke scope) package; consistent with the publisher's ecosystem pattern. | ai | |
| phantom-deps | phantom-dep:@stryke/json | AI (phantom-deps): Phantom dep pattern is a packaging artifact of the Storm Software monorepo build; not a security concern. | ai | |
| dependencies | unvetted-dep:powerlines | AI (dependencies): First-party Storm Software monorepo package; consistent with the publisher's ecosystem pattern across all versions. | ai | |
| phantom-deps | phantom-dep:typescript | AI (phantom-deps): TypeScript declared as dep but used only in config files; packaging hygiene issue, not a security concern for this package. | ai | |
| dependencies | unvetted-dep:@powerlines/plugin-tsc | AI (dependencies): First-party Storm Software (@powerlines scope) sibling package; consistent with the publisher's monorepo ecosystem. | ai | |
| provenance | slsa-provenance | AI (provenance): Storm Software consistently publishes with SLSA provenance via CI/CD; this is a stable positive signal for all versions of this package. | ai |
Versions (showing 51 of 596)
| Version | Deps | Published |
|---|---|---|
| 0.11.470 | 6 / 2 | |
| 0.11.469 | 6 / 2 | |
| 0.11.468 | 6 / 2 | |
| 0.11.467 | 6 / 2 | |
| 0.11.466 | 6 / 2 | |
| 0.11.465 | 6 / 2 | |
| 0.11.464 | 6 / 2 | |
| 0.11.463 | 6 / 2 | |
| 0.11.462 | 6 / 2 | |
| 0.11.461 | 6 / 2 | |
| 0.11.460 | 6 / 2 | |
| 0.11.459 | 6 / 2 | |
| 0.11.458 | 6 / 2 | |
| 0.11.457 | 6 / 2 | |
| 0.11.456 | 6 / 2 | |
| 0.11.455 | 6 / 2 | |
| 0.11.454 | 6 / 2 | |
| 0.11.453 | 6 / 2 | |
| 0.11.452 | 6 / 2 | |
| 0.11.451 | 6 / 2 | |
| 0.11.450 | 6 / 2 | |
| 0.11.449 | 6 / 2 | |
| 0.11.448 | 6 / 2 | |
| 0.11.447 | 6 / 2 | |
| 0.11.446 | 6 / 2 | |
| 0.11.445 | 6 / 2 | |
| 0.11.444 | 6 / 2 | |
| 0.11.443 | 6 / 2 | |
| 0.11.442 | 6 / 2 | |
| 0.11.441 | 6 / 2 | |
| 0.11.440 | 6 / 2 | |
| 0.11.439 | 6 / 2 | |
| 0.11.438 | 6 / 2 | |
| 0.11.437 | 6 / 2 | |
| 0.11.436 | 6 / 2 | |
| 0.11.435 | 6 / 2 | |
| 0.11.434 | 6 / 2 | |
| 0.11.433 | 6 / 2 | |
| 0.11.432 | 6 / 2 | |
| 0.11.431 | 6 / 2 | |
| 0.11.430 | 6 / 2 | |
| 0.11.429 | 6 / 2 | |
| 0.11.428 | 6 / 2 | |
| 0.11.427 | 6 / 2 | |
| 0.11.426 | 6 / 2 | |
| 0.11.424 | 6 / 2 | |
| 0.11.423 | 6 / 2 | |
| 0.11.422 | 6 / 2 | |
| 0.11.421 | 6 / 2 | |
| 0.11.420 | 6 / 2 | |
| 0.11.419 | 6 / 2 |
v0.11.470
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.469
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.468
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.467
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.466
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.465
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.464
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.463
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.462
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.461
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.460
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.459
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.458
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.457
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.456
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.455
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.454
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.453
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.452
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.451
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.450
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.449
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.448
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.447
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.446
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.445
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.444
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.443
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.442
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.441
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.440
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.439
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.438
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.437
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.436
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.435
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.434
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.433
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.432
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.431
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.430
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.429
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.428
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.427
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.426
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.424
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.423
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.422
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.421
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.420
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.419
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.