@powerlines/plugin-deepkit
A package containing a Powerlines plugin to assist in developing other Powerlines plugins.
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@power-plant/schema | AI (dependencies): Sibling-ecosystem scoped package from same trusted publisher; no malicious behavior evidenced. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): Routine dependency swap within Storm Software's own package family. | ai | |
| phantom-deps | phantom-dep:@storm-software/config-tools | AI (phantom-deps): Config-referenced dependency; stable pattern for this plugin package. | ai | |
| phantom-deps | phantom-dep:@stryke/type-checks | AI (phantom-deps): Config-referenced dependency; stable pattern for this plugin package. | ai | |
| phantom-deps | phantom-dep:@stryke/types | AI (phantom-deps): Config-referenced dependency; stable pattern for this plugin package. | ai | |
| phantom-deps | phantom-dep:@stryke/path | AI (phantom-deps): Config-referenced dependency; stable pattern for this plugin package. | ai | |
| phantom-deps | phantom-dep:@stryke/fs | AI (phantom-deps): Config-referenced dependency; stable pattern for this plugin package. | ai | |
| phantom-deps | phantom-dep:unplugin | AI (phantom-deps): Config-referenced dependency; stable pattern for this plugin package. | ai | |
| phantom-deps | phantom-dep:chalk | AI (phantom-deps): Config-referenced dependency; stable pattern for this plugin package. | ai | |
| phantom-deps | phantom-dep:jiti | AI (phantom-deps): Config-referenced dependency; stable pattern for this plugin package. | ai | |
| phantom-deps | phantom-dep:defu | AI (phantom-deps): Config-referenced dependency; stable pattern for this plugin package. | ai | |
| source-diff | obfuscated-file:dist/index.mjs | AI (source-diff): Minified build output from CI/CD pipeline with SLSA provenance. Code is readable path utilities + plugin wiring, not obfuscated. Stable pattern for this package. | ai | |
| source-diff | obfuscated-file:dist/index.cjs | AI (source-diff): Minified build output from CI/CD pipeline with SLSA provenance. Code is readable path utilities + plugin wiring, not obfuscated. Stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@powerlines/deepkit | AI (phantom-deps): Same org scope sibling dependency in a monorepo plugin; referenced in config files, not a direct import risk. | ai | |
| phantom-deps | phantom-dep:powerlines | AI (phantom-deps): Monorepo plugin package; powerlines is a peer/config-level dependency not directly imported in plugin code. Stable pattern for this package. | ai | |
| provenance | publisher-changed | AI (provenance): Publisher changed from stormie-bot to GitHub Actions — a legitimate CI/CD migration. SLSA provenance attestation confirms builds are from the verified GitHub Actions environment. | ai | |
| phantom-deps | phantom-dep:@powerlines/plugin-tsc | AI (phantom-deps): Same org scope sibling dependency in a monorepo plugin; referenced in config files, not a direct import risk. | ai | |
| dependencies | unvetted-dep:@powerlines/deepkit | AI (dependencies): First-party Storm Software (@powerlines scope) sibling package; consistent with the publisher's monorepo ecosystem. | ai | |
| dependencies | unvetted-dep:@stryke/json | AI (dependencies): First-party Storm Software (@stryke scope) package; consistent with the publisher's ecosystem pattern. | ai | |
| dependencies | unvetted-dep:powerlines | AI (dependencies): First-party Storm Software monorepo package; consistent with the publisher's ecosystem pattern across all versions. | ai | |
| phantom-deps | phantom-dep:@stryke/json | AI (phantom-deps): Phantom dep pattern is a packaging artifact of the Storm Software monorepo build; not a security concern. | ai | |
| phantom-deps | phantom-dep:typescript | AI (phantom-deps): TypeScript declared as dep but used only in config files; packaging hygiene issue, not a security concern for this package. | ai | |
| dependencies | unvetted-dep:@powerlines/plugin-tsc | AI (dependencies): First-party Storm Software (@powerlines scope) sibling package; consistent with the publisher's monorepo ecosystem. | ai | |
| provenance | slsa-provenance | AI (provenance): Storm Software consistently publishes with SLSA provenance via CI/CD; this is a stable positive signal for all versions of this package. | ai |
Versions (showing 100 of 630)
v0.11.505
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.504
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.503
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.502
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.501
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.500
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.499
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.498
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.497
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.496
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.495
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.494
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.493
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.492
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.490
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.489
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.488
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.487
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.486
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.485
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.484
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.483
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.482
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.