← Home

@powerlines/plugin-env

A package containing a Powerlines plugin for injecting static .env configuration values to the code so that they're accessible at runtime.

100
Versions
Apache-2.0
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures gitHead linked

Maintainers

stormie-botsullivanpj

Keywords

dotenvpowerlinesstorm-softwarepowerlines-plugin

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@powerlines/plugin-power-plant AI (dependencies): Same-org sibling package in monorepo release train, not third-party. ai
publish-pattern new-deps-added AI (publish-pattern): Internal rename/split within trusted publisher's ecosystem, not injection of unrelated dep. ai
dependencies unvetted-dep:@power-plant/schema AI (dependencies): Sibling monorepo package replacing @powerlines/schema; same publisher/org pattern. ai
dependencies unvetted-dep:@power-plant/alloy-js AI (dependencies): Fits existing alloy-js plugin family already depended on; no malicious behavior evident. ai
source-diff source-size-tripled AI (source-diff): Size increase fully explained by inlinedDependencies bundling pattern documented in package.json. ai
source-diff large-new-source-files AI (source-diff): New files are inlined dependency bundles explicitly declared in package.json inlinedDependencies. ai
source-diff obfuscated-file:dist/json5-DEV_07Nb.cjs AI (source-diff): Bundled confbox/json5 dependency with long unicode regex lines; not obfuscated, just minified. ai
source-diff obfuscated-file:dist/load-DPB0maqs.cjs AI (source-diff): Bundled dotenv and other known deps; readable structure, hashed chunk filename is normal vite output. ai
source-diff obfuscated-file:dist/dist-C_a6goTt.cjs AI (source-diff): Standard rollup/vite bundle chunk with hashed filename; code is readable and references known deps. ai
source-diff obfuscated-file:dist/node_modules/.pnpm/[email protected]/node_modules/confbox/dist/json5.cjs AI (source-diff): Minified vendored dependency (confbox) bundled into dist/node_modules via pnpm; not malicious obfuscation. ai
phantom-deps phantom-dep:@alloy-js/markdown AI (phantom-deps): Config-referenced dep in monorepo plugin; stable false positive for this package. ai
phantom-deps phantom-dep:@powerlines/core AI (phantom-deps): Same org scope; likely loaded by convention or peer dependency pattern, stable false positive for this package. ai
provenance publisher-changed AI (provenance): stormie-bot is the org's established bot account with 2775 approved packages; transition from GH Actions to this account is expected org automation pattern. ai
source-diff obfuscated-file:dist/types/env.cjs AI (source-diff): Minified but fully readable build output for a new package export; no obfuscation or malicious patterns. ai
source-diff obfuscated-file:dist/types/env.mjs AI (source-diff): Same as .cjs counterpart — minified ESM build output, content is benign env variable metadata. ai
dependencies unvetted-dep:@powerlines/alloy AI (dependencies): @powerlines/alloy is a sibling package in the same org scope, published by the same Storm Software maintainer with 356 approved packages. Internal org dependency, not a third-party unknown. ai
source-diff obfuscated-file:dist/node_modules/.pnpm/[email protected]/node_modules/confbox/dist/_chunks/libs/json5.cjs AI (source-diff): Minified bundle of json5 parser from confbox package. Long line is a Unicode regex for JSON5 parsing — entirely benign. SLSA provenance confirms build integrity. ai
source-diff obfuscated-file:dist/node_modules/.pnpm/[email protected]/node_modules/jiti/dist/jiti.cjs AI (source-diff): Minified bundle of the legitimate jiti package included via rolldown bundling of pnpm deps. SLSA provenance attestation confirms CI build integrity. No malicious patterns in sample. ai
source-diff obfuscated-file:dist/node_modules/.pnpm/[email protected]/node_modules/node-fetch-native/dist/proxy.cjs AI (source-diff): Minified bundle of node-fetch-native proxy module using standard Node.js built-ins. No suspicious network calls or exfiltration. SLSA provenance confirms build integrity. ai
phantom-deps phantom-dep:@stryke/fs AI (phantom-deps): Part of the @powerlines monorepo ecosystem; phantom deps are expected for plugin packages loaded by convention or config, not direct import. ai
phantom-deps phantom-dep:@storm-software/config-tools AI (phantom-deps): Config tooling from the same org ecosystem; loaded by convention/config, stable false positive. ai
phantom-deps phantom-dep:@powerlines/plugin-babel AI (phantom-deps): Same-org plugin package from the @powerlines monorepo; loaded by plugin convention, not direct import. ai
phantom-deps phantom-dep:@stryke/string-format AI (phantom-deps): Same monorepo org utility package; loaded by config/convention, stable false positive. ai
phantom-deps phantom-dep:@alloy-js/typescript AI (phantom-deps): Framework-scoped package used via config/convention in the alloy-js ecosystem; stable false positive. ai
phantom-deps phantom-dep:@stryke/type-checks AI (phantom-deps): Same monorepo org utility package; loaded by config/convention, stable false positive. ai
phantom-deps phantom-dep:@powerlines/alloy AI (phantom-deps): Same-org package from the @powerlines monorepo; loaded by plugin convention, not direct import. ai
phantom-deps phantom-dep:@alloy-js/core AI (phantom-deps): Framework-scoped package used via config/convention in the alloy-js ecosystem; stable false positive. ai
phantom-deps phantom-dep:@stryke/types AI (phantom-deps): Type-only dependency from same org; not directly imported at runtime but declared for type resolution. ai
phantom-deps phantom-dep:@stryke/capnp AI (phantom-deps): Same monorepo org dependency loaded by config/convention; stable false positive for this plugin package. ai
phantom-deps phantom-dep:@stryke/env AI (phantom-deps): Same monorepo org dependency loaded by config/convention; stable false positive for this plugin package. ai
phantom-deps phantom-dep:@babel/core AI (phantom-deps): Framework-scoped package loaded by convention in Babel plugin ecosystems; stable false positive for this package. ai
phantom-deps phantom-dep:powerlines AI (phantom-deps): Core peer dependency of the @powerlines plugin ecosystem; loaded by convention, not direct import. ai
phantom-deps phantom-dep:@babel/types AI (phantom-deps): Framework-scoped package loaded by convention via @babel/core; stable pattern for Babel plugins. ai
phantom-deps phantom-dep:@powerlines/plugin-plugin AI (phantom-deps): Same-org scoped package loaded by convention in plugin ecosystem; stable for this package. ai
phantom-deps phantom-dep:@alloy-js/json AI (phantom-deps): Config-file referenced dependency; legitimate pattern in code generation frameworks. ai
phantom-deps phantom-dep:@stryke/json AI (phantom-deps): Config-file referenced dependency; legitimate pattern in config-driven tooling. ai

Versions (showing 100 of 572)

Version Deps Published
0.16.371 30 / 2
0.16.370 30 / 2
0.16.369 30 / 2
0.16.368 30 / 2
0.16.365 30 / 2
0.16.356 29 / 2
0.16.350 28 / 2
0.16.349 28 / 2
0.16.348 27 / 2
0.16.347 27 / 2
0.16.346 27 / 2
0.16.345 27 / 2
0.16.344 27 / 2
0.16.343 27 / 2
0.16.342 27 / 2
0.16.341 27 / 2
0.16.340 27 / 2
0.16.339 27 / 2
0.16.338 27 / 2
0.16.337 27 / 2
0.16.336 27 / 2
0.16.335 27 / 2
0.16.334 27 / 2
0.16.333 27 / 2
0.16.332 27 / 2
0.16.331 27 / 2
0.16.330 27 / 2
0.16.329 27 / 2
0.16.328 27 / 2
0.16.327 27 / 2
0.16.326 27 / 2
0.16.325 27 / 2
0.16.324 27 / 2
0.16.323 27 / 2
0.16.322 27 / 2
0.16.321 27 / 2
0.16.320 27 / 2
0.16.319 27 / 2
0.16.318 27 / 2
0.16.317 27 / 2
0.16.316 27 / 2
0.16.315 27 / 2
0.16.314 27 / 2
0.16.313 27 / 2
0.16.312 27 / 2
0.16.311 27 / 2
0.16.310 27 / 2
0.16.309 27 / 2
0.16.308 27 / 2
0.16.307 27 / 2
0.16.306 27 / 2
0.16.305 27 / 2
0.16.304 27 / 2
0.16.303 27 / 2
0.16.291 27 / 2
0.16.290 27 / 2
0.16.289 27 / 2
0.16.288 27 / 2
0.16.287 27 / 2
0.16.286 27 / 2
0.16.285 27 / 2
0.16.283 27 / 2
0.16.282 27 / 2
0.16.281 27 / 2
0.16.280 27 / 2
0.16.279 27 / 2
0.16.278 27 / 2
0.16.277 27 / 2
0.16.276 27 / 2
0.16.275 27 / 2
0.16.274 27 / 2
0.16.273 27 / 2
0.16.272 27 / 2
0.16.271 27 / 2
0.16.270 27 / 2
0.16.269 27 / 2
0.16.268 27 / 2
0.16.267 27 / 2
0.16.266 27 / 2
0.16.265 27 / 2
0.16.264 27 / 2
0.16.263 27 / 2
0.16.262 27 / 2
0.16.261 27 / 2
0.16.260 27 / 2
0.16.259 27 / 2
0.16.258 27 / 2
0.16.257 27 / 2
0.16.256 27 / 2
0.16.255 27 / 2
0.16.254 27 / 2
0.16.253 27 / 2
0.16.252 27 / 2
0.16.251 27 / 2
0.16.250 27 / 2
0.16.241 27 / 2
0.16.240 27 / 2
0.16.238 27 / 2
0.16.237 27 / 2
0.16.236 27 / 2
Showing 100 of 572 Next page →

v0.16.371

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.370

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.369

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.368

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.365

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.356

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.350

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.349

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.348

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.347

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.346

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.345

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.344

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.