← Home

@powerlines/plugin-env

A package containing a Powerlines plugin for injecting static .env configuration values to the code so that they're accessible at runtime.

100
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

stormie-botsullivanpj

Keywords

dotenvpowerlinesstorm-softwarepowerlines-plugin

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff source-size-tripled AI (source-diff): Size increase fully explained by inlinedDependencies bundling pattern documented in package.json. ai
source-diff large-new-source-files AI (source-diff): New files are inlined dependency bundles explicitly declared in package.json inlinedDependencies. ai
source-diff obfuscated-file:dist/load-DPB0maqs.cjs AI (source-diff): Bundled dotenv and other known deps; readable structure, hashed chunk filename is normal vite output. ai
source-diff obfuscated-file:dist/json5-DEV_07Nb.cjs AI (source-diff): Bundled confbox/json5 dependency with long unicode regex lines; not obfuscated, just minified. ai
source-diff obfuscated-file:dist/dist-C_a6goTt.cjs AI (source-diff): Standard rollup/vite bundle chunk with hashed filename; code is readable and references known deps. ai
source-diff obfuscated-file:dist/node_modules/.pnpm/[email protected]/node_modules/confbox/dist/json5.cjs AI (source-diff): Minified vendored dependency (confbox) bundled into dist/node_modules via pnpm; not malicious obfuscation. ai
phantom-deps phantom-dep:@alloy-js/markdown AI (phantom-deps): Config-referenced dep in monorepo plugin; stable false positive for this package. ai
provenance publisher-changed AI (provenance): stormie-bot is the org's established bot account with 2775 approved packages; transition from GH Actions to this account is expected org automation pattern. ai
phantom-deps phantom-dep:@powerlines/core AI (phantom-deps): Same org scope; likely loaded by convention or peer dependency pattern, stable false positive for this package. ai
source-diff obfuscated-file:dist/types/env.cjs AI (source-diff): Minified but fully readable build output for a new package export; no obfuscation or malicious patterns. ai
source-diff obfuscated-file:dist/types/env.mjs AI (source-diff): Same as .cjs counterpart — minified ESM build output, content is benign env variable metadata. ai
dependencies unvetted-dep:@powerlines/alloy AI (dependencies): @powerlines/alloy is a sibling package in the same org scope, published by the same Storm Software maintainer with 356 approved packages. Internal org dependency, not a third-party unknown. ai
source-diff obfuscated-file:dist/node_modules/.pnpm/[email protected]/node_modules/jiti/dist/jiti.cjs AI (source-diff): Minified bundle of the legitimate jiti package included via rolldown bundling of pnpm deps. SLSA provenance attestation confirms CI build integrity. No malicious patterns in sample. ai
source-diff obfuscated-file:dist/node_modules/.pnpm/[email protected]/node_modules/confbox/dist/_chunks/libs/json5.cjs AI (source-diff): Minified bundle of json5 parser from confbox package. Long line is a Unicode regex for JSON5 parsing — entirely benign. SLSA provenance confirms build integrity. ai
source-diff obfuscated-file:dist/node_modules/.pnpm/[email protected]/node_modules/node-fetch-native/dist/proxy.cjs AI (source-diff): Minified bundle of node-fetch-native proxy module using standard Node.js built-ins. No suspicious network calls or exfiltration. SLSA provenance confirms build integrity. ai
phantom-deps phantom-dep:@storm-software/config-tools AI (phantom-deps): Config tooling from the same org ecosystem; loaded by convention/config, stable false positive. ai
phantom-deps phantom-dep:@stryke/fs AI (phantom-deps): Part of the @powerlines monorepo ecosystem; phantom deps are expected for plugin packages loaded by convention or config, not direct import. ai
phantom-deps phantom-dep:powerlines AI (phantom-deps): Core peer dependency of the @powerlines plugin ecosystem; loaded by convention, not direct import. ai
phantom-deps phantom-dep:@babel/core AI (phantom-deps): Framework-scoped package loaded by convention in Babel plugin ecosystems; stable false positive for this package. ai
phantom-deps phantom-dep:@stryke/env AI (phantom-deps): Same monorepo org dependency loaded by config/convention; stable false positive for this plugin package. ai
phantom-deps phantom-dep:@stryke/capnp AI (phantom-deps): Same monorepo org dependency loaded by config/convention; stable false positive for this plugin package. ai
phantom-deps phantom-dep:@stryke/types AI (phantom-deps): Type-only dependency from same org; not directly imported at runtime but declared for type resolution. ai
phantom-deps phantom-dep:@alloy-js/core AI (phantom-deps): Framework-scoped package used via config/convention in the alloy-js ecosystem; stable false positive. ai
phantom-deps phantom-dep:@powerlines/alloy AI (phantom-deps): Same-org package from the @powerlines monorepo; loaded by plugin convention, not direct import. ai
phantom-deps phantom-dep:@stryke/type-checks AI (phantom-deps): Same monorepo org utility package; loaded by config/convention, stable false positive. ai
phantom-deps phantom-dep:@alloy-js/typescript AI (phantom-deps): Framework-scoped package used via config/convention in the alloy-js ecosystem; stable false positive. ai
phantom-deps phantom-dep:@stryke/string-format AI (phantom-deps): Same monorepo org utility package; loaded by config/convention, stable false positive. ai
phantom-deps phantom-dep:@powerlines/plugin-babel AI (phantom-deps): Same-org plugin package from the @powerlines monorepo; loaded by plugin convention, not direct import. ai
phantom-deps phantom-dep:@babel/types AI (phantom-deps): Framework-scoped package loaded by convention via @babel/core; stable pattern for Babel plugins. ai
phantom-deps phantom-dep:@powerlines/plugin-plugin AI (phantom-deps): Same-org scoped package loaded by convention in plugin ecosystem; stable for this package. ai
phantom-deps phantom-dep:@alloy-js/json AI (phantom-deps): Config-file referenced dependency; legitimate pattern in code generation frameworks. ai
phantom-deps phantom-dep:@stryke/json AI (phantom-deps): Config-file referenced dependency; legitimate pattern in config-driven tooling. ai

Versions (showing 100 of 554)

Version Deps Published
0.16.207 29 / 2
0.16.206 29 / 2
0.16.205 29 / 2
0.16.204 29 / 2
0.16.203 29 / 2
0.16.202 29 / 2
0.16.201 29 / 2
0.16.200 28 / 2
0.16.199 28 / 2
0.16.198 28 / 2
0.16.197 28 / 2
0.16.196 28 / 2
0.16.195 28 / 2
0.16.192 27 / 2
0.16.191 27 / 2
0.16.190 27 / 2
0.16.189 27 / 2
0.16.188 27 / 2
0.16.187 27 / 2
0.16.185 27 / 2
0.16.184 27 / 2
0.16.183 27 / 2
0.16.182 27 / 2
0.16.181 27 / 2
0.16.180 27 / 2
0.16.179 27 / 2
0.16.178 27 / 2
0.16.177 27 / 2
0.16.176 27 / 2
0.16.175 27 / 2
0.16.174 27 / 2
0.16.173 27 / 2
0.16.172 27 / 2
0.16.171 27 / 2
0.16.170 27 / 2
0.16.169 27 / 2
0.16.168 27 / 2
0.16.167 27 / 2
0.16.166 27 / 2
0.16.165 27 / 2
0.16.164 27 / 2
0.16.163 27 / 2
0.16.162 27 / 2
0.16.161 27 / 2
0.16.160 27 / 2
0.16.157 27 / 2
0.16.156 27 / 2
0.16.155 27 / 2
0.16.154 27 / 2
0.16.153 27 / 2
0.16.152 27 / 2
0.16.151 27 / 2
0.16.150 27 / 2
0.16.149 27 / 2
0.16.148 27 / 2
0.16.147 27 / 2
0.16.146 27 / 2
0.16.145 27 / 2
0.16.144 27 / 2
0.16.143 27 / 2
0.16.142 27 / 2
0.16.141 27 / 2
0.16.140 27 / 2
0.16.139 27 / 2
0.16.138 27 / 2
0.16.137 27 / 2
0.16.136 27 / 2
0.16.135 27 / 2
0.16.134 27 / 2
0.16.133 27 / 2
0.16.131 27 / 2
0.16.130 27 / 2
0.16.129 27 / 2
0.16.128 27 / 2
0.16.127 27 / 2
0.16.126 27 / 2
0.16.125 27 / 2
0.16.124 27 / 2
0.16.123 27 / 2
0.16.122 27 / 2
0.16.121 27 / 2
0.16.120 27 / 2
0.16.119 27 / 2
0.16.118 27 / 2
0.16.117 27 / 2
0.16.116 27 / 2
0.16.115 26 / 2
0.16.114 26 / 2
0.16.113 26 / 2
0.16.112 26 / 2
0.16.111 26 / 2
0.16.110 26 / 2
0.16.109 26 / 2
0.16.108 24 / 4
0.16.107 24 / 4
0.16.106 24 / 4
0.16.105 24 / 4
0.16.104 24 / 4
0.16.103 24 / 4
0.16.102 24 / 4
Showing 100 of 554 Next page →

v0.16.207

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.206

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.205

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.204

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.203

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.202

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.201

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.200

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.199

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.198

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.197

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.196

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.195

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.192

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.191

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.190

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.189

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.188

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.187

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.185

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.184

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.183

3 findings
HIGH New obfuscated file: dist/types/env.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/types/env.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.182

3 findings
HIGH New obfuscated file: dist/types/env.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/types/env.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.181

3 findings
HIGH New obfuscated file: dist/types/env.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/types/env.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.180

3 findings
HIGH New obfuscated file: dist/types/env.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/types/env.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.179

3 findings
HIGH New obfuscated file: dist/types/env.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/types/env.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.178

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.177

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.176

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.175

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.161

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.160

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.157

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.156

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.155

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.154

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.153

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.152

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.151

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.150

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.149

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.148

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.147

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.146

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.