@powerlines/plugin-env
A package containing a Powerlines plugin for injecting static .env configuration values to the code so that they're accessible at runtime.
100
Versions
Apache-2.0
License
No
Install Scripts
Attested
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation (unverified)
npm registry signatures
gitHead linked
Maintainers
stormie-botsullivanpj
Keywords
dotenvpowerlinesstorm-softwarepowerlines-plugin
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@powerlines/plugin-power-plant | AI (dependencies): Same-org sibling package in monorepo release train, not third-party. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): Internal rename/split within trusted publisher's ecosystem, not injection of unrelated dep. | ai | |
| dependencies | unvetted-dep:@power-plant/schema | AI (dependencies): Sibling monorepo package replacing @powerlines/schema; same publisher/org pattern. | ai | |
| dependencies | unvetted-dep:@power-plant/alloy-js | AI (dependencies): Fits existing alloy-js plugin family already depended on; no malicious behavior evident. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size increase fully explained by inlinedDependencies bundling pattern documented in package.json. | ai | |
| source-diff | large-new-source-files | AI (source-diff): New files are inlined dependency bundles explicitly declared in package.json inlinedDependencies. | ai | |
| source-diff | obfuscated-file:dist/json5-DEV_07Nb.cjs | AI (source-diff): Bundled confbox/json5 dependency with long unicode regex lines; not obfuscated, just minified. | ai | |
| source-diff | obfuscated-file:dist/load-DPB0maqs.cjs | AI (source-diff): Bundled dotenv and other known deps; readable structure, hashed chunk filename is normal vite output. | ai | |
| source-diff | obfuscated-file:dist/dist-C_a6goTt.cjs | AI (source-diff): Standard rollup/vite bundle chunk with hashed filename; code is readable and references known deps. | ai | |
| source-diff | obfuscated-file:dist/node_modules/.pnpm/[email protected]/node_modules/confbox/dist/json5.cjs | AI (source-diff): Minified vendored dependency (confbox) bundled into dist/node_modules via pnpm; not malicious obfuscation. | ai | |
| phantom-deps | phantom-dep:@alloy-js/markdown | AI (phantom-deps): Config-referenced dep in monorepo plugin; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@powerlines/core | AI (phantom-deps): Same org scope; likely loaded by convention or peer dependency pattern, stable false positive for this package. | ai | |
| provenance | publisher-changed | AI (provenance): stormie-bot is the org's established bot account with 2775 approved packages; transition from GH Actions to this account is expected org automation pattern. | ai | |
| source-diff | obfuscated-file:dist/types/env.cjs | AI (source-diff): Minified but fully readable build output for a new package export; no obfuscation or malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/types/env.mjs | AI (source-diff): Same as .cjs counterpart — minified ESM build output, content is benign env variable metadata. | ai | |
| dependencies | unvetted-dep:@powerlines/alloy | AI (dependencies): @powerlines/alloy is a sibling package in the same org scope, published by the same Storm Software maintainer with 356 approved packages. Internal org dependency, not a third-party unknown. | ai | |
| source-diff | obfuscated-file:dist/node_modules/.pnpm/[email protected]/node_modules/confbox/dist/_chunks/libs/json5.cjs | AI (source-diff): Minified bundle of json5 parser from confbox package. Long line is a Unicode regex for JSON5 parsing — entirely benign. SLSA provenance confirms build integrity. | ai | |
| source-diff | obfuscated-file:dist/node_modules/.pnpm/[email protected]/node_modules/jiti/dist/jiti.cjs | AI (source-diff): Minified bundle of the legitimate jiti package included via rolldown bundling of pnpm deps. SLSA provenance attestation confirms CI build integrity. No malicious patterns in sample. | ai | |
| source-diff | obfuscated-file:dist/node_modules/.pnpm/[email protected]/node_modules/node-fetch-native/dist/proxy.cjs | AI (source-diff): Minified bundle of node-fetch-native proxy module using standard Node.js built-ins. No suspicious network calls or exfiltration. SLSA provenance confirms build integrity. | ai | |
| phantom-deps | phantom-dep:@stryke/fs | AI (phantom-deps): Part of the @powerlines monorepo ecosystem; phantom deps are expected for plugin packages loaded by convention or config, not direct import. | ai | |
| phantom-deps | phantom-dep:@storm-software/config-tools | AI (phantom-deps): Config tooling from the same org ecosystem; loaded by convention/config, stable false positive. | ai | |
| phantom-deps | phantom-dep:@powerlines/plugin-babel | AI (phantom-deps): Same-org plugin package from the @powerlines monorepo; loaded by plugin convention, not direct import. | ai | |
| phantom-deps | phantom-dep:@stryke/string-format | AI (phantom-deps): Same monorepo org utility package; loaded by config/convention, stable false positive. | ai | |
| phantom-deps | phantom-dep:@alloy-js/typescript | AI (phantom-deps): Framework-scoped package used via config/convention in the alloy-js ecosystem; stable false positive. | ai | |
| phantom-deps | phantom-dep:@stryke/type-checks | AI (phantom-deps): Same monorepo org utility package; loaded by config/convention, stable false positive. | ai | |
| phantom-deps | phantom-dep:@powerlines/alloy | AI (phantom-deps): Same-org package from the @powerlines monorepo; loaded by plugin convention, not direct import. | ai | |
| phantom-deps | phantom-dep:@alloy-js/core | AI (phantom-deps): Framework-scoped package used via config/convention in the alloy-js ecosystem; stable false positive. | ai | |
| phantom-deps | phantom-dep:@stryke/types | AI (phantom-deps): Type-only dependency from same org; not directly imported at runtime but declared for type resolution. | ai | |
| phantom-deps | phantom-dep:@stryke/capnp | AI (phantom-deps): Same monorepo org dependency loaded by config/convention; stable false positive for this plugin package. | ai | |
| phantom-deps | phantom-dep:@stryke/env | AI (phantom-deps): Same monorepo org dependency loaded by config/convention; stable false positive for this plugin package. | ai | |
| phantom-deps | phantom-dep:@babel/core | AI (phantom-deps): Framework-scoped package loaded by convention in Babel plugin ecosystems; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:powerlines | AI (phantom-deps): Core peer dependency of the @powerlines plugin ecosystem; loaded by convention, not direct import. | ai | |
| phantom-deps | phantom-dep:@babel/types | AI (phantom-deps): Framework-scoped package loaded by convention via @babel/core; stable pattern for Babel plugins. | ai | |
| phantom-deps | phantom-dep:@powerlines/plugin-plugin | AI (phantom-deps): Same-org scoped package loaded by convention in plugin ecosystem; stable for this package. | ai | |
| phantom-deps | phantom-dep:@alloy-js/json | AI (phantom-deps): Config-file referenced dependency; legitimate pattern in code generation frameworks. | ai | |
| phantom-deps | phantom-dep:@stryke/json | AI (phantom-deps): Config-file referenced dependency; legitimate pattern in config-driven tooling. | ai |
Versions (showing 100 of 572)
| Version | Deps | Published |
|---|---|---|
| 0.16.15 | 20 / 4 | |
| 0.16.14 | 20 / 4 | |
| 0.16.13 | 20 / 4 | |
| 0.16.12 | 20 / 4 | |
| 0.16.11 | 20 / 4 | |
| 0.16.10 | 20 / 4 | |
| 0.16.9 | 20 / 4 | |
| 0.16.8 | 20 / 4 | |
| 0.16.7 | 20 / 4 | |
| 0.16.6 | 20 / 4 | |
| 0.16.5 | 20 / 4 | |
| 0.16.4 | 20 / 4 | |
| 0.16.3 | 20 / 4 | |
| 0.16.2 | 20 / 4 | |
| 0.16.1 | 20 / 4 | |
| 0.16.0 | 20 / 4 | |
| 0.15.205 | 20 / 4 | |
| 0.15.204 | 20 / 4 | |
| 0.15.203 | 20 / 4 | |
| 0.15.202 | 20 / 4 | |
| 0.15.201 | 20 / 4 | |
| 0.15.200 | 20 / 4 | |
| 0.15.199 | 20 / 4 | |
| 0.15.198 | 20 / 4 | |
| 0.15.197 | 20 / 4 | |
| 0.15.196 | 20 / 4 | |
| 0.15.195 | 20 / 4 | |
| 0.15.194 | 20 / 4 | |
| 0.15.193 | 20 / 4 | |
| 0.15.192 | 20 / 4 | |
| 0.15.191 | 20 / 4 | |
| 0.15.190 | 20 / 4 | |
| 0.15.189 | 20 / 4 | |
| 0.15.188 | 20 / 4 | |
| 0.15.187 | 20 / 4 | |
| 0.15.186 | 20 / 4 | |
| 0.15.185 | 20 / 4 | |
| 0.15.184 | 20 / 4 | |
| 0.15.183 | 20 / 4 | |
| 0.15.182 | 20 / 4 | |
| 0.15.181 | 20 / 4 | |
| 0.15.180 | 20 / 4 | |
| 0.15.179 | 20 / 4 | |
| 0.15.178 | 20 / 4 | |
| 0.15.177 | 20 / 4 | |
| 0.15.176 | 20 / 4 | |
| 0.15.175 | 20 / 4 | |
| 0.15.174 | 20 / 4 | |
| 0.15.173 | 20 / 4 | |
| 0.15.172 | 20 / 4 | |
| 0.15.171 | 20 / 4 | |
| 0.15.170 | 20 / 4 | |
| 0.15.169 | 20 / 4 | |
| 0.15.168 | 20 / 4 | |
| 0.15.167 | 20 / 4 | |
| 0.15.166 | 20 / 4 | |
| 0.15.165 | 20 / 4 | |
| 0.15.164 | 20 / 4 | |
| 0.15.163 | 20 / 4 | |
| 0.15.162 | 20 / 4 | |
| 0.15.161 | 20 / 4 | |
| 0.15.160 | 20 / 4 | |
| 0.15.159 | 20 / 4 | |
| 0.15.158 | 20 / 4 | |
| 0.15.157 | 20 / 4 | |
| 0.15.156 | 20 / 4 | |
| 0.15.155 | 20 / 4 | |
| 0.15.154 | 20 / 4 | |
| 0.15.153 | 20 / 4 | |
| 0.15.152 | 20 / 4 | |
| 0.15.151 | 19 / 4 | |
| 0.15.150 | 20 / 4 | |
| 0.15.149 | 20 / 4 | |
| 0.15.148 | 20 / 4 | |
| 0.15.147 | 20 / 4 | |
| 0.15.146 | 20 / 4 | |
| 0.15.145 | 20 / 4 | |
| 0.15.144 | 20 / 4 | |
| 0.15.143 | 20 / 4 | |
| 0.15.142 | 20 / 4 | |
| 0.15.141 | 20 / 4 | |
| 0.15.140 | 20 / 4 | |
| 0.15.139 | 20 / 4 | |
| 0.15.138 | 20 / 4 | |
| 0.15.137 | 20 / 4 | |
| 0.15.136 | 20 / 4 | |
| 0.15.135 | 20 / 4 | |
| 0.15.134 | 20 / 4 | |
| 0.15.133 | 20 / 4 | |
| 0.15.132 | 20 / 4 | |
| 0.15.131 | 20 / 4 | |
| 0.15.130 | 20 / 4 | |
| 0.15.129 | 20 / 4 | |
| 0.15.128 | 20 / 4 | |
| 0.15.127 | 20 / 4 | |
| 0.15.126 | 20 / 4 | |
| 0.15.125 | 20 / 4 | |
| 0.15.124 | 20 / 4 | |
| 0.15.123 | 20 / 4 | |
| 0.15.122 | 20 / 4 |
Showing 100 of 572
Next page →
v0.15.161
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.15.160
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.15.159
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.