@powerlines/plugin-graphql
A Powerlines plugin to generate project code from GraphQL schemas.
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/powerlines/src/plugin-utils/get-config-path.cjs | AI (source-diff): File is minified build output of a config path resolver; logic is transparent (existsSync checks for various config file extensions). Not obfuscated malicious code. | ai | |
| source-diff | obfuscated-file:dist/powerlines/src/plugin-utils/get-config-path.mjs | AI (source-diff): ESM variant of the same minified config path resolver. Benign minified build output, not obfuscation. | ai | |
| provenance | publisher-changed | AI (provenance): Publisher changed to GitHub Actions CI with SLSA Sigstore attestation — a legitimate migration to automated publishing, not a compromise indicator for this package. | ai | |
| phantom-deps | phantom-dep:@stryke/path | AI (phantom-deps): Phantom dependency pattern is legitimate for utility libraries used indirectly in config. | ai | |
| phantom-deps | phantom-dep:@stryke/types | AI (phantom-deps): Phantom dependency pattern is legitimate for type utilities used indirectly. | ai | |
| phantom-deps | phantom-dep:defu | AI (phantom-deps): Phantom dependency pattern is legitimate for config-driven code generation tools; defu is used indirectly. | ai | |
| phantom-deps | phantom-dep:@graphql-codegen/cli | AI (phantom-deps): Phantom dependency pattern is legitimate for code generation tools; CLI is used indirectly. | ai | |
| phantom-deps | phantom-dep:@stryke/type-checks | AI (phantom-deps): Phantom dependency pattern is legitimate for utility libraries used indirectly. | ai | |
| phantom-deps | phantom-dep:jiti | AI (phantom-deps): Phantom dependency pattern is legitimate for config-driven code generation tools; jiti is used indirectly. | ai | |
| phantom-deps | phantom-dep:powerlines | AI (phantom-deps): Phantom dependency pattern is legitimate for monorepo plugins; powerlines is used indirectly. | ai |
Versions (showing 51 of 420)
| Version | Deps | Published |
|---|---|---|
| 0.1.588 | 8 / 3 | |
| 0.1.587 | 8 / 3 | |
| 0.1.586 | 8 / 3 | |
| 0.1.585 | 8 / 3 | |
| 0.1.584 | 8 / 3 | |
| 0.1.583 | 8 / 3 | |
| 0.1.582 | 8 / 3 | |
| 0.1.581 | 8 / 3 | |
| 0.1.580 | 8 / 3 | |
| 0.1.579 | 8 / 3 | |
| 0.1.578 | 8 / 3 | |
| 0.1.577 | 8 / 3 | |
| 0.1.576 | 8 / 3 | |
| 0.1.575 | 8 / 3 | |
| 0.1.574 | 8 / 3 | |
| 0.1.573 | 8 / 3 | |
| 0.1.572 | 8 / 3 | |
| 0.1.571 | 8 / 3 | |
| 0.1.570 | 8 / 3 | |
| 0.1.569 | 8 / 3 | |
| 0.1.568 | 8 / 3 | |
| 0.1.567 | 8 / 3 | |
| 0.1.566 | 8 / 3 | |
| 0.1.565 | 8 / 3 | |
| 0.1.564 | 8 / 3 | |
| 0.1.563 | 8 / 3 | |
| 0.1.562 | 8 / 3 | |
| 0.1.561 | 8 / 3 | |
| 0.1.560 | 8 / 3 | |
| 0.1.559 | 8 / 3 | |
| 0.1.558 | 8 / 3 | |
| 0.1.557 | 8 / 3 | |
| 0.1.556 | 8 / 3 | |
| 0.1.555 | 8 / 3 | |
| 0.1.554 | 8 / 3 | |
| 0.1.553 | 8 / 3 | |
| 0.1.552 | 8 / 3 | |
| 0.1.551 | 8 / 3 | |
| 0.1.550 | 8 / 3 | |
| 0.1.549 | 8 / 3 | |
| 0.1.548 | 8 / 3 | |
| 0.1.547 | 8 / 3 | |
| 0.1.546 | 8 / 3 | |
| 0.1.545 | 8 / 3 | |
| 0.1.543 | 8 / 3 | |
| 0.1.542 | 8 / 3 | |
| 0.1.541 | 8 / 3 | |
| 0.1.540 | 8 / 3 | |
| 0.1.539 | 8 / 3 | |
| 0.1.538 | 8 / 3 | |
| 0.1.537 | 8 / 3 |
v0.1.588
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.587
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.586
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.585
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.584
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.583
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.582
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.581
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.580
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.579
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.578
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.577
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.576
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.575
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.574
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.573
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.572
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.571
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.570
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.569
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.568
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.567
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.566
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.565
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.564
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.563
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.562
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.561
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.560
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.559
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.558
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.557
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.556
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.555
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.554
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.553
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.552
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.551
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.550
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.549
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.548
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.547
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.546
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.545
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.543
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.542
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.541
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.540
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.539
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.538
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.537
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.