← Home

@powerlines/plugin-hey-api

A Powerlines plugin to generate project code using Hey API.

51
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

stormie-botsullivanpj

Keywords

hey-apipowerlinesstorm-softwarepowerlines-plugin

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@power-plant/core AI (dependencies): Same-org monorepo sibling package, not third-party. ai
publish-pattern new-deps-added AI (publish-pattern): New deps are first-party sibling packages from same publisher. ai
phantom-deps phantom-dep:@power-plant/core AI (phantom-deps): Likely used via dynamic/config resolution in plugin system, same-org dep. ai
dependencies unvetted-dep:@powerlines/plugin-power-plant AI (dependencies): Same-org monorepo sibling package. ai
dependencies unvetted-dep:@power-plant/hey-api AI (dependencies): Same-org monorepo sibling package. ai
phantom-deps phantom-dep:defu AI (phantom-deps): defu is a declared runtime dependency; phantom detection is a false positive likely due to indirect usage or bundling. ai
provenance publisher-changed AI (provenance): Publisher changed from stormie-bot to GitHub Actions as part of a CI/CD migration; SLSA provenance attestation confirms legitimate automated publishing from the storm-software org. ai
phantom-deps phantom-dep:powerlines AI (phantom-deps): powerlines is a declared runtime dependency from the same org; phantom detection is a false positive. ai
phantom-deps phantom-dep:@stryke/path AI (phantom-deps): @stryke/path is a declared runtime dependency; phantom detection is a false positive. ai
phantom-deps phantom-dep:@stryke/type-checks AI (phantom-deps): @stryke/type-checks is a declared runtime dependency; phantom detection is a false positive. ai
phantom-deps phantom-dep:@stryke/string-format AI (phantom-deps): @stryke/string-format is a declared runtime dependency; phantom detection is a false positive. ai
dependencies unvetted-dep:@hey-api/openapi-ts AI (dependencies): @hey-api/openapi-ts is a well-known OpenAPI code generation tool; legitimate dependency for this plugin's purpose. ai
dependencies unvetted-dep:@stryke/types AI (dependencies): @stryke/* packages are part of the Storm Software ecosystem; unvetted status is expected for this monorepo family. ai
dependencies unvetted-dep:powerlines AI (dependencies): powerlines is the parent framework package from the same Storm Software monorepo; unvetted status is expected for this ecosystem. ai
phantom-deps phantom-dep:jiti AI (phantom-deps): jiti is commonly referenced in config files for TypeScript config loading in build tooling; not a security concern. ai
phantom-deps phantom-dep:@stryke/types AI (phantom-deps): Type-only package referenced in config files; phantom dep finding is a false positive for type-only usage patterns. ai
dependencies unvetted-dep:@stryke/string-format AI (dependencies): @stryke/* packages are part of the Storm Software ecosystem; unvetted status is expected for this monorepo family. ai
dependencies unvetted-dep:@stryke/path AI (dependencies): @stryke/* packages are part of the Storm Software ecosystem; unvetted status is expected for this monorepo family. ai
dependencies unvetted-dep:@stryke/type-checks AI (dependencies): @stryke/* packages are part of the Storm Software ecosystem; unvetted status is expected for this monorepo family. ai

Versions (showing 51 of 528)

View all versions
Version Deps Published
0.1.560 11 / 2
0.1.559 8 / 2
0.1.558 8 / 2
0.1.557 8 / 2
0.1.556 8 / 2
0.1.555 8 / 2
0.1.554 8 / 2
0.1.553 8 / 2
0.1.552 8 / 2
0.1.551 8 / 2
0.1.550 8 / 2
0.1.549 8 / 2
0.1.548 8 / 2
0.1.547 8 / 2
0.1.546 8 / 2
0.1.545 8 / 2
0.1.544 8 / 2
0.1.543 8 / 2
0.1.542 8 / 2
0.1.541 8 / 2
0.1.540 8 / 2
0.1.539 8 / 2
0.1.538 8 / 2
0.1.537 8 / 2
0.1.536 8 / 2
0.1.535 8 / 2
0.1.534 8 / 2
0.1.533 8 / 2
0.1.532 8 / 2
0.1.531 8 / 2
0.1.530 8 / 2
0.1.529 8 / 2
0.1.528 8 / 2
0.1.527 8 / 2
0.1.526 8 / 2
0.1.525 8 / 2
0.1.524 8 / 2
0.1.523 8 / 2
0.1.522 8 / 2
0.1.521 8 / 2
0.1.520 8 / 2
0.1.519 8 / 2
0.1.518 8 / 2
0.1.517 8 / 2
0.1.515 8 / 2
0.1.503 8 / 2
0.1.502 8 / 2
0.1.501 8 / 2
0.1.500 8 / 2
0.1.499 8 / 2
0.1.498 8 / 2

v0.1.560

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.559

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.558

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.557

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.556

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.555

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.