← Home

@powerlines/plugin-hey-api

A Powerlines plugin to generate project code using Hey API.

100
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

stormie-botsullivanpj

Keywords

hey-apipowerlinesstorm-softwarepowerlines-plugin

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@power-plant/core AI (dependencies): Same-org monorepo sibling package, not third-party. ai
publish-pattern new-deps-added AI (publish-pattern): New deps are first-party sibling packages from same publisher. ai
phantom-deps phantom-dep:@power-plant/core AI (phantom-deps): Likely used via dynamic/config resolution in plugin system, same-org dep. ai
dependencies unvetted-dep:@powerlines/plugin-power-plant AI (dependencies): Same-org monorepo sibling package. ai
dependencies unvetted-dep:@power-plant/hey-api AI (dependencies): Same-org monorepo sibling package. ai
phantom-deps phantom-dep:defu AI (phantom-deps): defu is a declared runtime dependency; phantom detection is a false positive likely due to indirect usage or bundling. ai
provenance publisher-changed AI (provenance): Publisher changed from stormie-bot to GitHub Actions as part of a CI/CD migration; SLSA provenance attestation confirms legitimate automated publishing from the storm-software org. ai
phantom-deps phantom-dep:powerlines AI (phantom-deps): powerlines is a declared runtime dependency from the same org; phantom detection is a false positive. ai
phantom-deps phantom-dep:@stryke/path AI (phantom-deps): @stryke/path is a declared runtime dependency; phantom detection is a false positive. ai
phantom-deps phantom-dep:@stryke/type-checks AI (phantom-deps): @stryke/type-checks is a declared runtime dependency; phantom detection is a false positive. ai
phantom-deps phantom-dep:@stryke/string-format AI (phantom-deps): @stryke/string-format is a declared runtime dependency; phantom detection is a false positive. ai
dependencies unvetted-dep:@hey-api/openapi-ts AI (dependencies): @hey-api/openapi-ts is a well-known OpenAPI code generation tool; legitimate dependency for this plugin's purpose. ai
dependencies unvetted-dep:@stryke/types AI (dependencies): @stryke/* packages are part of the Storm Software ecosystem; unvetted status is expected for this monorepo family. ai
dependencies unvetted-dep:powerlines AI (dependencies): powerlines is the parent framework package from the same Storm Software monorepo; unvetted status is expected for this ecosystem. ai
phantom-deps phantom-dep:jiti AI (phantom-deps): jiti is commonly referenced in config files for TypeScript config loading in build tooling; not a security concern. ai
phantom-deps phantom-dep:@stryke/types AI (phantom-deps): Type-only package referenced in config files; phantom dep finding is a false positive for type-only usage patterns. ai
dependencies unvetted-dep:@stryke/string-format AI (dependencies): @stryke/* packages are part of the Storm Software ecosystem; unvetted status is expected for this monorepo family. ai
dependencies unvetted-dep:@stryke/path AI (dependencies): @stryke/* packages are part of the Storm Software ecosystem; unvetted status is expected for this monorepo family. ai
dependencies unvetted-dep:@stryke/type-checks AI (dependencies): @stryke/* packages are part of the Storm Software ecosystem; unvetted status is expected for this monorepo family. ai

Versions (showing 100 of 528)

Version Deps Published
0.1.560 11 / 2
0.1.559 8 / 2
0.1.558 8 / 2
0.1.557 8 / 2
0.1.556 8 / 2
0.1.555 8 / 2
0.1.554 8 / 2
0.1.553 8 / 2
0.1.552 8 / 2
0.1.551 8 / 2
0.1.550 8 / 2
0.1.549 8 / 2
0.1.548 8 / 2
0.1.547 8 / 2
0.1.546 8 / 2
0.1.545 8 / 2
0.1.544 8 / 2
0.1.543 8 / 2
0.1.542 8 / 2
0.1.541 8 / 2
0.1.540 8 / 2
0.1.539 8 / 2
0.1.538 8 / 2
0.1.537 8 / 2
0.1.536 8 / 2
0.1.535 8 / 2
0.1.534 8 / 2
0.1.533 8 / 2
0.1.532 8 / 2
0.1.531 8 / 2
0.1.530 8 / 2
0.1.529 8 / 2
0.1.528 8 / 2
0.1.527 8 / 2
0.1.526 8 / 2
0.1.525 8 / 2
0.1.524 8 / 2
0.1.523 8 / 2
0.1.522 8 / 2
0.1.521 8 / 2
0.1.520 8 / 2
0.1.519 8 / 2
0.1.518 8 / 2
0.1.517 8 / 2
0.1.515 8 / 2
0.1.503 8 / 2
0.1.502 8 / 2
0.1.501 8 / 2
0.1.500 8 / 2
0.1.499 8 / 2
0.1.498 8 / 2
0.1.496 8 / 2
0.1.495 8 / 2
0.1.494 8 / 2
0.1.493 8 / 2
0.1.492 8 / 2
0.1.491 8 / 2
0.1.490 8 / 2
0.1.489 8 / 2
0.1.488 8 / 2
0.1.487 8 / 2
0.1.486 8 / 2
0.1.485 8 / 2
0.1.484 8 / 2
0.1.483 8 / 2
0.1.482 8 / 2
0.1.481 8 / 2
0.1.480 8 / 2
0.1.479 8 / 2
0.1.478 8 / 2
0.1.477 8 / 2
0.1.476 8 / 2
0.1.475 8 / 2
0.1.474 8 / 2
0.1.473 8 / 2
0.1.472 8 / 2
0.1.463 8 / 2
0.1.462 8 / 2
0.1.460 8 / 2
0.1.459 8 / 2
0.1.458 8 / 2
0.1.457 8 / 2
0.1.456 8 / 2
0.1.455 8 / 2
0.1.454 8 / 2
0.1.453 8 / 2
0.1.451 8 / 2
0.1.450 8 / 2
0.1.449 8 / 2
0.1.448 8 / 2
0.1.447 8 / 2
0.1.446 8 / 2
0.1.445 8 / 2
0.1.444 8 / 2
0.1.443 8 / 2
0.1.442 8 / 2
0.1.441 8 / 2
0.1.440 8 / 2
0.1.439 8 / 2
0.1.438 8 / 2
Showing 100 of 528 Next page →

v0.1.560

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.559

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.558

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.557

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.556

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.555

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.