@powerlines/plugin-hey-api
A Powerlines plugin to generate project code using Hey API.
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@power-plant/core | AI (dependencies): Same-org monorepo sibling package, not third-party. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New deps are first-party sibling packages from same publisher. | ai | |
| phantom-deps | phantom-dep:@power-plant/core | AI (phantom-deps): Likely used via dynamic/config resolution in plugin system, same-org dep. | ai | |
| dependencies | unvetted-dep:@powerlines/plugin-power-plant | AI (dependencies): Same-org monorepo sibling package. | ai | |
| dependencies | unvetted-dep:@power-plant/hey-api | AI (dependencies): Same-org monorepo sibling package. | ai | |
| phantom-deps | phantom-dep:defu | AI (phantom-deps): defu is a declared runtime dependency; phantom detection is a false positive likely due to indirect usage or bundling. | ai | |
| provenance | publisher-changed | AI (provenance): Publisher changed from stormie-bot to GitHub Actions as part of a CI/CD migration; SLSA provenance attestation confirms legitimate automated publishing from the storm-software org. | ai | |
| phantom-deps | phantom-dep:powerlines | AI (phantom-deps): powerlines is a declared runtime dependency from the same org; phantom detection is a false positive. | ai | |
| phantom-deps | phantom-dep:@stryke/path | AI (phantom-deps): @stryke/path is a declared runtime dependency; phantom detection is a false positive. | ai | |
| phantom-deps | phantom-dep:@stryke/type-checks | AI (phantom-deps): @stryke/type-checks is a declared runtime dependency; phantom detection is a false positive. | ai | |
| phantom-deps | phantom-dep:@stryke/string-format | AI (phantom-deps): @stryke/string-format is a declared runtime dependency; phantom detection is a false positive. | ai | |
| dependencies | unvetted-dep:@hey-api/openapi-ts | AI (dependencies): @hey-api/openapi-ts is a well-known OpenAPI code generation tool; legitimate dependency for this plugin's purpose. | ai | |
| dependencies | unvetted-dep:@stryke/types | AI (dependencies): @stryke/* packages are part of the Storm Software ecosystem; unvetted status is expected for this monorepo family. | ai | |
| dependencies | unvetted-dep:powerlines | AI (dependencies): powerlines is the parent framework package from the same Storm Software monorepo; unvetted status is expected for this ecosystem. | ai | |
| phantom-deps | phantom-dep:jiti | AI (phantom-deps): jiti is commonly referenced in config files for TypeScript config loading in build tooling; not a security concern. | ai | |
| phantom-deps | phantom-dep:@stryke/types | AI (phantom-deps): Type-only package referenced in config files; phantom dep finding is a false positive for type-only usage patterns. | ai | |
| dependencies | unvetted-dep:@stryke/string-format | AI (dependencies): @stryke/* packages are part of the Storm Software ecosystem; unvetted status is expected for this monorepo family. | ai | |
| dependencies | unvetted-dep:@stryke/path | AI (dependencies): @stryke/* packages are part of the Storm Software ecosystem; unvetted status is expected for this monorepo family. | ai | |
| dependencies | unvetted-dep:@stryke/type-checks | AI (dependencies): @stryke/* packages are part of the Storm Software ecosystem; unvetted status is expected for this monorepo family. | ai |
Versions (showing 100 of 528)
| Version | Deps | Published |
|---|---|---|
| 0.1.560 | 11 / 2 | |
| 0.1.559 | 8 / 2 | |
| 0.1.558 | 8 / 2 | |
| 0.1.557 | 8 / 2 | |
| 0.1.556 | 8 / 2 | |
| 0.1.555 | 8 / 2 | |
| 0.1.554 | 8 / 2 | |
| 0.1.553 | 8 / 2 | |
| 0.1.552 | 8 / 2 | |
| 0.1.551 | 8 / 2 | |
| 0.1.550 | 8 / 2 | |
| 0.1.549 | 8 / 2 | |
| 0.1.548 | 8 / 2 | |
| 0.1.547 | 8 / 2 | |
| 0.1.546 | 8 / 2 | |
| 0.1.545 | 8 / 2 | |
| 0.1.544 | 8 / 2 | |
| 0.1.543 | 8 / 2 | |
| 0.1.542 | 8 / 2 | |
| 0.1.541 | 8 / 2 | |
| 0.1.540 | 8 / 2 | |
| 0.1.539 | 8 / 2 | |
| 0.1.538 | 8 / 2 | |
| 0.1.537 | 8 / 2 | |
| 0.1.536 | 8 / 2 | |
| 0.1.535 | 8 / 2 | |
| 0.1.534 | 8 / 2 | |
| 0.1.533 | 8 / 2 | |
| 0.1.532 | 8 / 2 | |
| 0.1.531 | 8 / 2 | |
| 0.1.530 | 8 / 2 | |
| 0.1.529 | 8 / 2 | |
| 0.1.528 | 8 / 2 | |
| 0.1.527 | 8 / 2 | |
| 0.1.526 | 8 / 2 | |
| 0.1.525 | 8 / 2 | |
| 0.1.524 | 8 / 2 | |
| 0.1.523 | 8 / 2 | |
| 0.1.522 | 8 / 2 | |
| 0.1.521 | 8 / 2 | |
| 0.1.520 | 8 / 2 | |
| 0.1.519 | 8 / 2 | |
| 0.1.518 | 8 / 2 | |
| 0.1.517 | 8 / 2 | |
| 0.1.515 | 8 / 2 | |
| 0.1.503 | 8 / 2 | |
| 0.1.502 | 8 / 2 | |
| 0.1.501 | 8 / 2 | |
| 0.1.500 | 8 / 2 | |
| 0.1.499 | 8 / 2 | |
| 0.1.498 | 8 / 2 | |
| 0.1.496 | 8 / 2 | |
| 0.1.495 | 8 / 2 | |
| 0.1.494 | 8 / 2 | |
| 0.1.493 | 8 / 2 | |
| 0.1.492 | 8 / 2 | |
| 0.1.491 | 8 / 2 | |
| 0.1.490 | 8 / 2 | |
| 0.1.489 | 8 / 2 | |
| 0.1.488 | 8 / 2 | |
| 0.1.487 | 8 / 2 | |
| 0.1.486 | 8 / 2 | |
| 0.1.485 | 8 / 2 | |
| 0.1.484 | 8 / 2 | |
| 0.1.483 | 8 / 2 | |
| 0.1.482 | 8 / 2 | |
| 0.1.481 | 8 / 2 | |
| 0.1.480 | 8 / 2 | |
| 0.1.479 | 8 / 2 | |
| 0.1.478 | 8 / 2 | |
| 0.1.477 | 8 / 2 | |
| 0.1.476 | 8 / 2 | |
| 0.1.475 | 8 / 2 | |
| 0.1.474 | 8 / 2 | |
| 0.1.473 | 8 / 2 | |
| 0.1.472 | 8 / 2 | |
| 0.1.463 | 8 / 2 | |
| 0.1.462 | 8 / 2 | |
| 0.1.460 | 8 / 2 | |
| 0.1.459 | 8 / 2 | |
| 0.1.458 | 8 / 2 | |
| 0.1.457 | 8 / 2 | |
| 0.1.456 | 8 / 2 | |
| 0.1.455 | 8 / 2 | |
| 0.1.454 | 8 / 2 | |
| 0.1.453 | 8 / 2 | |
| 0.1.451 | 8 / 2 | |
| 0.1.450 | 8 / 2 | |
| 0.1.449 | 8 / 2 | |
| 0.1.448 | 8 / 2 | |
| 0.1.447 | 8 / 2 | |
| 0.1.446 | 8 / 2 | |
| 0.1.445 | 8 / 2 | |
| 0.1.444 | 8 / 2 | |
| 0.1.443 | 8 / 2 | |
| 0.1.442 | 8 / 2 | |
| 0.1.441 | 8 / 2 | |
| 0.1.440 | 8 / 2 | |
| 0.1.439 | 8 / 2 | |
| 0.1.438 | 8 / 2 |
v0.1.560
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.559
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.558
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.557
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.556
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.555
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.