← Home

@powerlines/plugin-image-compression

A Powerlines plugin to optimize images used by the project.

51
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

stormie-botsullivanpj

Keywords

sharpsvgopowerlinesstorm-softwarepowerlines-plugin

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@stryke/fs AI (phantom-deps): Config-file reference; stable pattern for this package across 390 versions. ai
phantom-deps phantom-dep:@stryke/string-format AI (phantom-deps): Config-file reference; stable pattern for this package across 390 versions. ai
phantom-deps phantom-dep:powerlines AI (phantom-deps): Powerlines is the framework this plugin extends; phantom reference in config is expected for plugin packages. ai
phantom-deps phantom-dep:chalk AI (phantom-deps): Chalk is a legitimate dependency for CLI output; phantom reference in config is expected for monorepo packages. ai
phantom-deps phantom-dep:@stryke/path AI (phantom-deps): Utility dependency referenced in config; phantom reference is expected in monorepo build setup. ai
phantom-deps phantom-dep:@stryke/convert AI (phantom-deps): Utility dependency referenced in config; phantom reference is expected in monorepo build setup. ai
dependencies unvetted-dep:svgo AI (dependencies): svgo is a well-known SVG optimization library; its use is expected and appropriate for an image compression plugin. Not a genuine risk for this package. ai
phantom-deps phantom-dep:jiti AI (phantom-deps): jiti is a well-known TypeScript/ESM runtime loader; phantom dep status reflects config-file usage pattern, not a security concern. ai
phantom-deps phantom-dep:defu AI (phantom-deps): defu is a well-known, legitimate utility package; phantom dep status reflects config-file usage pattern, not a security concern. ai
provenance slsa-provenance AI (provenance): Package consistently published via CI/CD with SLSA provenance attestation; this is a stable characteristic of the Storm Software release pipeline. ai

Versions (showing 51 of 238)

View all versions
Version Deps Published
0.2.576 10 / 3
0.2.575 10 / 3
0.2.574 10 / 3
0.2.573 10 / 3
0.2.572 10 / 3
0.2.571 10 / 3
0.2.570 10 / 3
0.2.569 10 / 3
0.2.568 10 / 3
0.2.567 10 / 3
0.2.566 10 / 3
0.2.565 10 / 3
0.2.564 10 / 3
0.2.563 10 / 3
0.2.562 10 / 3
0.2.561 10 / 3
0.2.560 10 / 3
0.2.559 10 / 3
0.2.557 10 / 3
0.2.556 10 / 3
0.2.555 10 / 3
0.2.554 10 / 3
0.2.553 10 / 3
0.2.552 10 / 3
0.2.551 10 / 3
0.2.550 10 / 3
0.2.549 10 / 3
0.2.548 10 / 3
0.2.547 10 / 3
0.2.546 10 / 3
0.2.545 10 / 3
0.2.544 10 / 3
0.2.543 10 / 3
0.2.542 10 / 3
0.2.541 10 / 3
0.2.540 10 / 3
0.2.539 10 / 3
0.2.538 10 / 3
0.2.537 10 / 3
0.2.536 10 / 3
0.2.535 10 / 3
0.2.534 10 / 3
0.2.533 10 / 3
0.2.532 10 / 3
0.2.531 10 / 3
0.2.530 10 / 3
0.2.529 10 / 3
0.2.528 10 / 3
0.2.527 10 / 3
0.2.526 10 / 3
0.2.525 10 / 3

v0.2.576

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.575

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.574

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.573

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.572

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.571

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.570

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.569

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.568

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.567

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.566

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.565

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.564

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.563

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.562

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.561

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.560

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.559

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.557

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.556

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.555

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.554

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.553

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.552

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.551

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.550

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.