@powerlines/plugin-nodejs
A package containing a Powerlines plugin for building a Node.js application.
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@power-plant/alloy-js | AI (dependencies): New alloy-js ecosystem dep, consistent with package's codegen purpose; trusted publisher. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): Single new dep matching existing alloy-js dependency family. | ai | |
| source-diff | obfuscated-file:dist/components/env-builtin.cjs | AI (source-diff): Standard Rolldown CJS bundle output; code is readable JSX component logic, not obfuscated. | ai | |
| provenance | publisher-changed | AI (provenance): Publisher changed from stormie-bot to GitHub Actions, consistent with org adopting CI/CD OIDC publishing. SLSA provenance attestation confirms legitimate automated pipeline. | ai | |
| phantom-deps | phantom-dep:@powerlines/plugin-babel | AI (phantom-deps): Same-org plugin dependency; referenced in config/architecture, not direct imports. Stable pattern. | ai | |
| phantom-deps | phantom-dep:@powerlines/plugin-alloy | AI (phantom-deps): Same-org plugin dependency; referenced in config/architecture, not direct imports. Stable pattern. | ai | |
| phantom-deps | phantom-dep:powerlines | AI (phantom-deps): Core framework dependency for plugin system; referenced in config, not direct imports. Expected pattern. | ai | |
| phantom-deps | phantom-dep:@alloy-js/json | AI (phantom-deps): Framework dependency referenced in plugin architecture; not directly imported. Expected for this package type. | ai | |
| phantom-deps | phantom-dep:@powerlines/plugin-env | AI (phantom-deps): Same-org plugin dependency; referenced in config/architecture, not direct imports. Stable pattern. | ai | |
| phantom-deps | phantom-dep:@powerlines/plugin-plugin | AI (phantom-deps): Same-org sibling package declared as dependency; phantom detection is a stable false positive for this package's build/config pattern. | ai | |
| phantom-deps | phantom-dep:@storm-software/config-tools | AI (phantom-deps): Referenced in config files per finding description; not a direct import but legitimately declared. Stable false positive for this package. | ai |
Versions (showing 51 of 511)
| Version | Deps | Published |
|---|---|---|
| 0.1.551 | 11 / 1 | |
| 0.1.550 | 11 / 1 | |
| 0.1.549 | 10 / 1 | |
| 0.1.548 | 10 / 1 | |
| 0.1.547 | 10 / 1 | |
| 0.1.546 | 10 / 1 | |
| 0.1.545 | 10 / 1 | |
| 0.1.544 | 10 / 1 | |
| 0.1.543 | 10 / 1 | |
| 0.1.542 | 10 / 1 | |
| 0.1.541 | 10 / 1 | |
| 0.1.540 | 10 / 1 | |
| 0.1.539 | 10 / 1 | |
| 0.1.538 | 10 / 1 | |
| 0.1.537 | 10 / 1 | |
| 0.1.536 | 10 / 1 | |
| 0.1.535 | 10 / 1 | |
| 0.1.534 | 10 / 1 | |
| 0.1.533 | 10 / 1 | |
| 0.1.532 | 10 / 1 | |
| 0.1.531 | 10 / 1 | |
| 0.1.530 | 10 / 1 | |
| 0.1.529 | 10 / 1 | |
| 0.1.528 | 10 / 1 | |
| 0.1.527 | 10 / 1 | |
| 0.1.526 | 10 / 1 | |
| 0.1.525 | 10 / 1 | |
| 0.1.524 | 10 / 1 | |
| 0.1.523 | 10 / 1 | |
| 0.1.522 | 10 / 1 | |
| 0.1.521 | 10 / 1 | |
| 0.1.520 | 10 / 1 | |
| 0.1.519 | 10 / 1 | |
| 0.1.518 | 10 / 1 | |
| 0.1.517 | 10 / 1 | |
| 0.1.516 | 10 / 1 | |
| 0.1.515 | 10 / 1 | |
| 0.1.514 | 10 / 1 | |
| 0.1.513 | 10 / 1 | |
| 0.1.512 | 10 / 1 | |
| 0.1.511 | 10 / 1 | |
| 0.1.510 | 10 / 1 | |
| 0.1.509 | 10 / 1 | |
| 0.1.508 | 10 / 1 | |
| 0.1.507 | 10 / 1 | |
| 0.1.506 | 10 / 1 | |
| 0.1.505 | 10 / 1 | |
| 0.1.504 | 10 / 1 | |
| 0.1.492 | 10 / 1 | |
| 0.1.491 | 10 / 1 | |
| 0.1.490 | 10 / 1 |
v0.1.551
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.550
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.549
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.548
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.547
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.546
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.545
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.544
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.