← Home

@powerlines/plugin-nodejs

A package containing a Powerlines plugin for building a Node.js application.

51
Versions
Apache-2.0
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures gitHead linked

Maintainers

stormie-botsullivanpj

Keywords

nodejspowerlinesstorm-softwarepowerlines-plugin

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@power-plant/alloy-js AI (dependencies): New alloy-js ecosystem dep, consistent with package's codegen purpose; trusted publisher. ai
publish-pattern new-deps-added AI (publish-pattern): Single new dep matching existing alloy-js dependency family. ai
source-diff obfuscated-file:dist/components/env-builtin.cjs AI (source-diff): Standard Rolldown CJS bundle output; code is readable JSX component logic, not obfuscated. ai
provenance publisher-changed AI (provenance): Publisher changed from stormie-bot to GitHub Actions, consistent with org adopting CI/CD OIDC publishing. SLSA provenance attestation confirms legitimate automated pipeline. ai
phantom-deps phantom-dep:@powerlines/plugin-babel AI (phantom-deps): Same-org plugin dependency; referenced in config/architecture, not direct imports. Stable pattern. ai
phantom-deps phantom-dep:@powerlines/plugin-alloy AI (phantom-deps): Same-org plugin dependency; referenced in config/architecture, not direct imports. Stable pattern. ai
phantom-deps phantom-dep:powerlines AI (phantom-deps): Core framework dependency for plugin system; referenced in config, not direct imports. Expected pattern. ai
phantom-deps phantom-dep:@alloy-js/json AI (phantom-deps): Framework dependency referenced in plugin architecture; not directly imported. Expected for this package type. ai
phantom-deps phantom-dep:@powerlines/plugin-env AI (phantom-deps): Same-org plugin dependency; referenced in config/architecture, not direct imports. Stable pattern. ai
phantom-deps phantom-dep:@powerlines/plugin-plugin AI (phantom-deps): Same-org sibling package declared as dependency; phantom detection is a stable false positive for this package's build/config pattern. ai
phantom-deps phantom-dep:@storm-software/config-tools AI (phantom-deps): Referenced in config files per finding description; not a direct import but legitimately declared. Stable false positive for this package. ai

Versions (showing 51 of 511)

View all versions
Version Deps Published
0.1.551 11 / 1
0.1.550 11 / 1
0.1.549 10 / 1
0.1.548 10 / 1
0.1.547 10 / 1
0.1.546 10 / 1
0.1.545 10 / 1
0.1.544 10 / 1
0.1.543 10 / 1
0.1.542 10 / 1
0.1.541 10 / 1
0.1.540 10 / 1
0.1.539 10 / 1
0.1.538 10 / 1
0.1.537 10 / 1
0.1.536 10 / 1
0.1.535 10 / 1
0.1.534 10 / 1
0.1.533 10 / 1
0.1.532 10 / 1
0.1.531 10 / 1
0.1.530 10 / 1
0.1.529 10 / 1
0.1.528 10 / 1
0.1.527 10 / 1
0.1.526 10 / 1
0.1.525 10 / 1
0.1.524 10 / 1
0.1.523 10 / 1
0.1.522 10 / 1
0.1.521 10 / 1
0.1.520 10 / 1
0.1.519 10 / 1
0.1.518 10 / 1
0.1.517 10 / 1
0.1.516 10 / 1
0.1.515 10 / 1
0.1.514 10 / 1
0.1.513 10 / 1
0.1.512 10 / 1
0.1.511 10 / 1
0.1.510 10 / 1
0.1.509 10 / 1
0.1.508 10 / 1
0.1.507 10 / 1
0.1.506 10 / 1
0.1.505 10 / 1
0.1.504 10 / 1
0.1.492 10 / 1
0.1.491 10 / 1
0.1.490 10 / 1

v0.1.551

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.550

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.549

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.548

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.547

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.546

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.545

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.544

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.