@powerlines/plugin-openapi
A Powerlines plugin to generate project code from OpenAPI specifications.
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@powerlines/plugin-power-plant | AI (dependencies): Sibling monorepo package from same publisher/org. | ai | |
| dependencies | unvetted-dep:@power-plant/openapi-schema | AI (dependencies): Sibling monorepo package from same publisher/org. | ai | |
| phantom-deps | phantom-dep:@power-plant/core | AI (phantom-deps): Likely used via bundled/build output; heuristic false positive for monorepo package. | ai | |
| dependencies | unvetted-dep:@power-plant/openapi-typescript | AI (dependencies): Sibling monorepo package from same publisher/org. | ai | |
| dependencies | unvetted-dep:@power-plant/core | AI (dependencies): Sibling monorepo package from same publisher/org. | ai | |
| provenance | publisher-changed | AI (provenance): Transition from stormie-bot to GitHub Actions is a legitimate CI/CD modernization, confirmed by SLSA provenance attestation. Generalizes to future versions for this package. | ai | |
| phantom-deps | phantom-dep:@stryke/type-checks | AI (phantom-deps): Declared dependency used indirectly; common pattern in plugin/config-driven architectures. | ai | |
| phantom-deps | phantom-dep:@stryke/path | AI (phantom-deps): Declared dependency used indirectly; common pattern in plugin/config-driven architectures. | ai | |
| phantom-deps | phantom-dep:defu | AI (phantom-deps): Declared dependency used indirectly; common pattern in plugin/config-driven architectures. | ai | |
| phantom-deps | phantom-dep:jiti | AI (phantom-deps): Declared dependency used indirectly; common pattern in plugin/config-driven architectures. | ai | |
| phantom-deps | phantom-dep:powerlines | AI (phantom-deps): Declared dependency used indirectly; common pattern in plugin/config-driven architectures. | ai | |
| phantom-deps | phantom-dep:@stryke/types | AI (phantom-deps): Declared dependency used indirectly; common pattern in plugin/config-driven architectures. | ai | |
| phantom-deps | phantom-dep:openapi-typescript | AI (phantom-deps): Declared dependency used indirectly; common pattern in plugin/config-driven architectures. | ai | |
| dependencies | unvetted-dep:powerlines | AI (dependencies): powerlines is the core package of the same Storm Software ecosystem; unvetted status reflects review queue lag, not a security concern for this publisher. | ai | |
| dependencies | unvetted-dep:@stryke/type-checks | AI (dependencies): @stryke/type-checks is a Storm Software utility library from the same org; no security concern. | ai | |
| dependencies | unvetted-dep:@stryke/types | AI (dependencies): @stryke/types is a Storm Software utility library from the same org; no security concern. | ai | |
| dependencies | unvetted-dep:@stryke/path | AI (dependencies): @stryke/path is a Storm Software utility library from the same org; no security concern. | ai |
Versions (showing 51 of 587)
| Version | Deps | Published |
|---|---|---|
| 0.2.611 | 9 / 2 | |
| 0.2.610 | 7 / 2 | |
| 0.2.609 | 7 / 2 | |
| 0.2.608 | 7 / 2 | |
| 0.2.607 | 7 / 2 | |
| 0.2.606 | 7 / 2 | |
| 0.2.605 | 7 / 2 | |
| 0.2.604 | 7 / 2 | |
| 0.2.603 | 7 / 2 | |
| 0.2.602 | 7 / 2 | |
| 0.2.601 | 7 / 2 | |
| 0.2.600 | 7 / 2 | |
| 0.2.599 | 7 / 2 | |
| 0.2.598 | 7 / 2 | |
| 0.2.597 | 7 / 2 | |
| 0.2.596 | 7 / 2 | |
| 0.2.595 | 7 / 2 | |
| 0.2.594 | 7 / 2 | |
| 0.2.593 | 7 / 2 | |
| 0.2.592 | 7 / 2 | |
| 0.2.591 | 7 / 2 | |
| 0.2.590 | 7 / 2 | |
| 0.2.589 | 7 / 2 | |
| 0.2.588 | 7 / 2 | |
| 0.2.587 | 7 / 2 | |
| 0.2.586 | 7 / 2 | |
| 0.2.585 | 7 / 2 | |
| 0.2.584 | 7 / 2 | |
| 0.2.583 | 7 / 2 | |
| 0.2.582 | 7 / 2 | |
| 0.2.581 | 7 / 2 | |
| 0.2.580 | 7 / 2 | |
| 0.2.579 | 7 / 2 | |
| 0.2.578 | 7 / 2 | |
| 0.2.577 | 7 / 2 | |
| 0.2.576 | 7 / 2 | |
| 0.2.575 | 7 / 2 | |
| 0.2.574 | 7 / 2 | |
| 0.2.573 | 7 / 2 | |
| 0.2.572 | 7 / 2 | |
| 0.2.571 | 7 / 2 | |
| 0.2.570 | 7 / 2 | |
| 0.2.569 | 7 / 2 | |
| 0.2.568 | 7 / 2 | |
| 0.2.567 | 7 / 2 | |
| 0.2.566 | 7 / 2 | |
| 0.2.565 | 7 / 2 | |
| 0.2.564 | 7 / 2 | |
| 0.2.563 | 7 / 2 | |
| 0.2.562 | 7 / 2 | |
| 0.2.561 | 7 / 2 |
v0.2.611
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.610
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.609
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.608
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.607
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.606
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.605
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.