← Home

@powerlines/plugin-rollup

A package containing a Powerlines plugin to assist in developing other Powerlines plugins.

51
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

stormie-botsullivanpj

Keywords

rolluppowerlinesstorm-softwarepowerlines-plugin

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@powerlines/unplugin AI (dependencies): Same-org dependency (@powerlines namespace); consistent with this package's internal ecosystem structure. ai
phantom-deps phantom-dep:@rollup/plugin-alias AI (phantom-deps): Framework-scoped rollup plugin loaded by convention; stable false positive for this package. ai
phantom-deps phantom-dep:@rollup/plugin-babel AI (phantom-deps): Framework-scoped rollup plugin loaded by convention; stable false positive for this package. ai
phantom-deps phantom-dep:@rollup/plugin-inject AI (phantom-deps): Framework-scoped rollup plugin loaded by convention; stable false positive for this package. ai
phantom-deps phantom-dep:@rollup/plugin-replace AI (phantom-deps): Framework-scoped rollup plugin loaded by convention; stable false positive for this package. ai
phantom-deps phantom-dep:rollup-plugin-typescript2 AI (phantom-deps): Referenced in config files by convention; stable false positive for this rollup plugin package. ai
phantom-deps phantom-dep:@rollup/plugin-node-resolve AI (phantom-deps): Framework-scoped rollup plugin loaded by convention; stable false positive for this package. ai
phantom-deps phantom-dep:@stryke/helpers AI (phantom-deps): Same-org helper package referenced in config files; stable false positive for this package. ai
source-diff obfuscated-file:dist/powerlines/src/api.cjs AI (source-diff): Minified rolldown bundle output. Content is legitimate build tooling logic with standard npm imports. No malicious patterns. ai
source-diff obfuscated-file:dist/powerlines/src/lib/contexts/environment-context.cjs AI (source-diff): Minified rolldown bundle output. Content is legitimate plugin context logic. No malicious patterns. ai
source-diff obfuscated-file:dist/powerlines/schemas/fs.cjs AI (source-diff): Minified rolldown bundle output with capnp schema definitions. Legitimate data structure code. No malicious patterns. ai
source-diff obfuscated-file:dist/powerlines/src/internal/helpers/resolve-tsconfig.cjs AI (source-diff): Minified rolldown bundle output. Content is TypeScript config resolution logic. No malicious patterns. ai
source-diff obfuscated-file:dist/powerlines/src/lib/build/rollup.cjs AI (source-diff): Minified rolldown bundle output. Content is rollup build configuration logic. No malicious patterns. ai
source-diff obfuscated-file:dist/powerlines/src/lib/fs/vfs.cjs AI (source-diff): Minified rolldown bundle output. Content is virtual filesystem implementation. No malicious patterns. ai
source-diff obfuscated-file:dist/powerlines/src/lib/contexts/api-context.mjs AI (source-diff): Minified rolldown bundle output (ESM variant). Expected build artifact for this build tool plugin package. ai
source-diff obfuscated-file:dist/powerlines/src/lib/contexts/api-context.cjs AI (source-diff): Minified rolldown/rollup bundle output, not obfuscated malware. Code is readable JS class definitions. Expected for a build tool plugin package. ai
source-diff obfuscated-file:dist/powerlines/src/lib/contexts/context.cjs AI (source-diff): Minified rolldown bundle output. Content is legitimate context class implementation. No malicious patterns. ai
publish-pattern new-deps-added AI (publish-pattern): All new deps are established rollup ecosystem plugins or same-org @powerlines/* packages. Consistent with a legitimate refactor splitting functionality across packages. ai
provenance publisher-changed AI (provenance): Publisher changed from stormie-bot to GitHub Actions with SLSA provenance attestation — this is a CI/CD migration by the same org (Storm Software), not a hostile takeover. ai
phantom-deps phantom-dep:unplugin AI (phantom-deps): Unplugin is used in plugin configuration; phantom pattern is expected for Rollup plugins. ai
phantom-deps phantom-dep:defu AI (phantom-deps): Phantom dep pattern is expected for build tool plugins; defu is used in config context. ai
phantom-deps phantom-dep:rollup AI (phantom-deps): Rollup is a peer/plugin dependency used in config context; phantom pattern is stable for this package type. ai
phantom-deps phantom-dep:powerlines AI (phantom-deps): Powerlines is the parent framework used in config context; phantom pattern is stable. ai
phantom-deps phantom-dep:@stryke/path AI (phantom-deps): Phantom dep pattern is expected for build tool plugins; used in config context. ai
phantom-deps phantom-dep:@stryke/convert AI (phantom-deps): Phantom dep pattern is expected for build tool plugins; used in config context. ai
phantom-deps phantom-dep:@stryke/type-checks AI (phantom-deps): Phantom dep pattern is expected for build tool plugins; used in config context. ai
phantom-deps phantom-dep:jiti AI (phantom-deps): jiti is a well-known runtime TS loader; declared for config file usage, not a security concern for this package. ai
phantom-deps phantom-dep:@powerlines/plugin-babel AI (phantom-deps): Same org scope (@powerlines); sibling plugin dependency used in config files, not a security concern. ai
phantom-deps phantom-dep:@stryke/types AI (phantom-deps): Same publisher ecosystem (@stryke); type-only dependency declared for config usage, not a security concern. ai
phantom-deps phantom-dep:@stryke/fs AI (phantom-deps): Same publisher ecosystem (@stryke); declared for config file usage, not a security concern. ai

Versions (showing 51 of 441)

View all versions
Version Deps Published
0.7.618 18 / 2
0.7.617 18 / 2
0.7.616 18 / 2
0.7.615 18 / 2
0.7.614 18 / 2
0.7.613 18 / 2
0.7.612 18 / 2
0.7.611 18 / 2
0.7.610 18 / 2
0.7.609 18 / 2
0.7.608 18 / 2
0.7.607 18 / 2
0.7.606 18 / 2
0.7.605 18 / 2
0.7.604 18 / 2
0.7.602 18 / 2
0.7.601 18 / 2
0.7.600 18 / 2
0.7.599 18 / 2
0.7.598 18 / 2
0.7.597 18 / 2
0.7.596 18 / 2
0.7.595 18 / 2
0.7.594 18 / 2
0.7.593 18 / 2
0.7.592 18 / 2
0.7.591 18 / 2
0.7.590 18 / 2
0.7.589 18 / 2
0.7.588 18 / 2
0.7.587 18 / 2
0.7.586 18 / 2
0.7.585 18 / 2
0.7.584 18 / 2
0.7.583 18 / 2
0.7.582 18 / 2
0.7.581 18 / 2
0.7.580 18 / 2
0.7.579 18 / 2
0.7.578 18 / 2
0.7.577 18 / 2
0.7.576 18 / 2
0.7.575 18 / 2
0.7.574 18 / 2
0.7.573 18 / 2
0.7.572 18 / 2
0.7.571 18 / 2
0.7.570 18 / 2
0.7.569 18 / 2
0.7.568 18 / 2
0.7.567 18 / 2

v0.7.618

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.617

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.616

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.615

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.614

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.613

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.612

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.611

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.610

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.609

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.608

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.607

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.606

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.605

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.604

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.602

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.601

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.600

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.599

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.598

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.597

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.596

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.595

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.594

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.