@powerlines/plugin-rollup
A package containing a Powerlines plugin to assist in developing other Powerlines plugins.
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@powerlines/unplugin | AI (dependencies): Same-org dependency (@powerlines namespace); consistent with this package's internal ecosystem structure. | ai | |
| phantom-deps | phantom-dep:@rollup/plugin-alias | AI (phantom-deps): Framework-scoped rollup plugin loaded by convention; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@rollup/plugin-babel | AI (phantom-deps): Framework-scoped rollup plugin loaded by convention; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@rollup/plugin-inject | AI (phantom-deps): Framework-scoped rollup plugin loaded by convention; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@rollup/plugin-replace | AI (phantom-deps): Framework-scoped rollup plugin loaded by convention; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:rollup-plugin-typescript2 | AI (phantom-deps): Referenced in config files by convention; stable false positive for this rollup plugin package. | ai | |
| phantom-deps | phantom-dep:@rollup/plugin-node-resolve | AI (phantom-deps): Framework-scoped rollup plugin loaded by convention; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@stryke/helpers | AI (phantom-deps): Same-org helper package referenced in config files; stable false positive for this package. | ai | |
| source-diff | obfuscated-file:dist/powerlines/src/api.cjs | AI (source-diff): Minified rolldown bundle output. Content is legitimate build tooling logic with standard npm imports. No malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/powerlines/src/lib/contexts/environment-context.cjs | AI (source-diff): Minified rolldown bundle output. Content is legitimate plugin context logic. No malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/powerlines/schemas/fs.cjs | AI (source-diff): Minified rolldown bundle output with capnp schema definitions. Legitimate data structure code. No malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/powerlines/src/internal/helpers/resolve-tsconfig.cjs | AI (source-diff): Minified rolldown bundle output. Content is TypeScript config resolution logic. No malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/powerlines/src/lib/build/rollup.cjs | AI (source-diff): Minified rolldown bundle output. Content is rollup build configuration logic. No malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/powerlines/src/lib/fs/vfs.cjs | AI (source-diff): Minified rolldown bundle output. Content is virtual filesystem implementation. No malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/powerlines/src/lib/contexts/api-context.mjs | AI (source-diff): Minified rolldown bundle output (ESM variant). Expected build artifact for this build tool plugin package. | ai | |
| source-diff | obfuscated-file:dist/powerlines/src/lib/contexts/api-context.cjs | AI (source-diff): Minified rolldown/rollup bundle output, not obfuscated malware. Code is readable JS class definitions. Expected for a build tool plugin package. | ai | |
| source-diff | obfuscated-file:dist/powerlines/src/lib/contexts/context.cjs | AI (source-diff): Minified rolldown bundle output. Content is legitimate context class implementation. No malicious patterns. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): All new deps are established rollup ecosystem plugins or same-org @powerlines/* packages. Consistent with a legitimate refactor splitting functionality across packages. | ai | |
| provenance | publisher-changed | AI (provenance): Publisher changed from stormie-bot to GitHub Actions with SLSA provenance attestation — this is a CI/CD migration by the same org (Storm Software), not a hostile takeover. | ai | |
| phantom-deps | phantom-dep:unplugin | AI (phantom-deps): Unplugin is used in plugin configuration; phantom pattern is expected for Rollup plugins. | ai | |
| phantom-deps | phantom-dep:defu | AI (phantom-deps): Phantom dep pattern is expected for build tool plugins; defu is used in config context. | ai | |
| phantom-deps | phantom-dep:rollup | AI (phantom-deps): Rollup is a peer/plugin dependency used in config context; phantom pattern is stable for this package type. | ai | |
| phantom-deps | phantom-dep:powerlines | AI (phantom-deps): Powerlines is the parent framework used in config context; phantom pattern is stable. | ai | |
| phantom-deps | phantom-dep:@stryke/path | AI (phantom-deps): Phantom dep pattern is expected for build tool plugins; used in config context. | ai | |
| phantom-deps | phantom-dep:@stryke/convert | AI (phantom-deps): Phantom dep pattern is expected for build tool plugins; used in config context. | ai | |
| phantom-deps | phantom-dep:@stryke/type-checks | AI (phantom-deps): Phantom dep pattern is expected for build tool plugins; used in config context. | ai | |
| phantom-deps | phantom-dep:jiti | AI (phantom-deps): jiti is a well-known runtime TS loader; declared for config file usage, not a security concern for this package. | ai | |
| phantom-deps | phantom-dep:@powerlines/plugin-babel | AI (phantom-deps): Same org scope (@powerlines); sibling plugin dependency used in config files, not a security concern. | ai | |
| phantom-deps | phantom-dep:@stryke/types | AI (phantom-deps): Same publisher ecosystem (@stryke); type-only dependency declared for config usage, not a security concern. | ai | |
| phantom-deps | phantom-dep:@stryke/fs | AI (phantom-deps): Same publisher ecosystem (@stryke); declared for config file usage, not a security concern. | ai |
Versions (showing 51 of 406)
| Version | Deps | Published |
|---|---|---|
| 0.7.582 | 18 / 2 | |
| 0.7.581 | 18 / 2 | |
| 0.7.580 | 18 / 2 | |
| 0.7.579 | 18 / 2 | |
| 0.7.578 | 18 / 2 | |
| 0.7.577 | 18 / 2 | |
| 0.7.576 | 18 / 2 | |
| 0.7.575 | 18 / 2 | |
| 0.7.574 | 18 / 2 | |
| 0.7.573 | 18 / 2 | |
| 0.7.572 | 18 / 2 | |
| 0.7.571 | 18 / 2 | |
| 0.7.570 | 18 / 2 | |
| 0.7.569 | 18 / 2 | |
| 0.7.568 | 18 / 2 | |
| 0.7.567 | 18 / 2 | |
| 0.7.566 | 18 / 2 | |
| 0.7.565 | 18 / 2 | |
| 0.7.564 | 18 / 2 | |
| 0.7.563 | 18 / 2 | |
| 0.7.562 | 18 / 2 | |
| 0.7.561 | 18 / 2 | |
| 0.7.560 | 18 / 2 | |
| 0.7.559 | 18 / 2 | |
| 0.7.558 | 18 / 2 | |
| 0.7.557 | 18 / 2 | |
| 0.7.556 | 18 / 2 | |
| 0.7.555 | 18 / 2 | |
| 0.7.554 | 18 / 2 | |
| 0.7.553 | 18 / 2 | |
| 0.7.552 | 18 / 2 | |
| 0.7.551 | 18 / 2 | |
| 0.7.550 | 18 / 2 | |
| 0.7.549 | 18 / 2 | |
| 0.7.548 | 18 / 2 | |
| 0.7.547 | 18 / 2 | |
| 0.7.546 | 18 / 2 | |
| 0.7.545 | 18 / 2 | |
| 0.7.544 | 18 / 2 | |
| 0.7.543 | 18 / 2 | |
| 0.7.542 | 18 / 2 | |
| 0.7.541 | 18 / 2 | |
| 0.7.540 | 18 / 2 | |
| 0.7.539 | 18 / 2 | |
| 0.7.538 | 18 / 2 | |
| 0.7.536 | 18 / 2 | |
| 0.7.535 | 18 / 2 | |
| 0.7.534 | 18 / 2 | |
| 0.7.533 | 18 / 2 | |
| 0.7.532 | 18 / 2 | |
| 0.7.531 | 18 / 2 |
v0.7.582
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.581
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.580
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.579
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.578
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.577
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.576
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.575
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.574
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.573
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.572
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.571
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.570
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.569
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.568
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.567
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.566
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.565
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.564
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.563
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.562
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.561
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.560
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.559
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.558
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.557
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.556
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.555
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.554
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.553
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.552
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.551
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.550
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.549
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.548
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.547
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.546
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.545
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.544
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.543
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.542
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.541
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.540
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.539
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.538
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.536
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.535
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.534
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.533
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.532
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.531
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.