← Home

@powerlines/plugin-rollup

A package containing a Powerlines plugin to assist in developing other Powerlines plugins.

100
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

stormie-botsullivanpj

Keywords

rolluppowerlinesstorm-softwarepowerlines-plugin

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@powerlines/unplugin AI (dependencies): Same-org dependency (@powerlines namespace); consistent with this package's internal ecosystem structure. ai
phantom-deps phantom-dep:@rollup/plugin-alias AI (phantom-deps): Framework-scoped rollup plugin loaded by convention; stable false positive for this package. ai
phantom-deps phantom-dep:@rollup/plugin-babel AI (phantom-deps): Framework-scoped rollup plugin loaded by convention; stable false positive for this package. ai
phantom-deps phantom-dep:@rollup/plugin-inject AI (phantom-deps): Framework-scoped rollup plugin loaded by convention; stable false positive for this package. ai
phantom-deps phantom-dep:@rollup/plugin-replace AI (phantom-deps): Framework-scoped rollup plugin loaded by convention; stable false positive for this package. ai
phantom-deps phantom-dep:rollup-plugin-typescript2 AI (phantom-deps): Referenced in config files by convention; stable false positive for this rollup plugin package. ai
phantom-deps phantom-dep:@rollup/plugin-node-resolve AI (phantom-deps): Framework-scoped rollup plugin loaded by convention; stable false positive for this package. ai
phantom-deps phantom-dep:@stryke/helpers AI (phantom-deps): Same-org helper package referenced in config files; stable false positive for this package. ai
source-diff obfuscated-file:dist/powerlines/src/api.cjs AI (source-diff): Minified rolldown bundle output. Content is legitimate build tooling logic with standard npm imports. No malicious patterns. ai
source-diff obfuscated-file:dist/powerlines/src/lib/contexts/environment-context.cjs AI (source-diff): Minified rolldown bundle output. Content is legitimate plugin context logic. No malicious patterns. ai
source-diff obfuscated-file:dist/powerlines/schemas/fs.cjs AI (source-diff): Minified rolldown bundle output with capnp schema definitions. Legitimate data structure code. No malicious patterns. ai
source-diff obfuscated-file:dist/powerlines/src/internal/helpers/resolve-tsconfig.cjs AI (source-diff): Minified rolldown bundle output. Content is TypeScript config resolution logic. No malicious patterns. ai
source-diff obfuscated-file:dist/powerlines/src/lib/build/rollup.cjs AI (source-diff): Minified rolldown bundle output. Content is rollup build configuration logic. No malicious patterns. ai
source-diff obfuscated-file:dist/powerlines/src/lib/fs/vfs.cjs AI (source-diff): Minified rolldown bundle output. Content is virtual filesystem implementation. No malicious patterns. ai
source-diff obfuscated-file:dist/powerlines/src/lib/contexts/api-context.mjs AI (source-diff): Minified rolldown bundle output (ESM variant). Expected build artifact for this build tool plugin package. ai
source-diff obfuscated-file:dist/powerlines/src/lib/contexts/api-context.cjs AI (source-diff): Minified rolldown/rollup bundle output, not obfuscated malware. Code is readable JS class definitions. Expected for a build tool plugin package. ai
source-diff obfuscated-file:dist/powerlines/src/lib/contexts/context.cjs AI (source-diff): Minified rolldown bundle output. Content is legitimate context class implementation. No malicious patterns. ai
publish-pattern new-deps-added AI (publish-pattern): All new deps are established rollup ecosystem plugins or same-org @powerlines/* packages. Consistent with a legitimate refactor splitting functionality across packages. ai
provenance publisher-changed AI (provenance): Publisher changed from stormie-bot to GitHub Actions with SLSA provenance attestation — this is a CI/CD migration by the same org (Storm Software), not a hostile takeover. ai
phantom-deps phantom-dep:unplugin AI (phantom-deps): Unplugin is used in plugin configuration; phantom pattern is expected for Rollup plugins. ai
phantom-deps phantom-dep:defu AI (phantom-deps): Phantom dep pattern is expected for build tool plugins; defu is used in config context. ai
phantom-deps phantom-dep:rollup AI (phantom-deps): Rollup is a peer/plugin dependency used in config context; phantom pattern is stable for this package type. ai
phantom-deps phantom-dep:powerlines AI (phantom-deps): Powerlines is the parent framework used in config context; phantom pattern is stable. ai
phantom-deps phantom-dep:@stryke/path AI (phantom-deps): Phantom dep pattern is expected for build tool plugins; used in config context. ai
phantom-deps phantom-dep:@stryke/convert AI (phantom-deps): Phantom dep pattern is expected for build tool plugins; used in config context. ai
phantom-deps phantom-dep:@stryke/type-checks AI (phantom-deps): Phantom dep pattern is expected for build tool plugins; used in config context. ai
phantom-deps phantom-dep:jiti AI (phantom-deps): jiti is a well-known runtime TS loader; declared for config file usage, not a security concern for this package. ai
phantom-deps phantom-dep:@powerlines/plugin-babel AI (phantom-deps): Same org scope (@powerlines); sibling plugin dependency used in config files, not a security concern. ai
phantom-deps phantom-dep:@stryke/types AI (phantom-deps): Same publisher ecosystem (@stryke); type-only dependency declared for config usage, not a security concern. ai
phantom-deps phantom-dep:@stryke/fs AI (phantom-deps): Same publisher ecosystem (@stryke); declared for config file usage, not a security concern. ai

Versions (showing 100 of 445)

Version Deps Published
0.7.402 16 / 2
0.7.401 16 / 2
0.7.400 16 / 2
0.7.399 16 / 2
0.7.398 16 / 2
0.7.397 16 / 2
0.7.396 16 / 2
0.7.395 16 / 2
0.7.394 16 / 2
0.7.393 16 / 2
0.7.392 16 / 2
0.7.391 16 / 2
0.7.390 16 / 2
0.7.389 16 / 2
0.7.388 16 / 2
0.7.387 16 / 2
0.7.386 16 / 2
0.7.385 16 / 2
0.7.384 16 / 2
0.7.383 16 / 2
0.7.382 16 / 2
0.7.381 16 / 2
0.7.380 16 / 2
0.7.379 16 / 2
0.7.378 16 / 2
0.7.377 16 / 2
0.7.376 16 / 2
0.7.375 16 / 2
0.7.374 16 / 2
0.7.373 16 / 2
0.7.372 16 / 2
0.7.371 16 / 2
0.7.370 16 / 2
0.7.369 16 / 2
0.7.368 16 / 2
0.7.366 16 / 2
0.7.365 16 / 2
0.7.364 16 / 2
0.7.363 16 / 2
0.7.362 16 / 2
0.7.361 16 / 2
0.7.358 16 / 2
0.7.357 16 / 2
0.7.356 16 / 2
0.7.355 16 / 2
0.7.354 16 / 2
0.7.353 16 / 2
0.7.352 16 / 2
0.7.351 16 / 2
0.7.350 16 / 2
0.7.349 16 / 2
0.7.348 16 / 2
0.7.347 16 / 2
0.7.346 16 / 2
0.7.345 16 / 2
0.7.344 16 / 2
0.7.343 16 / 2
0.7.342 16 / 2
0.7.340 16 / 2
0.7.339 16 / 2
0.7.338 16 / 2
0.7.337 16 / 2
0.7.336 16 / 2
0.7.335 16 / 2
0.7.334 16 / 2
0.7.333 16 / 2
0.7.332 16 / 2
0.7.331 16 / 2
0.7.330 16 / 2
0.7.329 16 / 2
0.7.328 16 / 2
0.7.327 16 / 2
0.7.326 16 / 2
0.7.325 16 / 2
0.7.324 16 / 2
0.7.323 16 / 2
0.7.322 16 / 2
0.7.321 16 / 2
0.7.320 16 / 2
0.7.319 16 / 2
0.7.318 16 / 2
0.7.317 16 / 2
0.7.316 16 / 2
0.7.315 16 / 2
0.7.314 16 / 2
0.7.313 16 / 2
0.7.312 16 / 2
0.7.311 16 / 2
0.7.310 16 / 2
0.7.309 16 / 2
0.7.308 16 / 2
0.7.307 16 / 2
0.7.306 15 / 2
0.7.305 15 / 2
0.7.304 15 / 2
0.7.303 15 / 2
0.7.302 16 / 1
0.7.301 16 / 1
0.7.300 10 / 2
0.7.299 10 / 2
Showing 100 of 445 Next page →