← Home

@powerlines/plugin-style-dictionary

A Powerlines plugin to generate project code with Style Dictionary.

51
Versions
Apache-2.0
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures gitHead linked

Maintainers

stormie-botsullivanpj

Keywords

style-dictionarypowerlinesstorm-softwarepowerlines-plugin

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@power-plant/style-dictionary AI (dependencies): Same-org monorepo sibling dependency, not third-party. ai
phantom-deps phantom-dep:@power-plant/core AI (phantom-deps): Likely bundled dist build; package ships compiled output only. ai
dependencies unvetted-dep:@powerlines/plugin-power-plant AI (dependencies): Same-org monorepo sibling dependency, not third-party. ai
dependencies unvetted-dep:@power-plant/core AI (dependencies): Same-org monorepo sibling dependency, not third-party. ai
publish-pattern new-deps-added AI (publish-pattern): New deps are from the same Storm Software org; consistent with internal refactoring across this package family. ai
source-diff large-new-source-files AI (source-diff): Large file counts reflect rolldown bundling virtual modules into dist. Expected pattern for this Storm Software package family. ai
provenance publisher-changed AI (provenance): Storm Software migrated publishing to GitHub Actions CI/CD with SLSA provenance attestation. This is a legitimate automation transition, not a compromise. ai
source-diff obfuscated-file:dist/index.mjs AI (source-diff): dist/index.mjs is standard minified ESM bundle output from esbuild, not obfuscation. SLSA provenance confirms CI/CD build integrity. Stable false positive for this package. ai
source-diff obfuscated-file:dist/index.cjs AI (source-diff): dist/index.cjs is a standard minified CJS bundle output. Code is readable and benign. Long lines are from bundling, not obfuscation. Stable false positive for this package. ai
phantom-deps phantom-dep:defu AI (phantom-deps): Phantom dependency is expected; defu is a legitimate utility used in config processing for this plugin. ai
phantom-deps phantom-dep:@stryke/types AI (phantom-deps): Type utilities used indirectly; phantom dependency is expected in this plugin context. ai
phantom-deps phantom-dep:powerlines AI (phantom-deps): Core plugin dependency; used through plugin architecture rather than direct imports. ai
phantom-deps phantom-dep:@stryke/type-checks AI (phantom-deps): Type checking utilities used indirectly; expected phantom dependency pattern. ai
phantom-deps phantom-dep:style-dictionary AI (phantom-deps): Core dependency for this style-dictionary plugin; used through plugin interface. ai
phantom-deps phantom-dep:jiti AI (phantom-deps): jiti is declared as a runtime dependency and used in config files; phantom-dep flag is a false positive for this config-tooling pattern. ai
provenance slsa-provenance AI (provenance): Package is consistently published via CI/CD with Sigstore SLSA attestation; this is a stable positive signal for the entire package ecosystem. ai
phantom-deps phantom-dep:@stryke/path AI (phantom-deps): @stryke/path is a sibling ecosystem package declared as a dependency and referenced in config; phantom-dep flag is a false positive here. ai

Versions (showing 51 of 597)

View all versions
Version Deps Published
0.3.515 10 / 2
0.3.514 11 / 2
0.3.513 8 / 2
0.3.512 8 / 2
0.3.511 8 / 2
0.3.510 8 / 2
0.3.509 8 / 2
0.3.508 8 / 2
0.3.507 8 / 2
0.3.506 8 / 2
0.3.505 8 / 2
0.3.504 8 / 2
0.3.503 8 / 2
0.3.502 8 / 2
0.3.501 8 / 2
0.3.500 8 / 2
0.3.499 8 / 2
0.3.498 8 / 2
0.3.497 8 / 2
0.3.496 8 / 2
0.3.495 8 / 2
0.3.494 8 / 2
0.3.493 8 / 2
0.3.492 8 / 2
0.3.491 8 / 2
0.3.490 8 / 2
0.3.489 8 / 2
0.3.488 8 / 2
0.3.487 8 / 2
0.3.486 8 / 2
0.3.485 8 / 2
0.3.484 8 / 2
0.3.483 8 / 2
0.3.482 8 / 2
0.3.481 8 / 2
0.3.480 8 / 2
0.3.479 8 / 2
0.3.478 8 / 2
0.3.477 8 / 2
0.3.476 8 / 2
0.3.475 8 / 2
0.3.474 8 / 2
0.3.473 8 / 2
0.3.472 8 / 2
0.3.471 8 / 2
0.3.470 8 / 2
0.3.469 8 / 2
0.3.468 8 / 2
0.3.467 8 / 2
0.3.466 8 / 2
0.3.465 8 / 2

v0.3.515

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.514

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.513

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.512

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.511

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.510

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.509

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.508

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.