@powerlines/plugin-style-dictionary
A Powerlines plugin to generate project code with Style Dictionary.
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@power-plant/style-dictionary | AI (dependencies): Same-org monorepo sibling dependency, not third-party. | ai | |
| phantom-deps | phantom-dep:@power-plant/core | AI (phantom-deps): Likely bundled dist build; package ships compiled output only. | ai | |
| dependencies | unvetted-dep:@powerlines/plugin-power-plant | AI (dependencies): Same-org monorepo sibling dependency, not third-party. | ai | |
| dependencies | unvetted-dep:@power-plant/core | AI (dependencies): Same-org monorepo sibling dependency, not third-party. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New deps are from the same Storm Software org; consistent with internal refactoring across this package family. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Large file counts reflect rolldown bundling virtual modules into dist. Expected pattern for this Storm Software package family. | ai | |
| provenance | publisher-changed | AI (provenance): Storm Software migrated publishing to GitHub Actions CI/CD with SLSA provenance attestation. This is a legitimate automation transition, not a compromise. | ai | |
| source-diff | obfuscated-file:dist/index.mjs | AI (source-diff): dist/index.mjs is standard minified ESM bundle output from esbuild, not obfuscation. SLSA provenance confirms CI/CD build integrity. Stable false positive for this package. | ai | |
| source-diff | obfuscated-file:dist/index.cjs | AI (source-diff): dist/index.cjs is a standard minified CJS bundle output. Code is readable and benign. Long lines are from bundling, not obfuscation. Stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:defu | AI (phantom-deps): Phantom dependency is expected; defu is a legitimate utility used in config processing for this plugin. | ai | |
| phantom-deps | phantom-dep:@stryke/types | AI (phantom-deps): Type utilities used indirectly; phantom dependency is expected in this plugin context. | ai | |
| phantom-deps | phantom-dep:powerlines | AI (phantom-deps): Core plugin dependency; used through plugin architecture rather than direct imports. | ai | |
| phantom-deps | phantom-dep:@stryke/type-checks | AI (phantom-deps): Type checking utilities used indirectly; expected phantom dependency pattern. | ai | |
| phantom-deps | phantom-dep:style-dictionary | AI (phantom-deps): Core dependency for this style-dictionary plugin; used through plugin interface. | ai | |
| phantom-deps | phantom-dep:jiti | AI (phantom-deps): jiti is declared as a runtime dependency and used in config files; phantom-dep flag is a false positive for this config-tooling pattern. | ai | |
| provenance | slsa-provenance | AI (provenance): Package is consistently published via CI/CD with Sigstore SLSA attestation; this is a stable positive signal for the entire package ecosystem. | ai | |
| phantom-deps | phantom-dep:@stryke/path | AI (phantom-deps): @stryke/path is a sibling ecosystem package declared as a dependency and referenced in config; phantom-dep flag is a false positive here. | ai |
Versions (showing 51 of 597)
| Version | Deps | Published |
|---|---|---|
| 0.3.515 | 10 / 2 | |
| 0.3.514 | 11 / 2 | |
| 0.3.513 | 8 / 2 | |
| 0.3.512 | 8 / 2 | |
| 0.3.511 | 8 / 2 | |
| 0.3.510 | 8 / 2 | |
| 0.3.509 | 8 / 2 | |
| 0.3.508 | 8 / 2 | |
| 0.3.507 | 8 / 2 | |
| 0.3.506 | 8 / 2 | |
| 0.3.505 | 8 / 2 | |
| 0.3.504 | 8 / 2 | |
| 0.3.503 | 8 / 2 | |
| 0.3.502 | 8 / 2 | |
| 0.3.501 | 8 / 2 | |
| 0.3.500 | 8 / 2 | |
| 0.3.499 | 8 / 2 | |
| 0.3.498 | 8 / 2 | |
| 0.3.497 | 8 / 2 | |
| 0.3.496 | 8 / 2 | |
| 0.3.495 | 8 / 2 | |
| 0.3.494 | 8 / 2 | |
| 0.3.493 | 8 / 2 | |
| 0.3.492 | 8 / 2 | |
| 0.3.491 | 8 / 2 | |
| 0.3.490 | 8 / 2 | |
| 0.3.489 | 8 / 2 | |
| 0.3.488 | 8 / 2 | |
| 0.3.487 | 8 / 2 | |
| 0.3.486 | 8 / 2 | |
| 0.3.485 | 8 / 2 | |
| 0.3.484 | 8 / 2 | |
| 0.3.483 | 8 / 2 | |
| 0.3.482 | 8 / 2 | |
| 0.3.481 | 8 / 2 | |
| 0.3.480 | 8 / 2 | |
| 0.3.479 | 8 / 2 | |
| 0.3.478 | 8 / 2 | |
| 0.3.477 | 8 / 2 | |
| 0.3.476 | 8 / 2 | |
| 0.3.475 | 8 / 2 | |
| 0.3.474 | 8 / 2 | |
| 0.3.473 | 8 / 2 | |
| 0.3.472 | 8 / 2 | |
| 0.3.471 | 8 / 2 | |
| 0.3.470 | 8 / 2 | |
| 0.3.469 | 8 / 2 | |
| 0.3.468 | 8 / 2 | |
| 0.3.467 | 8 / 2 | |
| 0.3.466 | 8 / 2 | |
| 0.3.465 | 8 / 2 |
v0.3.515
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3.514
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3.513
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3.512
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3.511
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3.510
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3.509
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3.508
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.