← Home

@powerlines/plugin-tsup

A package containing a Powerlines plugin to assist in developing other Powerlines plugins.

51
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

stormie-botsullivanpj

Keywords

tsuppowerlinesstorm-softwarepowerlines-plugin

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): stormie-bot is Storm Software's established release bot with 5762 approved packages; publisher change is expected for this org. ai
phantom-deps phantom-dep:@stryke/path AI (phantom-deps): Config-referenced dependency; stable pattern for this package. ai
phantom-deps phantom-dep:@stryke/helpers AI (phantom-deps): Config-referenced dependency; stable pattern for this package. ai
phantom-deps phantom-dep:@powerlines/core AI (phantom-deps): Same-org scoped dependency; stable pattern for this package. ai
phantom-deps phantom-dep:@powerlines/plugin-esbuild AI (phantom-deps): Same-org scoped dependency; stable pattern for this package. ai
phantom-deps phantom-dep:@storm-software/build-tools AI (phantom-deps): Config-referenced dependency; stable pattern for this package. ai
phantom-deps phantom-dep:defu AI (phantom-deps): Config-referenced dependency; stable pattern for this package. ai
phantom-deps phantom-dep:unplugin AI (phantom-deps): Config-referenced dependency; stable pattern for this package. ai
phantom-deps phantom-dep:@stryke/convert AI (phantom-deps): Config-referenced dependency; stable pattern for this package. ai
bogus-package bogus-package AI (bogus-package): Storm Software monorepo packages consistently trigger README signals due to templated/generated READMEs. Publisher has 224 approved packages, SLSA provenance, and legitimate package purpose. Not a spam/phishing operation. ai
dependencies unvetted-dep:@storm-software/tsup AI (dependencies): @storm-software/tsup is a first-party dependency from the same Storm Software org; consistent with this package's purpose as a tsup build plugin. ai
phantom-deps phantom-dep:@stryke/types AI (phantom-deps): @stryke/types is a declared runtime dep used in config files; phantom-dep finding is a false positive for this package's pattern of config-referenced type packages. ai
phantom-deps phantom-dep:@stryke/type-checks AI (phantom-deps): @stryke/type-checks is a declared runtime dep used in config files; same benign config-reference pattern as @stryke/types. ai

Versions (showing 51 of 618)

View all versions
Version Deps Published
0.12.624 11 / 3
0.12.623 11 / 3
0.12.622 11 / 3
0.12.621 11 / 3
0.12.620 11 / 3
0.12.619 11 / 3
0.12.618 11 / 3
0.12.617 11 / 3
0.12.616 11 / 3
0.12.615 11 / 3
0.12.614 11 / 3
0.12.613 11 / 3
0.12.612 11 / 3
0.12.611 11 / 3
0.12.610 11 / 3
0.12.609 11 / 3
0.12.608 11 / 3
0.12.607 11 / 3
0.12.606 11 / 3
0.12.604 11 / 3
0.12.603 11 / 3
0.12.602 11 / 3
0.12.601 11 / 3
0.12.600 11 / 3
0.12.599 11 / 3
0.12.598 11 / 3
0.12.597 11 / 3
0.12.596 11 / 3
0.12.595 11 / 3
0.12.594 11 / 3
0.12.593 11 / 3
0.12.592 11 / 3
0.12.591 11 / 3
0.12.590 11 / 3
0.12.589 11 / 3
0.12.588 11 / 3
0.12.587 11 / 3
0.12.586 11 / 3
0.12.585 11 / 3
0.12.584 11 / 3
0.12.583 11 / 3
0.12.582 11 / 3
0.12.581 11 / 3
0.12.580 11 / 3
0.12.579 11 / 3
0.12.578 11 / 3
0.12.577 11 / 3
0.12.576 11 / 3
0.12.575 11 / 3
0.12.574 11 / 3
0.12.573 11 / 3

v0.12.624

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.623

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.622

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.621

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.620

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.619

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.618

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.617

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.616

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.615

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.614

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.613

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.612

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.611

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.610

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.609

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.608

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.607

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.606

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.604

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.603

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.602

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.601

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.600

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.599

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.598

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.597

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.596

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.