@powerlines/plugin-unbuild
A package containing a Powerlines plugin to build projects using Unbuild.
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): stormie-bot is the Storm Software CI bot with 2775 approved packages; transition from GitHub Actions is expected automation account usage. | ai | |
| phantom-deps | phantom-dep:@stryke/helpers | AI (phantom-deps): Sibling org package used in config files; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@powerlines/unplugin | AI (phantom-deps): Same-org dependency; phantom detection is a false positive for this build-tool wrapper pattern. | ai | |
| dependencies | unvetted-dep:@storm-software/unbuild | AI (dependencies): @storm-software/unbuild is a first-party Storm Software dependency consistent with this package's purpose as a build plugin wrapper. Stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:powerlines | AI (phantom-deps): Build plugin pattern; deps referenced in config files passed to consumers rather than directly imported. Stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@stryke/types | AI (phantom-deps): Build plugin pattern; deps referenced in config files passed to consumers rather than directly imported. Stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@stryke/type-checks | AI (phantom-deps): Build plugin pattern; deps referenced in config files passed to consumers rather than directly imported. Stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@storm-software/unbuild | AI (phantom-deps): Intra-org dependency from same Storm Software organization; referenced in config files. Stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@stryke/path | AI (phantom-deps): Build plugin pattern; deps referenced in config files passed to consumers rather than directly imported. Stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:defu | AI (phantom-deps): Build plugin pattern; deps referenced in config files passed to consumers rather than directly imported. Stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:jiti | AI (phantom-deps): Build plugin pattern; deps referenced in config files passed to consumers rather than directly imported. Stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@stryke/fs | AI (phantom-deps): Build plugin pattern; deps referenced in config files passed to consumers rather than directly imported. Stable false positive for this package. | ai | |
| dependencies | unvetted-dep:@powerlines/plugin-rollup | AI (dependencies): Sibling package within the same Storm Software/powerlines monorepo; published via the same CI/CD pipeline with SLSA provenance. Not an independent supply chain risk. | ai | |
| dependencies | unvetted-dep:@powerlines/core | AI (dependencies): Sibling package within the same Storm Software/powerlines monorepo; published via the same CI/CD pipeline with SLSA provenance. Not an independent supply chain risk. | ai | |
| phantom-deps | phantom-dep:unplugin | AI (phantom-deps): unplugin is a declared runtime dep used in the plugin architecture; phantom detection is a false positive for this package's plugin pattern. | ai |
Versions (showing 51 of 602)
| Version | Deps | Published |
|---|---|---|
| 0.5.618 | 9 / 2 | |
| 0.5.617 | 9 / 2 | |
| 0.5.616 | 9 / 2 | |
| 0.5.615 | 9 / 2 | |
| 0.5.614 | 9 / 2 | |
| 0.5.613 | 9 / 2 | |
| 0.5.612 | 9 / 2 | |
| 0.5.611 | 9 / 2 | |
| 0.5.610 | 9 / 2 | |
| 0.5.609 | 9 / 2 | |
| 0.5.608 | 9 / 2 | |
| 0.5.607 | 9 / 2 | |
| 0.5.606 | 9 / 2 | |
| 0.5.605 | 9 / 2 | |
| 0.5.603 | 9 / 2 | |
| 0.5.602 | 9 / 2 | |
| 0.5.601 | 9 / 2 | |
| 0.5.600 | 9 / 2 | |
| 0.5.599 | 9 / 2 | |
| 0.5.598 | 9 / 2 | |
| 0.5.597 | 9 / 2 | |
| 0.5.596 | 9 / 2 | |
| 0.5.595 | 9 / 2 | |
| 0.5.594 | 9 / 2 | |
| 0.5.593 | 9 / 2 | |
| 0.5.592 | 9 / 2 | |
| 0.5.591 | 9 / 2 | |
| 0.5.590 | 9 / 2 | |
| 0.5.589 | 9 / 2 | |
| 0.5.588 | 9 / 2 | |
| 0.5.587 | 9 / 2 | |
| 0.5.586 | 9 / 2 | |
| 0.5.585 | 9 / 2 | |
| 0.5.584 | 9 / 2 | |
| 0.5.583 | 9 / 2 | |
| 0.5.582 | 9 / 2 | |
| 0.5.581 | 9 / 2 | |
| 0.5.580 | 9 / 2 | |
| 0.5.579 | 9 / 2 | |
| 0.5.578 | 9 / 2 | |
| 0.5.577 | 9 / 2 | |
| 0.5.576 | 9 / 2 | |
| 0.5.575 | 9 / 2 | |
| 0.5.574 | 9 / 2 | |
| 0.5.573 | 9 / 2 | |
| 0.5.572 | 9 / 2 | |
| 0.5.571 | 9 / 2 | |
| 0.5.570 | 9 / 2 | |
| 0.5.569 | 9 / 2 | |
| 0.5.568 | 9 / 2 | |
| 0.5.567 | 9 / 2 |
v0.5.618
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.617
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.616
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.615
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.614
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.613
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.612
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.611
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.610
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.609
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.608
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.607
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.606
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.605
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.603
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.602
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.601
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.600
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.599
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.598
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.597
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.596
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.595
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.