← Home

@powerlines/plugin-unbuild

A package containing a Powerlines plugin to build projects using Unbuild.

100
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

stormie-botsullivanpj

Keywords

unbuildpowerlinesstorm-softwarepowerlines-plugin

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): stormie-bot is the Storm Software CI bot with 2775 approved packages; transition from GitHub Actions is expected automation account usage. ai
phantom-deps phantom-dep:@stryke/helpers AI (phantom-deps): Sibling org package used in config files; stable false positive for this package. ai
phantom-deps phantom-dep:@powerlines/unplugin AI (phantom-deps): Same-org dependency; phantom detection is a false positive for this build-tool wrapper pattern. ai
dependencies unvetted-dep:@storm-software/unbuild AI (dependencies): @storm-software/unbuild is a first-party Storm Software dependency consistent with this package's purpose as a build plugin wrapper. Stable false positive for this package. ai
phantom-deps phantom-dep:powerlines AI (phantom-deps): Build plugin pattern; deps referenced in config files passed to consumers rather than directly imported. Stable false positive for this package. ai
phantom-deps phantom-dep:@stryke/types AI (phantom-deps): Build plugin pattern; deps referenced in config files passed to consumers rather than directly imported. Stable false positive for this package. ai
phantom-deps phantom-dep:@stryke/type-checks AI (phantom-deps): Build plugin pattern; deps referenced in config files passed to consumers rather than directly imported. Stable false positive for this package. ai
phantom-deps phantom-dep:@storm-software/unbuild AI (phantom-deps): Intra-org dependency from same Storm Software organization; referenced in config files. Stable false positive for this package. ai
phantom-deps phantom-dep:@stryke/path AI (phantom-deps): Build plugin pattern; deps referenced in config files passed to consumers rather than directly imported. Stable false positive for this package. ai
phantom-deps phantom-dep:defu AI (phantom-deps): Build plugin pattern; deps referenced in config files passed to consumers rather than directly imported. Stable false positive for this package. ai
phantom-deps phantom-dep:jiti AI (phantom-deps): Build plugin pattern; deps referenced in config files passed to consumers rather than directly imported. Stable false positive for this package. ai
phantom-deps phantom-dep:@stryke/fs AI (phantom-deps): Build plugin pattern; deps referenced in config files passed to consumers rather than directly imported. Stable false positive for this package. ai
dependencies unvetted-dep:@powerlines/plugin-rollup AI (dependencies): Sibling package within the same Storm Software/powerlines monorepo; published via the same CI/CD pipeline with SLSA provenance. Not an independent supply chain risk. ai
dependencies unvetted-dep:@powerlines/core AI (dependencies): Sibling package within the same Storm Software/powerlines monorepo; published via the same CI/CD pipeline with SLSA provenance. Not an independent supply chain risk. ai
phantom-deps phantom-dep:unplugin AI (phantom-deps): unplugin is a declared runtime dep used in the plugin architecture; phantom detection is a false positive for this package's plugin pattern. ai

Versions (showing 100 of 579)

Version Deps Published
0.5.471 9 / 2
0.5.470 9 / 2
0.5.469 9 / 2
0.5.468 9 / 2
0.5.467 9 / 2
0.5.466 9 / 2
0.5.465 9 / 2
0.5.464 9 / 2
0.5.461 8 / 2
0.5.460 8 / 2
0.5.459 8 / 2
0.5.458 8 / 2
0.5.457 8 / 2
0.5.455 8 / 2
0.5.454 8 / 2
0.5.453 8 / 2
0.5.452 8 / 2
0.5.451 8 / 2
0.5.450 8 / 2
0.5.449 8 / 2
0.5.448 8 / 2
0.5.447 8 / 2
0.5.446 8 / 2
0.5.445 8 / 2
0.5.444 8 / 2
0.5.443 7 / 2
0.5.442 7 / 2
0.5.441 7 / 2
0.5.440 7 / 2
0.5.439 7 / 2
0.5.438 7 / 2
0.5.437 7 / 2
0.5.436 7 / 2
0.5.435 7 / 2
0.5.434 7 / 2
0.5.433 7 / 2
0.5.432 7 / 2
0.5.431 7 / 2
0.5.430 7 / 2
0.5.429 7 / 2
0.5.428 7 / 2
0.5.427 7 / 2
0.5.426 7 / 2
0.5.425 7 / 2
0.5.424 7 / 2
0.5.423 7 / 2
0.5.422 7 / 2
0.5.421 7 / 2
0.5.420 7 / 2
0.5.419 7 / 2
0.5.418 7 / 2
0.5.417 7 / 2
0.5.416 7 / 2
0.5.415 7 / 2
0.5.414 7 / 2
0.5.413 7 / 2
0.5.412 7 / 2
0.5.411 7 / 2
0.5.410 7 / 2
0.5.409 7 / 2
0.5.408 7 / 2
0.5.407 7 / 2
0.5.406 7 / 2
0.5.405 7 / 2
0.5.404 7 / 2
0.5.402 7 / 2
0.5.401 7 / 2
0.5.400 7 / 2
0.5.399 7 / 2
0.5.398 7 / 2
0.5.397 7 / 2
0.5.396 7 / 2
0.5.395 7 / 2
0.5.394 7 / 2
0.5.393 7 / 2
0.5.392 7 / 2
0.5.391 7 / 2
0.5.390 7 / 2
0.5.389 7 / 2
0.5.388 7 / 2
0.5.387 7 / 2
0.5.386 7 / 2
0.5.385 7 / 2
0.5.384 7 / 2
0.5.383 7 / 2
0.5.382 7 / 2
0.5.381 7 / 2
0.5.380 7 / 2
0.5.379 7 / 2
0.5.378 7 / 2
0.5.377 7 / 2
0.5.376 7 / 2
0.5.375 7 / 2
0.5.374 7 / 2
0.5.373 7 / 2
0.5.372 7 / 2
0.5.371 7 / 2
0.5.370 7 / 2
0.5.369 7 / 2
0.5.368 7 / 2
Showing 100 of 579 Next page →

v0.5.471

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.470

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.469

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.468

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.467

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.466

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.465

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.464

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.461

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.460

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.459

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.458

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.457

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.455

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.454

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.453

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.452

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.451

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.450

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.449

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.448

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.447

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.446

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.445

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.375

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.374

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.373

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.371

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.370

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.368

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.