@powerlines/plugin-untyped
A Powerlines plugin to use Untyped for code generation based on user-defined schemas.
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@stryke/convert | AI (phantom-deps): @stryke/convert is a declared runtime dependency; phantom detection is a false positive for this plugin package where deps may be used indirectly. | ai | |
| provenance | publisher-changed | AI (provenance): Publisher changed from stormie-bot to GitHub Actions as part of a CI/CD automation migration, confirmed by SLSA provenance attestation. This is a legitimate and positive supply chain improvement. | ai | |
| phantom-deps | phantom-dep:@stryke/helpers | AI (phantom-deps): Declared dependency referenced in config; part of @stryke utility suite. | ai | |
| phantom-deps | phantom-dep:@stryke/type-checks | AI (phantom-deps): Declared dependency referenced in config; part of @stryke utility suite. | ai | |
| phantom-deps | phantom-dep:powerlines | AI (phantom-deps): Declared dependency; core framework for this plugin package. | ai | |
| phantom-deps | phantom-dep:@stryke/path | AI (phantom-deps): Declared dependency referenced in config; part of @stryke utility suite. | ai | |
| phantom-deps | phantom-dep:defu | AI (phantom-deps): Declared dependency used in plugin configuration; typical for config-driven packages. | ai | |
| phantom-deps | phantom-dep:@stryke/fs | AI (phantom-deps): Declared dependency referenced in config; part of @stryke utility suite used by plugin. | ai | |
| dependencies | unvetted-dep:powerlines | AI (dependencies): powerlines is the core package of this publisher's own ecosystem; @powerlines/plugin-untyped is explicitly a plugin for it. Dependency is expected and coherent. | ai | |
| dependencies | unvetted-dep:@stryke/convert | AI (dependencies): @stryke/convert is part of the same Storm Software organization's tooling suite, consistent with the publisher's ecosystem. | ai | |
| dependencies | unvetted-dep:@storm-software/untyped | AI (dependencies): @storm-software/untyped is the underlying untyped integration from the same publisher; this plugin wraps it, making the dependency structurally expected. | ai | |
| provenance | slsa-provenance | AI (provenance): Package is consistently published via CI/CD with Sigstore/SLSA attestation; this is a stable property of the Storm Software publishing pipeline. | ai |
Versions (showing 51 of 602)
| Version | Deps | Published |
|---|---|---|
| 0.2.578 | 4 / 2 | |
| 0.2.577 | 4 / 2 | |
| 0.2.576 | 4 / 2 | |
| 0.2.575 | 4 / 2 | |
| 0.2.574 | 4 / 2 | |
| 0.2.573 | 4 / 2 | |
| 0.2.572 | 4 / 2 | |
| 0.2.571 | 4 / 2 | |
| 0.2.570 | 4 / 2 | |
| 0.2.569 | 4 / 2 | |
| 0.2.568 | 4 / 2 | |
| 0.2.567 | 4 / 2 | |
| 0.2.566 | 4 / 2 | |
| 0.2.565 | 4 / 2 | |
| 0.2.564 | 4 / 2 | |
| 0.2.562 | 4 / 2 | |
| 0.2.561 | 4 / 2 | |
| 0.2.560 | 4 / 2 | |
| 0.2.559 | 4 / 2 | |
| 0.2.558 | 4 / 2 | |
| 0.2.557 | 4 / 2 | |
| 0.2.556 | 4 / 2 | |
| 0.2.555 | 4 / 2 | |
| 0.2.554 | 4 / 2 | |
| 0.2.553 | 4 / 2 | |
| 0.2.552 | 4 / 2 | |
| 0.2.551 | 4 / 2 | |
| 0.2.550 | 4 / 2 | |
| 0.2.549 | 4 / 2 | |
| 0.2.548 | 4 / 2 | |
| 0.2.547 | 4 / 2 | |
| 0.2.546 | 4 / 2 | |
| 0.2.545 | 4 / 2 | |
| 0.2.544 | 4 / 2 | |
| 0.2.543 | 4 / 2 | |
| 0.2.542 | 4 / 2 | |
| 0.2.541 | 4 / 2 | |
| 0.2.540 | 4 / 2 | |
| 0.2.539 | 4 / 2 | |
| 0.2.538 | 4 / 2 | |
| 0.2.537 | 4 / 2 | |
| 0.2.536 | 4 / 2 | |
| 0.2.535 | 4 / 2 | |
| 0.2.534 | 4 / 2 | |
| 0.2.533 | 4 / 2 | |
| 0.2.532 | 4 / 2 | |
| 0.2.531 | 4 / 2 | |
| 0.2.530 | 4 / 2 | |
| 0.2.529 | 4 / 2 | |
| 0.2.528 | 4 / 2 | |
| 0.2.527 | 4 / 2 |
v0.2.578
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.577
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.576
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.575
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.574
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.573
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.572
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.571
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.570
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.569
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.568
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.567
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.566
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.565
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.564
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.562
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.561
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.560
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.559
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.558
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.557
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.556
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.555
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.554
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.