@tanstack/create
TanStack Application Builder Engine
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | large-new-source-files | AI (source-diff): Consistent with active framework scaffold development, no malicious content found. | ai | |
| provenance | missing-githead | AI (provenance): CI metadata quirk; SLSA attestation still present, no provenance regression. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Added maintainers are known TanStack core contributors. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size increase explained by addition of large generated template manifest file, not injected payload. | ai | |
| source-diff | obfuscated-file:dist/generated/create-manifest.js | AI (source-diff): Generated template manifest with long lines from inlined template strings; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:src/generated/create-manifest.ts | AI (source-diff): Same generated manifest source; header comment confirms machine-generated, content is scaffolding templates. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Used in file-helpers to decode binary template content; benign utility pattern stable for this package. | ai |
Versions (showing 36 of 36)
| Version | Deps | Published |
|---|---|---|
| 0.69.0 | 8 / 8 | |
| 0.68.5 | 8 / 8 | |
| 0.68.4 | 8 / 8 | |
| 0.68.3 | 8 / 8 | |
| 0.68.2 | 8 / 8 | |
| 0.68.1 | 8 / 8 | |
| 0.68.0 | 8 / 8 | |
| 0.67.0 | 8 / 8 | |
| 0.66.0 | 8 / 8 | |
| 0.65.0 | 8 / 8 | |
| 0.64.0 | 8 / 8 | |
| 0.63.9 | 8 / 8 | |
| 0.63.8 | 8 / 8 | |
| 0.63.7 | 8 / 8 | |
| 0.63.6 | 8 / 8 | |
| 0.63.5 | 8 / 8 | |
| 0.63.4 | 8 / 8 | |
| 0.63.3 | 8 / 8 | |
| 0.63.2 | 8 / 8 | |
| 0.63.1 | 8 / 8 | |
| 0.63.0 | 8 / 8 | |
| 0.62.3 | 8 / 8 | |
| 0.62.1 | 8 / 8 | |
| 0.62.0 | 8 / 8 | |
| 0.61.6 | 8 / 8 | |
| 0.61.5 | 8 / 8 | |
| 0.61.4 | 8 / 8 | |
| 0.61.3 | 8 / 8 | |
| 0.61.2 | 8 / 8 | |
| 0.61.1 | 8 / 8 | |
| 0.61.0 | 8 / 8 | |
| 0.60.0 | 8 / 8 | |
| 0.59.4 | 8 / 8 | |
| 0.49.3 | 8 / 8 | |
| 0.49.2 | 8 / 8 | |
| 0.49.1 | 8 / 8 |
v0.69.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.68.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.63.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.63.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.62.3
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.62.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.62.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.61.6
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.61.5
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.61.4
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.61.3
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.61.2
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.61.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.61.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.60.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.59.4
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.49.3
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.49.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.49.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.