@tanstack/react-router-devtools
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): TanStack migrated to GitHub Actions publishing with SLSA attestation; this is the expected new publisher for all future versions. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Package was dormant due to org-level CI migration, not account takeover; SLSA attestation confirms legitimate publish. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): lachlancollins is a known TanStack contributor; addition aligns with org-level maintainer expansion. | ai | |
| dependencies | unvetted-dep:@tanstack/router-devtools-core | AI (dependencies): Sibling package in the TanStack/router monorepo; expected dependency for this devtools package. | ai |
Versions (showing 18 of 318)
| Version | Deps | Published |
|---|---|---|
| 1.120.18 | 2 / 3 | |
| 1.120.17 | 2 / 3 | |
| 1.120.16 | 2 / 3 | |
| 1.120.15 | 2 / 3 | |
| 1.120.13 | 2 / 3 | |
| 1.120.12 | 2 / 3 | |
| 1.120.11 | 2 / 3 | |
| 1.120.10 | 2 / 3 | |
| 1.120.9 | 2 / 3 | |
| 1.120.8 | 2 / 3 | |
| 1.120.7 | 2 / 3 | |
| 1.120.6 | 2 / 3 | |
| 1.120.5 | 2 / 3 | |
| 1.120.4 | 2 / 3 | |
| 1.120.3 | 2 / 3 | |
| 1.120.2 | 2 / 3 | |
| 1.120.1 | 2 / 3 | |
| 1.120.0 | 2 / 3 |
v1.120.18
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.120.17
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.120.16
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.120.15
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.120.13
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.120.12
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.120.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.120.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.120.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.120.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.120.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.120.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.120.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.120.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.120.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.120.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.120.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.120.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.