@tanstack/react-start-server
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:tiny-warning | AI (phantom-deps): tiny-warning is a standard utility dependency for this package. | ai | |
| phantom-deps | phantom-dep:h3 | AI (phantom-deps): h3 is a legitimate server framework dependency for this routing package. | ai | |
| phantom-deps | phantom-dep:jsesc | AI (phantom-deps): jsesc is a legitimate utility dependency referenced in config. | ai | |
| phantom-deps | phantom-dep:unctx | AI (phantom-deps): unctx is a legitimate async context utility for this package. | ai | |
| provenance | publisher-changed | AI (provenance): TanStack migrated to GitHub Actions CI/CD publishing with SLSA provenance attestation. This is a legitimate and security-improving transition, not a compromise. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): lachlancollins is a known TanStack contributor; maintainer additions in an active OSS org are routine and not a compromise signal. | ai | |
| phantom-deps | phantom-dep:@tanstack/history | AI (phantom-deps): Same-org sibling package from TanStack monorepo; phantom dep pattern is expected in monorepo package structures. | ai | |
| phantom-deps | phantom-dep:@tanstack/start-client-core | AI (phantom-deps): Same-org sibling package from TanStack monorepo; phantom dep pattern is expected in monorepo package structures. | ai |
Versions (showing 100 of 427)
| Version | Deps | Published |
|---|---|---|
| 1.157.17 | 5 / 4 | |
| 1.157.16 | 5 / 4 | |
| 1.157.15 | 5 / 4 | |
| 1.157.14 | 5 / 4 | |
| 1.157.13 | 5 / 4 | |
| 1.157.12 | 5 / 4 | |
| 1.157.11 | 5 / 4 | |
| 1.157.10 | 5 / 4 | |
| 1.157.9 | 5 / 4 | |
| 1.157.8 | 5 / 4 | |
| 1.157.7 | 5 / 4 | |
| 1.157.6 | 5 / 4 | |
| 1.157.5 | 5 / 4 | |
| 1.157.4 | 5 / 4 | |
| 1.157.3 | 5 / 4 | |
| 1.157.2 | 5 / 4 | |
| 1.157.1 | 5 / 4 | |
| 1.157.0 | 5 / 4 | |
| 1.156.0 | 5 / 4 | |
| 1.155.0 | 5 / 4 | |
| 1.154.14 | 5 / 4 | |
| 1.154.13 | 5 / 4 | |
| 1.154.12 | 5 / 4 | |
| 1.154.10 | 5 / 4 | |
| 1.154.8 | 5 / 4 | |
| 1.154.7 | 5 / 4 | |
| 1.154.6 | 5 / 4 | |
| 1.154.5 | 5 / 4 | |
| 1.154.4 | 5 / 4 | |
| 1.154.3 | 5 / 4 | |
| 1.154.2 | 5 / 4 | |
| 1.154.1 | 5 / 4 | |
| 1.153.2 | 5 / 4 | |
| 1.153.1 | 5 / 4 | |
| 1.153.0 | 5 / 4 | |
| 1.152.0 | 5 / 4 | |
| 1.151.6 | 5 / 4 | |
| 1.151.3 | 5 / 4 | |
| 1.151.2 | 5 / 4 | |
| 1.151.1 | 5 / 4 | |
| 1.151.0 | 5 / 4 | |
| 1.150.0 | 5 / 4 | |
| 1.149.3 | 5 / 4 | |
| 1.149.1 | 5 / 4 | |
| 1.148.0 | 5 / 4 | |
| 1.147.3 | 5 / 4 | |
| 1.147.2 | 5 / 4 | |
| 1.147.1 | 5 / 4 | |
| 1.147.0 | 5 / 4 | |
| 1.146.2 | 5 / 4 | |
| 1.146.1 | 5 / 4 | |
| 1.146.0 | 5 / 4 | |
| 1.145.11 | 5 / 4 | |
| 1.145.7 | 5 / 4 | |
| 1.145.6 | 5 / 4 | |
| 1.145.5 | 5 / 4 | |
| 1.145.3 | 5 / 4 | |
| 1.145.0 | 5 / 4 | |
| 1.144.0 | 5 / 4 | |
| 1.143.12 | 5 / 4 | |
| 1.143.11 | 5 / 4 | |
| 1.143.9 | 5 / 4 | |
| 1.143.8 | 5 / 4 | |
| 1.143.6 | 5 / 4 | |
| 1.143.5 | 5 / 4 | |
| 1.143.4 | 5 / 4 | |
| 1.143.3 | 5 / 4 | |
| 1.143.2 | 5 / 4 | |
| 1.142.13 | 5 / 4 | |
| 1.142.11 | 5 / 4 | |
| 1.142.8 | 5 / 4 | |
| 1.142.7 | 5 / 4 | |
| 1.142.6 | 5 / 4 | |
| 1.142.4 | 5 / 4 | |
| 1.142.3 | 5 / 4 | |
| 1.142.1 | 5 / 4 | |
| 1.141.8 | 5 / 4 | |
| 1.141.6 | 5 / 4 | |
| 1.141.4 | 5 / 4 | |
| 1.141.2 | 5 / 4 | |
| 1.141.1 | 5 / 4 | |
| 1.141.0 | 5 / 4 | |
| 1.140.5 | 5 / 4 | |
| 1.140.4 | 5 / 4 | |
| 1.140.3 | 5 / 4 | |
| 1.140.2 | 5 / 4 | |
| 1.140.1 | 5 / 4 | |
| 1.140.0 | 5 / 4 | |
| 1.139.14 | 5 / 4 | |
| 1.139.13 | 5 / 4 | |
| 1.139.12 | 5 / 4 | |
| 1.139.11 | 5 / 4 | |
| 1.139.10 | 5 / 4 | |
| 1.139.9 | 5 / 4 | |
| 1.139.8 | 5 / 4 | |
| 1.139.7 | 5 / 4 | |
| 1.139.6 | 5 / 4 | |
| 1.139.5 | 5 / 4 | |
| 1.139.4 | 5 / 4 | |
| 1.139.3 | 5 / 4 |
v1.151.3
2 findingsThis version was published by a different npm account than previous versions on 2026-01-18. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.145.5
2 findingsThis version was published by a different npm account than previous versions on 2026-01-04. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.141.1
2 findingsThis version was published by a different npm account than previous versions on 2025-12-11. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.