← Home

@tanstack/react-start-server

100
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

tannerlinsleytkdodoalemtuzlakkevinvandyschiller-manuel

Keywords

reactlocationrouterroutingasyncasync routertypescript

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:tiny-warning AI (phantom-deps): tiny-warning is a standard utility dependency for this package. ai
phantom-deps phantom-dep:h3 AI (phantom-deps): h3 is a legitimate server framework dependency for this routing package. ai
phantom-deps phantom-dep:jsesc AI (phantom-deps): jsesc is a legitimate utility dependency referenced in config. ai
phantom-deps phantom-dep:unctx AI (phantom-deps): unctx is a legitimate async context utility for this package. ai
provenance publisher-changed AI (provenance): TanStack migrated to GitHub Actions CI/CD publishing with SLSA provenance attestation. This is a legitimate and security-improving transition, not a compromise. ai
maintainer-change maintainer-added AI (maintainer-change): lachlancollins is a known TanStack contributor; maintainer additions in an active OSS org are routine and not a compromise signal. ai
phantom-deps phantom-dep:@tanstack/history AI (phantom-deps): Same-org sibling package from TanStack monorepo; phantom dep pattern is expected in monorepo package structures. ai
phantom-deps phantom-dep:@tanstack/start-client-core AI (phantom-deps): Same-org sibling package from TanStack monorepo; phantom dep pattern is expected in monorepo package structures. ai

Versions (showing 100 of 427)

Version Deps Published
1.157.17 5 / 4
1.157.16 5 / 4
1.157.15 5 / 4
1.157.14 5 / 4
1.157.13 5 / 4
1.157.12 5 / 4
1.157.11 5 / 4
1.157.10 5 / 4
1.157.9 5 / 4
1.157.8 5 / 4
1.157.7 5 / 4
1.157.6 5 / 4
1.157.5 5 / 4
1.157.4 5 / 4
1.157.3 5 / 4
1.157.2 5 / 4
1.157.1 5 / 4
1.157.0 5 / 4
1.156.0 5 / 4
1.155.0 5 / 4
1.154.14 5 / 4
1.154.13 5 / 4
1.154.12 5 / 4
1.154.10 5 / 4
1.154.8 5 / 4
1.154.7 5 / 4
1.154.6 5 / 4
1.154.5 5 / 4
1.154.4 5 / 4
1.154.3 5 / 4
1.154.2 5 / 4
1.154.1 5 / 4
1.153.2 5 / 4
1.153.1 5 / 4
1.153.0 5 / 4
1.152.0 5 / 4
1.151.6 5 / 4
1.151.3 5 / 4
1.151.2 5 / 4
1.151.1 5 / 4
1.151.0 5 / 4
1.150.0 5 / 4
1.149.3 5 / 4
1.149.1 5 / 4
1.148.0 5 / 4
1.147.3 5 / 4
1.147.2 5 / 4
1.147.1 5 / 4
1.147.0 5 / 4
1.146.2 5 / 4
1.146.1 5 / 4
1.146.0 5 / 4
1.145.11 5 / 4
1.145.7 5 / 4
1.145.6 5 / 4
1.145.5 5 / 4
1.145.3 5 / 4
1.145.0 5 / 4
1.144.0 5 / 4
1.143.12 5 / 4
1.143.11 5 / 4
1.143.9 5 / 4
1.143.8 5 / 4
1.143.6 5 / 4
1.143.5 5 / 4
1.143.4 5 / 4
1.143.3 5 / 4
1.143.2 5 / 4
1.142.13 5 / 4
1.142.11 5 / 4
1.142.8 5 / 4
1.142.7 5 / 4
1.142.6 5 / 4
1.142.4 5 / 4
1.142.3 5 / 4
1.142.1 5 / 4
1.141.8 5 / 4
1.141.6 5 / 4
1.141.4 5 / 4
1.141.2 5 / 4
1.141.1 5 / 4
1.141.0 5 / 4
1.140.5 5 / 4
1.140.4 5 / 4
1.140.3 5 / 4
1.140.2 5 / 4
1.140.1 5 / 4
1.140.0 5 / 4
1.139.14 5 / 4
1.139.13 5 / 4
1.139.12 5 / 4
1.139.11 5 / 4
1.139.10 5 / 4
1.139.9 5 / 4
1.139.8 5 / 4
1.139.7 5 / 4
1.139.6 5 / 4
1.139.5 5 / 4
1.139.4 5 / 4
1.139.3 5 / 4
Showing 100 of 427 Next page →

v1.151.3

2 findings
HIGH Publisher changed: tannerlinsley → GitHub Actions (on 2026-01-18) provenance

This version was published by a different npm account than previous versions on 2026-01-18. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.145.5

2 findings
HIGH Publisher changed: tannerlinsley → GitHub Actions (on 2026-01-04) provenance

This version was published by a different npm account than previous versions on 2026-01-04. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.141.1

2 findings
HIGH Publisher changed: tannerlinsley → GitHub Actions (on 2025-12-11) provenance

This version was published by a different npm account than previous versions on 2025-12-11. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.