← Home

@tanstack/react-start

100
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

tannerlinsleytkdodoalemtuzlakkevinvandyschiller-manuel

Keywords

reactlocationrouterroutingasyncasync routertypescript

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@tanstack/react-start-plugin AI (dependencies): First-party sibling package from TanStack monorepo; pinned to same release version. ai
dependencies unvetted-dep:@tanstack/start-server-functions-handler AI (dependencies): First-party TanStack monorepo sub-package; stable pattern across releases. ai
dependencies unvetted-dep:@tanstack/react-start-router-manifest AI (dependencies): First-party TanStack monorepo sub-package; stable pattern across releases. ai
dependencies unvetted-dep:@tanstack/start-server-functions-client AI (dependencies): First-party TanStack monorepo sub-package; stable pattern across releases. ai
dependencies unvetted-dep:@tanstack/start-server-functions-server AI (dependencies): First-party TanStack monorepo sub-package; stable pattern across releases. ai
dependencies unvetted-dep:@tanstack/start-api-routes AI (dependencies): First-party TanStack monorepo sub-package; stable pattern across releases. ai
dependencies unvetted-dep:@tanstack/react-start-config AI (dependencies): First-party TanStack monorepo sub-package; stable pattern across releases. ai
dependencies unvetted-dep:@tanstack/start-server-functions-ssr AI (dependencies): First-party TanStack monorepo sub-package; stable pattern across releases. ai
maintainer-change maintainer-added AI (maintainer-change): lachlancollins is a known TanStack collaborator; adding maintainers to a mature project is expected. ai
provenance publisher-changed AI (provenance): Transition from manual (tannerlinsley) to CI/CD (GitHub Actions) publishing with SLSA provenance. This is a security improvement, not a risk. ai
phantom-deps phantom-dep:@tanstack/router-utils AI (phantom-deps): Same-org sibling package from TanStack monorepo; phantom dep status is a packaging detail, not a security concern for this well-attested package. ai

Versions (showing 100 of 438)

Version Deps Published
1.136.4 8 / 0
1.136.3 8 / 0
1.136.2 8 / 0
1.136.1 8 / 0
1.136.0 8 / 0
1.135.2 8 / 0
1.135.1 8 / 0
1.135.0 8 / 0
1.134.20 8 / 0
1.134.18 8 / 0
1.134.17 8 / 0
1.134.15 8 / 0
1.134.14 8 / 0
1.134.13 8 / 0
1.134.12 8 / 0
1.134.10 8 / 0
1.134.9 8 / 0
1.134.7 8 / 0
1.134.6 8 / 0
1.134.5 8 / 0
1.134.4 8 / 0
1.134.3 8 / 0
1.134.2 8 / 0
1.134.0 8 / 0
1.133.37 8 / 0
1.133.36 8 / 0
1.133.35 8 / 0
1.133.34 8 / 0
1.133.32 8 / 0
1.133.31 8 / 0
1.133.29 8 / 0
1.133.28 8 / 0
1.133.27 8 / 0
1.133.26 8 / 0
1.133.25 8 / 0
1.133.22 8 / 0
1.133.21 8 / 0
1.133.20 8 / 0
1.133.19 8 / 0
1.133.18 8 / 0
1.133.15 8 / 0
1.133.14 8 / 0
1.133.13 8 / 0
1.133.12 8 / 0
1.133.11 8 / 0
1.133.10 8 / 0
1.133.9 8 / 0
1.133.8 8 / 0
1.133.7 8 / 0
1.133.6 8 / 0
1.133.5 8 / 0
1.133.4 8 / 0
1.133.3 8 / 0
1.133.2 8 / 0
1.132.56 8 / 0
1.132.55 8 / 0
1.132.54 8 / 0
1.132.53 8 / 0
1.132.52 8 / 0
1.132.51 8 / 0
1.132.48 8 / 0
1.132.47 8 / 0
1.132.45 8 / 0
1.132.43 8 / 0
1.132.42 8 / 0
1.132.41 8 / 0
1.132.40 8 / 0
1.132.38 8 / 0
1.132.37 8 / 0
1.132.36 8 / 0
1.132.35 8 / 0
1.132.34 8 / 0
1.132.33 8 / 0
1.132.32 8 / 0
1.132.31 8 / 0
1.132.29 8 / 0
1.132.28 8 / 0
1.132.27 8 / 0
1.132.26 8 / 0
1.132.25 8 / 0
1.132.24 8 / 0
1.132.23 8 / 0
1.132.22 8 / 0
1.132.21 8 / 0
1.132.19 8 / 0
1.132.18 8 / 0
1.132.17 8 / 0
1.132.16 8 / 0
1.132.15 8 / 0
1.132.14 8 / 0
1.132.13 8 / 0
1.132.12 7 / 0
1.132.11 7 / 0
1.132.10 7 / 0
1.132.9 7 / 0
1.132.8 7 / 0
1.132.7 7 / 0
1.132.6 7 / 0
1.132.4 7 / 0
1.132.3 7 / 0
Showing 100 of 438 Next page →

v1.136.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.135.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.135.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.133.20

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.133.13

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.133.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.132.53

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.132.41

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.132.31

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.132.18

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.132.13

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.132.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.