@tanstack/router-utils
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Legitimate transition from personal npm credentials to GitHub Actions CI/CD publishing, confirmed by SLSA provenance attestation. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Known TanStack contributors added as maintainers; normal for a growing open-source project. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Sub-package in a monorepo; publish gaps are normal when the utility package doesn't change every release cycle. | ai | |
| phantom-deps | phantom-dep:@babel/core | AI (phantom-deps): @babel/core is a declared direct dependency in package.json; the phantom-dep finding is a false positive for this framework-scoped package loaded by convention. | ai |
Versions (showing 41 of 41)
| Version | Deps | Published |
|---|---|---|
| 1.162.2 | 8 / 3 | |
| 1.162.1 | 9 / 5 | |
| 1.162.0 | 9 / 5 | |
| 1.161.8 | 9 / 5 | |
| 1.161.7 | 9 / 5 | |
| 1.161.6 | 9 / 4 | |
| 1.161.5 | 9 / 4 | |
| 1.161.4 | 9 / 4 | |
| 1.158.0 | 9 / 3 | |
| 1.154.7 | 7 / 4 | |
| 1.143.11 | 7 / 4 | |
| 1.141.0 | 8 / 4 | |
| 1.140.0 | 8 / 4 | |
| 1.139.0 | 8 / 4 | |
| 1.133.19 | 8 / 4 | |
| 1.133.3 | 8 / 4 | |
| 1.132.51 | 8 / 4 | |
| 1.132.31 | 8 / 4 | |
| 1.132.21 | 8 / 4 | |
| 1.132.0 | 8 / 4 | |
| 1.131.2 | 6 / 4 | |
| 1.130.12 | 6 / 4 | |
| 1.129.7 | 6 / 4 | |
| 1.121.21 | 6 / 4 | |
| 1.121.20 | 6 / 4 | |
| 1.121.19 | 6 / 4 | |
| 1.121.18 | 6 / 4 | |
| 1.121.0 | 6 / 4 | |
| 1.120.17 | 4 / 3 | |
| 1.115.0 | 4 / 3 | |
| 1.114.29 | 4 / 3 | |
| 1.114.12 | 4 / 3 | |
| 1.114.6 | 4 / 3 | |
| 1.114.3 | 4 / 3 | |
| 1.114.1 | 4 / 3 | |
| 1.112.18 | 4 / 3 | |
| 1.102.2 | 4 / 3 | |
| 1.99.5 | 4 / 3 | |
| 1.99.3 | 4 / 3 | |
| 1.99.0 | 4 / 3 | |
| 1.98.5 | 4 / 3 |
v1.115.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.114.29
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.114.12
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.114.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.114.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.114.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.112.18
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.102.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.99.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.99.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.99.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.98.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.