@tanstack/router-vite-plugin
Modern and scalable routing for React applications
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@types/babel__traverse | AI (phantom-deps): Type definitions for Babel; loaded by convention in this package. | ai | |
| phantom-deps | phantom-dep:@types/babel__template | AI (phantom-deps): Type definitions for Babel; loaded by convention in this package. | ai | |
| phantom-deps | phantom-dep:@types/babel__generator | AI (phantom-deps): Type definitions for Babel; loaded by convention in this package. | ai | |
| phantom-deps | phantom-dep:@types/babel__core | AI (phantom-deps): Type definitions for Babel; loaded by convention in this package. | ai | |
| vendored-integrity | unresolved-vendored-tree:build/cjs/node_modules/.pnpm/[email protected]/node_modules/prettier | AI (vendored-integrity): Nested prettier copy from pnpm install structure, expected in build output. | ai | |
| phantom-deps | phantom-dep:@vitejs/plugin-react | AI (phantom-deps): Vite plugin referenced in config; stable for this package. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-transform-typescript | AI (phantom-deps): Babel plugin loaded by convention in Vite plugin; stable pattern. | ai | |
| phantom-deps | phantom-dep:@babel/generator | AI (phantom-deps): Babel plugin loaded by convention in Vite plugin; stable pattern. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-syntax-jsx | AI (phantom-deps): Babel plugin loaded by convention in Vite plugin; stable pattern. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-syntax-typescript | AI (phantom-deps): Babel plugin loaded by convention in Vite plugin; stable pattern. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-transform-react-jsx | AI (phantom-deps): Babel plugin loaded by convention in Vite plugin; stable pattern. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Cosmetic; established package with clear repo/homepage. | ai | |
| vendored-integrity | unresolved-vendored-tree:build/cjs/node_modules/.pnpm | AI (vendored-integrity): Stray pnpm store leakage of known deps (prettier, graceful-fs, fs-extra), not an unidentified implant. | ai | |
| provenance | publisher-changed | AI (provenance): Transition from manual (tannerlinsley) to CI/CD (GitHub Actions) publishing with SLSA provenance from TanStack/router repo. Legitimate and expected. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): lachlancollins is a known TanStack contributor; adding maintainers to a mature actively-developed project is normal. | ai |
Versions (showing 100 of 725)
v1.167.23
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.167.22
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.167.21
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.167.20
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.167.19
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.