← Home

@tanstack/solid-query

Primitives for managing, caching and syncing asynchronous and remote data in Solid

7
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

tannerlinsleyalemtuzlakkevinvandy

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): TanStack/query uses GitHub Actions for automated releases; CI publisher is expected and backed by SLSA attestation. ai
source-diff obfuscated-file:build/umd/index.production.js AI (source-diff): Standard minified UMD bundle; consistent with TanStack/query build output across all versions. ai
publish-pattern dormant-publish AI (publish-pattern): v4 maintenance release alongside active v5; long gap expected for older major version. ai
semgrep semgrep:api-obfuscation-reflect AI (semgrep): Reflect.get() used in a Proxy handler for transparent property forwarding — idiomatic JS, not obfuscation. ai

Versions (showing 7 of 307)

Version Deps Published
5.2.1 2 / 2
5.2.0 2 / 2
5.0.5 2 / 2
5.0.0 2 / 2
4.44.0 1 / 1
4.43.0 1 / 1
4.41.1 1 / 1

v5.2.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.0.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.