@tanstack/solid-start-client
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:vinxi | AI (phantom-deps): vinxi is a declared dependency used in config/build context; phantom-dep heuristic is a false positive here. | ai | |
| phantom-deps | phantom-dep:jsesc | AI (phantom-deps): Build-time dep referenced in config; not a runtime import concern for this package. | ai | |
| phantom-deps | phantom-dep:cookie-es | AI (phantom-deps): Declared dependency used in config context; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:tiny-invariant | AI (phantom-deps): tiny-invariant is a declared runtime dependency used via build output; phantom-dep finding is a false positive for this package's build structure. | ai | |
| phantom-deps | phantom-dep:tiny-warning | AI (phantom-deps): tiny-warning is a declared runtime dependency used via build output; phantom-dep finding is a false positive for this package's build structure. | ai | |
| provenance | publisher-changed | AI (provenance): TanStack migrated to GitHub Actions CI/CD publishing with SLSA provenance attestation — this is a legitimate and security-improving automation transition, not a compromise. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): lachlancollins is a known TanStack contributor; addition is consistent with legitimate team growth in this active open-source project. | ai | |
| dependencies | unvetted-dep:@tanstack/router-core | AI (dependencies): First-party TanStack monorepo dependency; part of the same release train as this package. Not a third-party risk. | ai | |
| dependencies | unvetted-dep:@tanstack/start-client-core | AI (dependencies): First-party TanStack monorepo dependency; part of the same release train as this package. Not a third-party risk. | ai | |
| dependencies | unvetted-dep:@tanstack/solid-router | AI (dependencies): First-party TanStack monorepo dependency; part of the same release train as this package. Not a third-party risk. | ai |
Versions (showing 51 of 382)
| Version | Deps | Published |
|---|---|---|
| 1.168.12 | 3 / 3 | |
| 1.168.11 | 3 / 3 | |
| 1.168.10 | 3 / 3 | |
| 1.168.9 | 3 / 3 | |
| 1.168.8 | 3 / 4 | |
| 1.168.7 | 3 / 4 | |
| 1.168.6 | 3 / 4 | |
| 1.168.5 | 3 / 4 | |
| 1.168.4 | 3 / 4 | |
| 1.168.3 | 3 / 4 | |
| 1.168.2 | 3 / 4 | |
| 1.168.1 | 3 / 4 | |
| 1.168.0 | 3 / 4 | |
| 1.167.4 | 3 / 4 | |
| 1.167.3 | 3 / 4 | |
| 1.167.2 | 3 / 4 | |
| 1.167.1 | 3 / 4 | |
| 1.167.0 | 3 / 4 | |
| 1.166.47 | 3 / 4 | |
| 1.166.46 | 3 / 4 | |
| 1.166.45 | 3 / 4 | |
| 1.166.44 | 3 / 4 | |
| 1.166.43 | 3 / 4 | |
| 1.166.42 | 3 / 4 | |
| 1.166.41 | 3 / 4 | |
| 1.166.40 | 3 / 4 | |
| 1.166.39 | 3 / 4 | |
| 1.166.38 | 3 / 4 | |
| 1.166.37 | 3 / 4 | |
| 1.166.36 | 3 / 4 | |
| 1.166.35 | 3 / 4 | |
| 1.166.34 | 3 / 4 | |
| 1.166.33 | 3 / 4 | |
| 1.166.32 | 3 / 4 | |
| 1.166.31 | 3 / 4 | |
| 1.166.30 | 3 / 4 | |
| 1.166.29 | 3 / 4 | |
| 1.166.28 | 3 / 4 | |
| 1.166.27 | 3 / 4 | |
| 1.166.26 | 3 / 4 | |
| 1.166.25 | 3 / 4 | |
| 1.166.24 | 3 / 4 | |
| 1.166.23 | 3 / 4 | |
| 1.166.22 | 3 / 4 | |
| 1.166.21 | 3 / 4 | |
| 1.166.20 | 3 / 4 | |
| 1.166.19 | 3 / 4 | |
| 1.166.18 | 3 / 4 | |
| 1.166.17 | 3 / 4 | |
| 1.166.16 | 3 / 4 | |
| 1.166.15 | 5 / 4 |
v1.168.12
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.168.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.168.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.168.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.168.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.168.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.168.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.168.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.168.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.168.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.168.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.168.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.168.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.167.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.167.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.167.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.167.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.167.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.166.47
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.166.46
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.166.45
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.166.44
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.166.43
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.166.40
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.166.39
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.166.38
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.166.37
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.166.36
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.166.35
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.166.34
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.166.33
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.166.32
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.166.31
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.166.30
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.166.29
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.166.28
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.166.27
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.166.26
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.166.25
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.166.24
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.166.23
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.166.22
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.166.21
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.166.20
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.166.19
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.166.18
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.166.17
2 findingsThis version was published by a different npm account than previous versions on 2026-03-23. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.166.16
2 findingsThis version was published by a different npm account than previous versions on 2026-03-22. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.166.15
2 findingsThis version was published by a different npm account than previous versions on 2026-03-20. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.