← Home

@tanstack/solid-start

20
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

tannerlinsleytkdodoalemtuzlakkevinvandyschiller-manuel

Keywords

solidlocationrouterroutingasyncasync routertypescript

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@tanstack/solid-start-plugin AI (dependencies): Internal @tanstack monorepo dependency released in lockstep; same publisher, no independent risk. ai
dependencies unvetted-dep:@tanstack/start-api-routes AI (dependencies): Internal TanStack monorepo sub-package, co-published with same version. ai
dependencies unvetted-dep:@tanstack/solid-start-config AI (dependencies): Internal TanStack monorepo sub-package, co-published with same version. ai
dependencies unvetted-dep:@tanstack/start-server-functions-ssr AI (dependencies): Internal TanStack monorepo sub-package, co-published with same version. ai
dependencies unvetted-dep:@tanstack/solid-start-router-manifest AI (dependencies): Internal TanStack monorepo sub-package, co-published with same version. ai
dependencies unvetted-dep:@tanstack/start-server-functions-server AI (dependencies): Internal TanStack monorepo sub-package, co-published alongside this release. ai
dependencies unvetted-dep:@tanstack/start-server-functions-handler AI (dependencies): Internal TanStack monorepo sub-package, co-published with same version. ai
dependencies unvetted-dep:@tanstack/start-server-functions-client AI (dependencies): Internal TanStack monorepo sub-package, co-published with same version. ai
provenance publisher-changed AI (provenance): TanStack/router migrated to GitHub Actions CI/CD publishing with SLSA provenance attestation — this is a supply chain improvement, not a compromise signal. Stable for this package going forward. ai
maintainer-change maintainer-added AI (maintainer-change): lachlancollins is a known TanStack contributor. Adding maintainers to an active OSS project is routine and expected. ai

Versions (showing 20 of 422)

Version Deps Published
1.132.14 7 / 2
1.132.13 7 / 2
1.132.12 6 / 2
1.132.11 6 / 2
1.132.10 6 / 2
1.132.9 6 / 2
1.132.8 6 / 2
1.132.7 6 / 2
1.132.6 6 / 2
1.132.5 6 / 2
1.132.4 6 / 2
1.132.3 6 / 2
1.132.2 6 / 2
1.132.1 6 / 2
1.132.0 6 / 2
1.131.35 5 / 1
1.121.0 5 / 1
1.120.5 9 / 1
1.119.2 9 / 1
1.117.1 9 / 1

v1.132.14

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.132.13

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.132.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.132.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.121.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.119.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.117.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.