← Home

@tanstack/start-client-core

33
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

tannerlinsleytkdodoalemtuzlakkevinvandyschiller-manuel

Keywords

reactlocationrouterroutingasyncasync routertypescript

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): TanStack migrated to GitHub Actions CI/CD publishing with SLSA provenance; publisher-changed to GitHub Actions is expected and stable for this package going forward. ai
maintainer-change maintainer-added AI (maintainer-change): lachlancollins is a known TanStack contributor; this is a legitimate team expansion for the TanStack org, not a suspicious takeover. ai
phantom-deps phantom-dep:tiny-warning AI (phantom-deps): tiny-warning is declared as a runtime dependency in package.json; the phantom-dep finding is a false positive for this package. ai
bogus-package bogus-package AI (bogus-package): TanStack monorepo sub-packages routinely have minimal READMEs that defer to the main docs site. Not a spam/phishing indicator for this established ecosystem package. ai

Versions (showing 33 of 333)

Version Deps Published
1.123.0 4 / 0
1.122.0 4 / 0
1.121.40 4 / 0
1.121.39 4 / 0
1.121.34 4 / 0
1.121.33 4 / 0
1.121.27 4 / 0
1.121.23 4 / 0
1.121.21 4 / 0
1.121.20 4 / 0
1.121.19 4 / 0
1.121.18 4 / 0
1.121.17 4 / 0
1.121.16 4 / 0
1.121.15 4 / 0
1.121.14 4 / 0
1.121.12 4 / 0
1.121.2 4 / 0
1.121.0 4 / 0
1.120.19 4 / 0
1.120.17 4 / 0
1.120.16 4 / 0
1.120.15 4 / 0
1.120.13 4 / 0
1.120.10 4 / 0
1.120.9 4 / 0
1.120.8 4 / 0
1.120.7 4 / 0
1.120.5 4 / 0
1.120.4 4 / 0
1.120.3 4 / 0
1.119.0 4 / 0
1.117.1 4 / 0

v1.121.20

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.120.16

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.120.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.119.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.117.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.