@tanstack/start-plugin-core
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@types/babel__core | AI (phantom-deps): Type-only dep loaded by convention in this build tooling package; stable false positive. | ai | |
| phantom-deps | phantom-dep:@types/babel__code-frame | AI (phantom-deps): Type-only dep loaded by convention; stable false positive for this package. | ai | |
| dependencies | unvetted-dep:@tanstack/server-functions-plugin | AI (dependencies): Sibling package within the TanStack org monorepo; routinely published alongside this package. Not an independent third-party dependency. | ai | |
| bogus-package | bogus-package | AI (bogus-package): This is a monorepo sub-package from TanStack; sparse README is expected as docs live at tanstack.com/start. Not a spam or phishing package. | ai | |
| phantom-deps | phantom-dep:@rolldown/pluginutils | AI (phantom-deps): Build plugin package; @rolldown/pluginutils is a declared dependency used in config/build tooling context, not necessarily directly imported in source. | ai | |
| phantom-deps | phantom-dep:@tanstack/start-client-core | AI (phantom-deps): Same-org sibling package used conditionally in the plugin; phantom detection is a false positive for this monorepo package. | ai |
Versions (showing 51 of 428)
| Version | Deps | Published |
|---|---|---|
| 1.171.24 | 20 / 6 | |
| 1.171.23 | 20 / 6 | |
| 1.171.22 | 20 / 6 | |
| 1.171.21 | 20 / 6 | |
| 1.171.20 | 20 / 6 | |
| 1.171.19 | 20 / 6 | |
| 1.171.18 | 20 / 6 | |
| 1.171.17 | 20 / 6 | |
| 1.171.16 | 20 / 6 | |
| 1.171.15 | 20 / 6 | |
| 1.171.14 | 20 / 6 | |
| 1.171.13 | 20 / 6 | |
| 1.171.12 | 22 / 6 | |
| 1.171.11 | 22 / 6 | |
| 1.171.10 | 22 / 6 | |
| 1.171.9 | 22 / 6 | |
| 1.171.8 | 22 / 6 | |
| 1.171.7 | 22 / 6 | |
| 1.171.6 | 22 / 6 | |
| 1.171.5 | 22 / 6 | |
| 1.171.4 | 23 / 6 | |
| 1.171.3 | 23 / 6 | |
| 1.171.2 | 23 / 6 | |
| 1.171.1 | 23 / 6 | |
| 1.171.0 | 23 / 6 | |
| 1.170.6 | 23 / 6 | |
| 1.170.5 | 23 / 6 | |
| 1.170.4 | 23 / 6 | |
| 1.170.3 | 23 / 6 | |
| 1.170.2 | 23 / 6 | |
| 1.170.1 | 23 / 6 | |
| 1.170.0 | 23 / 6 | |
| 1.169.20 | 23 / 6 | |
| 1.169.19 | 23 / 6 | |
| 1.169.18 | 23 / 6 | |
| 1.169.17 | 23 / 6 | |
| 1.169.16 | 23 / 6 | |
| 1.169.15 | 23 / 6 | |
| 1.169.14 | 23 / 6 | |
| 1.169.13 | 23 / 6 | |
| 1.169.12 | 23 / 6 | |
| 1.169.11 | 23 / 6 | |
| 1.169.10 | 23 / 6 | |
| 1.169.9 | 23 / 6 | |
| 1.169.8 | 23 / 6 | |
| 1.169.7 | 23 / 6 | |
| 1.169.6 | 23 / 6 | |
| 1.169.5 | 23 / 6 | |
| 1.169.4 | 23 / 6 | |
| 1.169.3 | 23 / 6 | |
| 1.169.2 | 23 / 6 |
v1.171.24
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.171.23
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.171.22
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.171.21
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.171.20
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.171.19
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.