← Home

@tanstack/start-plugin-core

21
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

tannerlinsleytkdodoalemtuzlakkevinvandyschiller-manuel

Keywords

solidreactlocationrouterroutingasyncasync routertypescript

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@types/babel__core AI (phantom-deps): Type-only dep loaded by convention in this build tooling package; stable false positive. ai
phantom-deps phantom-dep:@types/babel__code-frame AI (phantom-deps): Type-only dep loaded by convention; stable false positive for this package. ai
dependencies unvetted-dep:@tanstack/server-functions-plugin AI (dependencies): Sibling package within the TanStack org monorepo; routinely published alongside this package. Not an independent third-party dependency. ai
bogus-package bogus-package AI (bogus-package): This is a monorepo sub-package from TanStack; sparse README is expected as docs live at tanstack.com/start. Not a spam or phishing package. ai
phantom-deps phantom-dep:@rolldown/pluginutils AI (phantom-deps): Build plugin package; @rolldown/pluginutils is a declared dependency used in config/build tooling context, not necessarily directly imported in source. ai
phantom-deps phantom-dep:@tanstack/start-client-core AI (phantom-deps): Same-org sibling package used conditionally in the plugin; phantom detection is a false positive for this monorepo package. ai

Versions (showing 21 of 422)

Version Deps Published
1.130.8 20 / 1
1.130.7 20 / 1
1.129.9 19 / 1
1.129.5 19 / 1
1.129.0 19 / 1
1.128.6 19 / 1
1.128.3 19 / 1
1.128.0 19 / 1
1.125.3 19 / 1
1.124.1 19 / 1
1.124.0 19 / 1
1.121.41 19 / 1
1.121.37 19 / 1
1.121.33 19 / 1
1.121.31 19 / 1
1.121.25 19 / 1
1.121.13 19 / 1
1.121.9 19 / 1
1.121.6 19 / 1
1.121.2 19 / 1
1.121.0 19 / 1

v1.130.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.