@tanstack/vue-query
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@tanstack/match-sorter-utils | AI (dependencies): First-party TanStack package; stable false positive for this ecosystem. | ai |
Versions (showing 51 of 295)
| Version | Deps | Published |
|---|---|---|
| 5.101.4 | 4 / 7 | |
| 5.101.3 | 4 / 7 | |
| 5.101.2 | 4 / 7 | |
| 5.101.1 | 4 / 7 | |
| 5.101.0 | 4 / 7 | |
| 5.100.14 | 4 / 7 | |
| 5.100.13 | 4 / 7 | |
| 5.100.12 | 4 / 7 | |
| 5.100.11 | 4 / 7 | |
| 5.100.10 | 4 / 7 | |
| 5.100.9 | 4 / 7 | |
| 5.100.8 | 4 / 7 | |
| 5.100.7 | 4 / 7 | |
| 5.100.6 | 4 / 7 | |
| 5.100.5 | 4 / 7 | |
| 5.100.4 | 4 / 7 | |
| 5.100.3 | 4 / 7 | |
| 5.100.2 | 4 / 7 | |
| 5.100.1 | 4 / 7 | |
| 5.100.0 | 4 / 7 | |
| 5.99.2 | 4 / 7 | |
| 5.99.1 | 4 / 7 | |
| 5.99.0 | 4 / 7 | |
| 5.98.0 | 4 / 7 | |
| 5.97.0 | 4 / 7 | |
| 5.96.2 | 4 / 7 | |
| 5.96.1 | 4 / 7 | |
| 5.96.0 | 4 / 7 | |
| 5.95.2 | 4 / 7 | |
| 5.95.1 | 4 / 7 | |
| 5.95.0 | 4 / 7 | |
| 5.94.5 | 4 / 7 | |
| 5.94.4 | 4 / 7 | |
| 5.92.12 | 4 / 7 | |
| 5.92.10 | 4 / 7 | |
| 5.92.9 | 4 / 7 | |
| 5.92.8 | 4 / 7 | |
| 5.92.7 | 4 / 7 | |
| 5.92.6 | 4 / 7 | |
| 5.92.5 | 4 / 7 | |
| 5.92.4 | 4 / 7 | |
| 5.92.3 | 4 / 7 | |
| 5.92.2 | 4 / 7 | |
| 5.92.1 | 4 / 7 | |
| 5.92.0 | 4 / 7 | |
| 5.91.4 | 4 / 7 | |
| 5.91.3 | 4 / 7 | |
| 5.91.2 | 4 / 7 | |
| 5.91.1 | 4 / 7 | |
| 5.91.0 | 4 / 7 | |
| 5.90.7 | 4 / 7 |
v5.101.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.101.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.101.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.100.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.98.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.97.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.96.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.95.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.95.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.95.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.94.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.94.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.92.12
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.92.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.92.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.92.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.92.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.92.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.92.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.92.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.92.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.92.2
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (tannerlinsley) on 2025-12-28, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v5.92.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.92.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.91.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.91.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.91.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.91.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.91.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.90.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.