@tanstack/vue-query
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@tanstack/match-sorter-utils | AI (dependencies): First-party TanStack package; stable false positive for this ecosystem. | ai |
Versions (showing 100 of 295)
| Version | Deps | Published |
|---|---|---|
| 5.101.4 | 4 / 7 | |
| 5.101.3 | 4 / 7 | |
| 5.101.2 | 4 / 7 | |
| 5.101.1 | 4 / 7 | |
| 5.101.0 | 4 / 7 | |
| 5.100.14 | 4 / 7 | |
| 5.100.13 | 4 / 7 | |
| 5.100.12 | 4 / 7 | |
| 5.100.11 | 4 / 7 | |
| 5.100.10 | 4 / 7 | |
| 5.100.9 | 4 / 7 | |
| 5.100.8 | 4 / 7 | |
| 5.100.7 | 4 / 7 | |
| 5.100.6 | 4 / 7 | |
| 5.100.5 | 4 / 7 | |
| 5.100.4 | 4 / 7 | |
| 5.100.3 | 4 / 7 | |
| 5.100.2 | 4 / 7 | |
| 5.100.1 | 4 / 7 | |
| 5.100.0 | 4 / 7 | |
| 5.99.2 | 4 / 7 | |
| 5.99.1 | 4 / 7 | |
| 5.99.0 | 4 / 7 | |
| 5.98.0 | 4 / 7 | |
| 5.97.0 | 4 / 7 | |
| 5.96.2 | 4 / 7 | |
| 5.96.1 | 4 / 7 | |
| 5.96.0 | 4 / 7 | |
| 5.95.2 | 4 / 7 | |
| 5.95.1 | 4 / 7 | |
| 5.95.0 | 4 / 7 | |
| 5.94.5 | 4 / 7 | |
| 5.94.4 | 4 / 7 | |
| 5.92.12 | 4 / 7 | |
| 5.92.10 | 4 / 7 | |
| 5.92.9 | 4 / 7 | |
| 5.92.8 | 4 / 7 | |
| 5.92.7 | 4 / 7 | |
| 5.92.6 | 4 / 7 | |
| 5.92.5 | 4 / 7 | |
| 5.92.4 | 4 / 7 | |
| 5.92.3 | 4 / 7 | |
| 5.92.2 | 4 / 7 | |
| 5.92.1 | 4 / 7 | |
| 5.92.0 | 4 / 7 | |
| 5.91.4 | 4 / 7 | |
| 5.91.3 | 4 / 7 | |
| 5.91.2 | 4 / 7 | |
| 5.91.1 | 4 / 7 | |
| 5.91.0 | 4 / 7 | |
| 5.90.7 | 4 / 7 | |
| 5.90.6 | 4 / 7 | |
| 5.90.5 | 4 / 7 | |
| 5.90.4 | 4 / 7 | |
| 5.90.3 | 4 / 7 | |
| 5.90.2 | 4 / 7 | |
| 5.90.1 | 4 / 7 | |
| 5.89.0 | 4 / 7 | |
| 5.87.4 | 4 / 7 | |
| 5.87.1 | 4 / 7 | |
| 5.87.0 | 4 / 7 | |
| 5.86.0 | 4 / 7 | |
| 5.85.9 | 4 / 7 | |
| 5.85.7 | 4 / 7 | |
| 5.85.6 | 4 / 7 | |
| 5.85.5 | 4 / 7 | |
| 5.85.4 | 4 / 7 | |
| 5.85.3 | 4 / 7 | |
| 5.85.2 | 4 / 7 | |
| 5.85.1 | 4 / 7 | |
| 5.83.1 | 4 / 7 | |
| 5.83.0 | 4 / 7 | |
| 5.82.0 | 4 / 7 | |
| 5.81.5 | 4 / 7 | |
| 5.81.4 | 4 / 7 | |
| 5.81.3 | 4 / 7 | |
| 5.81.2 | 4 / 7 | |
| 5.81.1 | 4 / 7 | |
| 5.81.0 | 4 / 7 | |
| 5.80.12 | 4 / 7 | |
| 5.80.11 | 4 / 7 | |
| 5.80.10 | 4 / 7 | |
| 5.80.7 | 4 / 7 | |
| 5.80.6 | 4 / 7 | |
| 5.80.5 | 4 / 7 | |
| 5.80.4 | 4 / 7 | |
| 5.80.2 | 4 / 7 | |
| 5.80.1 | 4 / 7 | |
| 5.80.0 | 4 / 7 | |
| 5.79.2 | 4 / 7 | |
| 5.79.1 | 4 / 7 | |
| 5.79.0 | 4 / 7 | |
| 5.77.2 | 4 / 7 | |
| 5.77.1 | 4 / 7 | |
| 5.77.0 | 4 / 7 | |
| 5.76.2 | 4 / 7 | |
| 5.76.0 | 4 / 7 | |
| 5.75.7 | 4 / 7 | |
| 5.75.6 | 4 / 7 | |
| 5.75.5 | 4 / 6 |
v5.101.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.101.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.101.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.100.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.98.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.97.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.96.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.95.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.95.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.95.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.94.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.94.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.92.12
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.92.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.92.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.92.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.92.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.92.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.92.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.92.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.92.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.92.2
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (tannerlinsley) on 2025-12-28, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v5.92.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.92.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.91.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.91.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.91.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.91.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.91.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.90.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.