@treeseed/core
Treeseed integrated platform starter for Astro/Starlight web runtimes and Hono API runtimes.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:env-spread | AI (semgrep): process.env spread into env of a spawned npm install to disable install scripts; not exfiltrated anywhere. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New deps are core Astro ecosystem packages; consistent with this Astro/Starlight framework's documented purpose. | ai | |
| dependencies | unvetted-dep:@astrojs/sitemap | AI (dependencies): Well-known Astro ecosystem package; no malware indicators. | ai | |
| dependencies | unvetted-dep:@astrojs/starlight | AI (dependencies): Well-known Astro ecosystem package; no malware indicators. | ai | |
| dependencies | unvetted-dep:@astrojs/cloudflare | AI (dependencies): Well-known Astro ecosystem package; no malware indicators. | ai | |
| phantom-deps | phantom-dep:katex | AI (phantom-deps): Math rendering dep referenced in config, not directly imported — expected for docs starter. | ai | |
| phantom-deps | phantom-dep:remark-gfm | AI (phantom-deps): Remark plugin referenced in config, not directly imported — expected pattern. | ai | |
| phantom-deps | phantom-dep:remark-mdx | AI (phantom-deps): Remark plugin referenced in config, not directly imported — expected pattern. | ai | |
| phantom-deps | phantom-dep:remark-stringify | AI (phantom-deps): Remark plugin referenced in config, not directly imported — expected pattern. | ai | |
| phantom-deps | phantom-dep:remark-frontmatter | AI (phantom-deps): Remark plugin referenced in config, not directly imported — expected pattern. | ai | |
| phantom-deps | phantom-dep:@astrojs/check | AI (phantom-deps): Astro type-checker referenced in scripts/config, not directly imported — expected pattern. | ai | |
| phantom-deps | phantom-dep:remark-parse | AI (phantom-deps): Remark plugin referenced in config, not directly imported — expected pattern. | ai | |
| phantom-deps | phantom-dep:wrangler | AI (phantom-deps): Framework starter; wrangler referenced in config/scripts, not imported directly — expected pattern. | ai | |
| phantom-deps | phantom-dep:vitest | AI (phantom-deps): Test runner referenced in vitest.config.ts, not directly imported — expected pattern. | ai | |
| phantom-deps | phantom-dep:tailwindcss | AI (phantom-deps): CSS framework referenced in config files, not directly imported — expected for Astro starter. | ai | |
| phantom-deps | phantom-dep:unified | AI (phantom-deps): Remark/unified pipeline dep referenced in config, not directly imported — expected pattern. | ai | |
| typosquat | typosquat.levenshtein:cors | AI (typosquat): Scoped package @treeseed/core is not a typosquat of 'cors'. The edit-distance match is on the unscoped portion only; the full name, repo, and purpose are clearly distinct. | ai |
Versions (showing 20 of 120)
| Version | Deps | Published |
|---|---|---|
| 0.6.1 | 24 / 1 | |
| 0.5.4 | 24 / 1 | |
| 0.5.3 | 24 / 1 | |
| 0.5.2 | 24 / 1 | |
| 0.4.13 | 24 / 1 | |
| 0.4.12 | 24 / 1 | |
| 0.4.11 | 24 / 1 | |
| 0.4.10 | 24 / 1 | |
| 0.4.9 | 24 / 1 | |
| 0.4.8 | 24 / 1 | |
| 0.4.7 | 24 / 1 | |
| 0.4.6 | 24 / 1 | |
| 0.4.5 | 24 / 1 | |
| 0.4.4 | 24 / 1 | |
| 0.4.2 | 23 / 1 | |
| 0.4.1 | 23 / 1 | |
| 0.4.0 | 23 / 1 | |
| 0.3.2 | 23 / 1 | |
| 0.3.0 | 23 / 1 | |
| 0.1.2 | 23 / 1 |
v0.6.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.13
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.12
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.