powerlines
The "framework framework" that simplifies modern dev tool usage, generates virtual (or actual) code modules, and improves DX across the board.
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:bin/prompts-Cb5cSsjg.mjs | AI (source-diff): Bundled CLI output (esbuild-style), not true obfuscation; no malicious behavior in sample. | ai | |
| source-diff | obfuscated-file:bin/prompts-BLU5Njeg.mjs | AI (source-diff): Minified bundled CLI output, not true obfuscation; no malicious behavior found. | ai | |
| source-diff | obfuscated-file:bin/prompts-D2lN84PY.mjs | AI (source-diff): Bundled tsup/esbuild CLI output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:bin/prompts-rJ8Zkvkh.mjs | AI (source-diff): Bundled CLI output, not true obfuscation; consistent with package's build tooling. | ai | |
| source-diff | obfuscated-file:bin/prompts-D_Rv-lNz.mjs | AI (source-diff): Bundled chunk, minified build output not true obfuscation. | ai | |
| source-diff | obfuscated-file:bin/bin.mjs | AI (source-diff): Bundled CLI entry, minified build output not true obfuscation. | ai | |
| phantom-deps | phantom-dep:typedoc-plugin-frontmatter | AI (phantom-deps): Config-referenced plugin, not a code-import; benign for this doc-tooling package. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Bin directory restructure/bundling, no malicious behavior observed. | ai | |
| source-diff | obfuscated-file:bin/prompts-DEjU8qNL.mjs | AI (source-diff): Bundled esbuild output for CLI, not true obfuscation. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Result of bundling more CLI subcommands into bin/, not injected payload. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Patches TS compiler for deepkit type transformer; documented build-tool behavior, no exfil/fetch. | ai | |
| install-scripts | install-script:install | AI (install-scripts): Removes bundled typescript dep, known deepkit/type-compiler workaround pattern. | ai | |
| phantom-deps | phantom-dep:@powerlines/plugin-unbuild | AI (phantom-deps): Config-referenced tool; stable pattern for this framework package. | ai | |
| phantom-deps | phantom-dep:@stryke/string-format | AI (phantom-deps): Config-referenced tool; stable pattern for this framework package. | ai | |
| phantom-deps | phantom-dep:compatx | AI (phantom-deps): Config-referenced tool; stable pattern for this framework package. | ai | |
| phantom-deps | phantom-dep:undici | AI (phantom-deps): Known implicit runtime dependency; stable for this package. | ai | |
| phantom-deps | phantom-dep:jiti | AI (phantom-deps): Config-referenced tool; stable pattern for this framework package. | ai | |
| phantom-deps | phantom-dep:@donedeal0/superdiff | AI (phantom-deps): Config-referenced tool; stable pattern for this framework package. | ai | |
| phantom-deps | phantom-dep:@stryke/unique-id | AI (phantom-deps): Config-referenced tool; stable pattern for this framework package. | ai | |
| phantom-deps | phantom-dep:bundle-require | AI (phantom-deps): Config-referenced tool; stable pattern for this framework package. | ai | |
| phantom-deps | phantom-dep:@stryke/capnp | AI (phantom-deps): Config-referenced tool; stable pattern for this framework package. | ai | |
| phantom-deps | phantom-dep:@stryke/json | AI (phantom-deps): Config-referenced tool; stable pattern for this framework package. | ai | |
| phantom-deps | phantom-dep:@stryke/http | AI (phantom-deps): Config-referenced tool; stable pattern for this framework package. | ai | |
| phantom-deps | phantom-dep:@stryke/hash | AI (phantom-deps): Config-referenced tool; stable pattern for this framework package. | ai | |
| phantom-deps | phantom-dep:oxc-parser | AI (phantom-deps): Config-referenced tool; stable pattern for this framework package. | ai | |
| phantom-deps | phantom-dep:flat-cache | AI (phantom-deps): Config-referenced tool; stable pattern for this framework package. | ai | |
| phantom-deps | phantom-dep:ts-morph | AI (phantom-deps): Config-referenced tool; stable pattern for this framework package. | ai | |
| dependencies | unvetted-dep:@power-plant/schema | AI (dependencies): Sibling first-party scoped package in same monorepo ecosystem, low risk. | ai | |
| phantom-deps | phantom-dep:@jridgewell/sourcemap-codec | AI (phantom-deps): Config-referenced dep; stable FP for this package. | ai | |
| phantom-deps | phantom-dep:locate-character | AI (phantom-deps): Config-referenced dep; stable FP for this package. | ai | |
| phantom-deps | phantom-dep:@stryke/env | AI (phantom-deps): First-party @stryke scoped dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@storm-software/config-tools | AI (phantom-deps): First-party @storm-software scoped dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@stryke/fs | AI (phantom-deps): First-party @stryke scoped dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:unplugin | AI (phantom-deps): Declared dep; used indirectly via @powerlines/unplugin integration layer. | ai | |
| phantom-deps | phantom-dep:defu | AI (phantom-deps): Declared in package.json deps; likely re-exported or used indirectly via sub-packages in this monorepo. | ai | |
| phantom-deps | phantom-dep:@stryke/convert | AI (phantom-deps): First-party @stryke scoped dep; stable false positive for this package. | ai | |
| source-diff | obfuscated-file:dist/plugin-utils.d.cts | AI (source-diff): File is a TypeScript declaration file with long bundled import lines, not obfuscated executable code. | ai | |
| provenance | publisher-changed | AI (provenance): Publisher changed to GitHub Actions with SLSA provenance attestation; legitimate CI/CD migration for this org. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-transform-export-namespace-from | AI (phantom-deps): Framework-scoped Babel plugin; loaded by convention in build tools. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-syntax-jsx | AI (phantom-deps): Framework-scoped Babel plugin; loaded by convention in build tools. | ai | |
| phantom-deps | phantom-dep:@babel/preset-typescript | AI (phantom-deps): Framework-scoped Babel preset; loaded by convention in build tools. | ai | |
| phantom-deps | phantom-dep:@babel/helper-simple-access | AI (phantom-deps): Framework-scoped Babel helper; loaded by convention in build tools. | ai | |
| phantom-deps | phantom-dep:@babel/helper-module-imports | AI (phantom-deps): Framework-scoped Babel helper; loaded by convention in build tools. | ai | |
| phantom-deps | phantom-dep:@babel/helper-module-transforms | AI (phantom-deps): Framework-scoped Babel helper; loaded by convention in build tools. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-syntax-typescript | AI (phantom-deps): Framework-scoped Babel plugin; loaded by convention in build tools. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-proposal-decorators | AI (phantom-deps): Framework-scoped Babel plugin; loaded by convention in build tools. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-transform-react-jsx | AI (phantom-deps): Framework-scoped Babel plugin; loaded by convention in build tools. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-transform-typescript | AI (phantom-deps): Framework-scoped Babel plugin; loaded by convention in build tools. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-syntax-class-properties | AI (phantom-deps): Framework-scoped Babel plugin; loaded by convention in build tools. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-syntax-import-assertions | AI (phantom-deps): Framework-scoped Babel plugin; loaded by convention in build tools. | ai | |
| phantom-deps | phantom-dep:@storm-software/esbuild | AI (phantom-deps): Config-referenced tool; stable pattern for this build-tool framework. | ai | |
| phantom-deps | phantom-dep:@babel/parser | AI (phantom-deps): powerlines is a build framework that loads Babel plugins by convention; phantom Babel deps are expected and stable across versions. | ai | |
| dependencies | unvetted-dep:babel-plugin-parameter-decorator | AI (dependencies): Well-known Babel plugin for TypeScript decorator support; no security concerns for this build framework. | ai | |
| dependencies | unvetted-dep:@storm-software/esbuild | AI (dependencies): First-party Storm Software package from the same publisher org with 233 approved packages; stable for this package. | ai | |
| dependencies | unvetted-dep:@storm-software/tsup | AI (dependencies): First-party Storm Software package from the same publisher org with 233 approved packages; stable for this package. | ai | |
| phantom-deps | phantom-dep:@alloy-js/babel-plugin-jsx-dom-expressions | AI (phantom-deps): Config-referenced package for this build framework; phantom dep pattern is stable. | ai | |
| phantom-deps | phantom-dep:babel-dead-code-elimination | AI (phantom-deps): Config-referenced Babel plugin for this build framework; phantom dep pattern is stable. | ai | |
| phantom-deps | phantom-dep:babel-plugin-parameter-decorator | AI (phantom-deps): Config-referenced Babel plugin for this build framework; phantom dep pattern is stable. | ai | |
| phantom-deps | phantom-dep:github-slugger | AI (phantom-deps): Config-referenced package for this build framework; phantom dep pattern is stable. | ai | |
| phantom-deps | phantom-dep:nanotar | AI (phantom-deps): Config-referenced package for this build framework; phantom dep pattern is stable. | ai | |
| phantom-deps | phantom-dep:@typescript-eslint/utils | AI (phantom-deps): Config-referenced package for this build framework; phantom dep pattern is stable. | ai | |
| phantom-deps | phantom-dep:@microsoft/api-extractor | AI (phantom-deps): Config-referenced package for this build framework; phantom dep pattern is stable. | ai | |
| phantom-deps | phantom-dep:@microsoft/tsdoc-config | AI (phantom-deps): Config-referenced package for this build framework; phantom dep pattern is stable. | ai | |
| phantom-deps | phantom-dep:@alloy-js/babel-preset | AI (phantom-deps): Config-referenced package for this build framework; phantom dep pattern is stable. | ai | |
| phantom-deps | phantom-dep:@alloy-js/babel-plugin | AI (phantom-deps): Config-referenced package for this build framework; phantom dep pattern is stable. | ai | |
| phantom-deps | phantom-dep:@babel/generator | AI (phantom-deps): Framework-scoped Babel package loaded by convention; expected for this build framework. | ai | |
| phantom-deps | phantom-dep:@babel/template | AI (phantom-deps): Framework-scoped Babel package loaded by convention; expected for this build framework. | ai | |
| dependencies | unvetted-dep:handlebars | AI (dependencies): Handlebars is a well-known templating library used legitimately in this code-generation framework. Constraint ^4.7.8 starts at a patched version past known prototype pollution CVEs. | ai | |
| phantom-deps | phantom-dep:oxc-resolver | AI (phantom-deps): oxc-resolver is a runtime dep used via dynamic/config-driven loading in this plugin framework; not directly imported but legitimately declared. | ai | |
| phantom-deps | phantom-dep:@cacheable/memory | AI (phantom-deps): @cacheable/memory is a runtime dep used via dynamic/config-driven loading in this plugin framework; not directly imported but legitimately declared. | ai | |
| phantom-deps | phantom-dep:unimport | AI (phantom-deps): unimport is a runtime dep used via dynamic/config-driven loading in this plugin framework; not directly imported but legitimately declared. | ai | |
| dependencies | unvetted-dep:@stryke/env | AI (dependencies): @stryke/* packages are first-party Storm Software org packages, consistent with monorepo publishing pattern for this package family. | ai | |
| phantom-deps | phantom-dep:@storm-software/config | AI (phantom-deps): Referenced in config files but not directly imported is expected behavior for a config package in a monorepo build tool context. | ai | |
| phantom-deps | phantom-dep:@babel/types | AI (phantom-deps): @babel/types is a well-known package loaded by convention in build tooling; phantom dep finding is expected for this type of framework package. | ai | |
| dependencies | unvetted-dep:@storm-software/config-tools | AI (dependencies): @storm-software/* packages are first-party Storm Software org packages, consistent with monorepo publishing pattern. | ai | |
| dependencies | unvetted-dep:@storm-software/config | AI (dependencies): @storm-software/* packages are first-party Storm Software org packages, consistent with monorepo publishing pattern. | ai | |
| dependencies | unvetted-dep:@powerlines/engine | AI (dependencies): @powerlines/* packages are first-party packages from the same Storm Software monorepo as powerlines itself. | ai | |
| dependencies | unvetted-dep:@powerlines/core | AI (dependencies): @powerlines/* packages are first-party packages from the same Storm Software monorepo as powerlines itself. | ai | |
| dependencies | unvetted-dep:@stryke/convert | AI (dependencies): @stryke/* packages are first-party Storm Software org packages, consistent with monorepo publishing pattern for this package family. | ai | |
| dependencies | unvetted-dep:@stryke/fs | AI (dependencies): @stryke/* packages are first-party Storm Software org packages, consistent with monorepo publishing pattern for this package family. | ai |
Versions (showing 100 of 574)
| Version | Deps | Published |
|---|---|---|
| 0.47.22 | 11 / 5 | |
| 0.47.21 | 11 / 5 | |
| 0.47.20 | 11 / 5 | |
| 0.47.19 | 11 / 5 | |
| 0.47.18 | 11 / 5 | |
| 0.47.17 | 11 / 5 | |
| 0.47.16 | 11 / 5 | |
| 0.47.15 | 11 / 5 | |
| 0.47.14 | 11 / 5 | |
| 0.47.13 | 11 / 5 | |
| 0.47.12 | 11 / 5 | |
| 0.47.11 | 11 / 5 | |
| 0.47.10 | 11 / 5 | |
| 0.47.9 | 11 / 5 | |
| 0.47.8 | 11 / 5 | |
| 0.47.7 | 11 / 5 | |
| 0.47.4 | 10 / 5 | |
| 0.47.3 | 10 / 5 | |
| 0.47.2 | 10 / 5 | |
| 0.47.1 | 10 / 5 | |
| 0.47.0 | 10 / 5 | |
| 0.46.6 | 10 / 5 | |
| 0.46.5 | 10 / 5 | |
| 0.46.4 | 10 / 5 | |
| 0.46.3 | 10 / 5 | |
| 0.46.2 | 10 / 5 | |
| 0.46.1 | 10 / 5 | |
| 0.46.0 | 10 / 5 | |
| 0.45.3 | 10 / 5 | |
| 0.45.2 | 10 / 5 | |
| 0.45.1 | 10 / 5 | |
| 0.45.0 | 10 / 5 | |
| 0.44.12 | 10 / 5 | |
| 0.44.11 | 10 / 5 | |
| 0.44.10 | 10 / 5 | |
| 0.44.9 | 10 / 5 | |
| 0.44.8 | 10 / 5 | |
| 0.44.7 | 10 / 5 | |
| 0.44.6 | 10 / 5 | |
| 0.44.5 | 10 / 5 | |
| 0.44.4 | 10 / 5 | |
| 0.44.3 | 10 / 5 | |
| 0.44.2 | 10 / 5 | |
| 0.44.1 | 10 / 5 | |
| 0.44.0 | 10 / 5 | |
| 0.43.31 | 10 / 5 | |
| 0.43.30 | 10 / 5 | |
| 0.43.29 | 10 / 5 | |
| 0.43.28 | 10 / 5 | |
| 0.43.27 | 10 / 5 | |
| 0.43.26 | 10 / 5 | |
| 0.43.25 | 10 / 5 | |
| 0.43.24 | 10 / 5 | |
| 0.43.23 | 10 / 5 | |
| 0.43.22 | 10 / 5 | |
| 0.43.21 | 10 / 5 | |
| 0.43.20 | 10 / 5 | |
| 0.43.19 | 10 / 5 | |
| 0.43.18 | 10 / 5 | |
| 0.43.17 | 10 / 5 | |
| 0.43.16 | 10 / 5 | |
| 0.43.15 | 10 / 5 | |
| 0.43.14 | 10 / 5 | |
| 0.43.13 | 10 / 5 | |
| 0.43.12 | 10 / 5 | |
| 0.43.11 | 10 / 5 | |
| 0.43.10 | 10 / 5 | |
| 0.43.9 | 10 / 5 | |
| 0.43.8 | 10 / 5 | |
| 0.43.7 | 10 / 5 | |
| 0.43.5 | 10 / 5 | |
| 0.43.4 | 10 / 5 | |
| 0.43.3 | 10 / 5 | |
| 0.43.2 | 10 / 5 | |
| 0.43.1 | 10 / 5 | |
| 0.43.0 | 10 / 5 | |
| 0.42.41 | 32 / 7 | |
| 0.42.40 | 32 / 7 | |
| 0.42.39 | 32 / 7 | |
| 0.42.38 | 32 / 7 | |
| 0.42.37 | 32 / 7 | |
| 0.42.36 | 32 / 7 | |
| 0.42.35 | 32 / 7 | |
| 0.42.34 | 31 / 7 | |
| 0.42.33 | 29 / 7 | |
| 0.42.32 | 29 / 8 | |
| 0.42.31 | 29 / 8 | |
| 0.42.30 | 29 / 17 | |
| 0.42.29 | 29 / 19 | |
| 0.42.28 | 29 / 19 | |
| 0.42.27 | 29 / 19 | |
| 0.42.26 | 29 / 19 | |
| 0.42.25 | 29 / 19 | |
| 0.42.24 | 29 / 19 | |
| 0.42.23 | 29 / 19 | |
| 0.42.22 | 29 / 19 | |
| 0.42.21 | 29 / 19 | |
| 0.42.20 | 29 / 19 | |
| 0.42.19 | 29 / 19 | |
| 0.42.18 | 29 / 19 |
v0.47.19
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.47.13
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.42.40
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.42.38
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.42.37
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.42.35
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.42.33
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.42.32
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.42.31
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.42.30
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.42.29
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.42.26
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.42.25
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.42.24
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.42.19
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.