← Home

powerlines

The "framework framework" that simplifies modern dev tool usage, generates virtual (or actual) code modules, and improves DX across the board.

100
Versions
Apache-2.0
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures gitHead linked

Maintainers

stormie-bot

Keywords

powerlinesstorm-softwareunplugintypescriptdotenvbabelesbuildunbuildnuxtviterolluprspackwebpackastro

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:bin/prompts-Cb5cSsjg.mjs AI (source-diff): Bundled CLI output (esbuild-style), not true obfuscation; no malicious behavior in sample. ai
source-diff obfuscated-file:bin/prompts-BLU5Njeg.mjs AI (source-diff): Minified bundled CLI output, not true obfuscation; no malicious behavior found. ai
source-diff obfuscated-file:bin/prompts-D2lN84PY.mjs AI (source-diff): Bundled tsup/esbuild CLI output, not true obfuscation. ai
source-diff obfuscated-file:bin/prompts-rJ8Zkvkh.mjs AI (source-diff): Bundled CLI output, not true obfuscation; consistent with package's build tooling. ai
source-diff obfuscated-file:bin/prompts-D_Rv-lNz.mjs AI (source-diff): Bundled chunk, minified build output not true obfuscation. ai
source-diff obfuscated-file:bin/bin.mjs AI (source-diff): Bundled CLI entry, minified build output not true obfuscation. ai
phantom-deps phantom-dep:typedoc-plugin-frontmatter AI (phantom-deps): Config-referenced plugin, not a code-import; benign for this doc-tooling package. ai
source-diff large-new-source-files AI (source-diff): Bin directory restructure/bundling, no malicious behavior observed. ai
source-diff obfuscated-file:bin/prompts-DEjU8qNL.mjs AI (source-diff): Bundled esbuild output for CLI, not true obfuscation. ai
source-diff source-size-tripled AI (source-diff): Result of bundling more CLI subcommands into bin/, not injected payload. ai
install-scripts install-script:postinstall AI (install-scripts): Patches TS compiler for deepkit type transformer; documented build-tool behavior, no exfil/fetch. ai
install-scripts install-script:install AI (install-scripts): Removes bundled typescript dep, known deepkit/type-compiler workaround pattern. ai
phantom-deps phantom-dep:@powerlines/plugin-unbuild AI (phantom-deps): Config-referenced tool; stable pattern for this framework package. ai
phantom-deps phantom-dep:@stryke/string-format AI (phantom-deps): Config-referenced tool; stable pattern for this framework package. ai
phantom-deps phantom-dep:compatx AI (phantom-deps): Config-referenced tool; stable pattern for this framework package. ai
phantom-deps phantom-dep:undici AI (phantom-deps): Known implicit runtime dependency; stable for this package. ai
phantom-deps phantom-dep:jiti AI (phantom-deps): Config-referenced tool; stable pattern for this framework package. ai
phantom-deps phantom-dep:@donedeal0/superdiff AI (phantom-deps): Config-referenced tool; stable pattern for this framework package. ai
phantom-deps phantom-dep:@stryke/unique-id AI (phantom-deps): Config-referenced tool; stable pattern for this framework package. ai
phantom-deps phantom-dep:bundle-require AI (phantom-deps): Config-referenced tool; stable pattern for this framework package. ai
phantom-deps phantom-dep:@stryke/capnp AI (phantom-deps): Config-referenced tool; stable pattern for this framework package. ai
phantom-deps phantom-dep:@stryke/json AI (phantom-deps): Config-referenced tool; stable pattern for this framework package. ai
phantom-deps phantom-dep:@stryke/http AI (phantom-deps): Config-referenced tool; stable pattern for this framework package. ai
phantom-deps phantom-dep:@stryke/hash AI (phantom-deps): Config-referenced tool; stable pattern for this framework package. ai
phantom-deps phantom-dep:oxc-parser AI (phantom-deps): Config-referenced tool; stable pattern for this framework package. ai
phantom-deps phantom-dep:flat-cache AI (phantom-deps): Config-referenced tool; stable pattern for this framework package. ai
phantom-deps phantom-dep:ts-morph AI (phantom-deps): Config-referenced tool; stable pattern for this framework package. ai
dependencies unvetted-dep:@power-plant/schema AI (dependencies): Sibling first-party scoped package in same monorepo ecosystem, low risk. ai
phantom-deps phantom-dep:@jridgewell/sourcemap-codec AI (phantom-deps): Config-referenced dep; stable FP for this package. ai
phantom-deps phantom-dep:locate-character AI (phantom-deps): Config-referenced dep; stable FP for this package. ai
phantom-deps phantom-dep:@stryke/env AI (phantom-deps): First-party @stryke scoped dep; stable false positive for this package. ai
phantom-deps phantom-dep:@storm-software/config-tools AI (phantom-deps): First-party @storm-software scoped dep; stable false positive for this package. ai
phantom-deps phantom-dep:@stryke/fs AI (phantom-deps): First-party @stryke scoped dep; stable false positive for this package. ai
phantom-deps phantom-dep:unplugin AI (phantom-deps): Declared dep; used indirectly via @powerlines/unplugin integration layer. ai
phantom-deps phantom-dep:defu AI (phantom-deps): Declared in package.json deps; likely re-exported or used indirectly via sub-packages in this monorepo. ai
phantom-deps phantom-dep:@stryke/convert AI (phantom-deps): First-party @stryke scoped dep; stable false positive for this package. ai
source-diff obfuscated-file:dist/plugin-utils.d.cts AI (source-diff): File is a TypeScript declaration file with long bundled import lines, not obfuscated executable code. ai
provenance publisher-changed AI (provenance): Publisher changed to GitHub Actions with SLSA provenance attestation; legitimate CI/CD migration for this org. ai
phantom-deps phantom-dep:@babel/plugin-transform-export-namespace-from AI (phantom-deps): Framework-scoped Babel plugin; loaded by convention in build tools. ai
phantom-deps phantom-dep:@babel/plugin-syntax-jsx AI (phantom-deps): Framework-scoped Babel plugin; loaded by convention in build tools. ai
phantom-deps phantom-dep:@babel/preset-typescript AI (phantom-deps): Framework-scoped Babel preset; loaded by convention in build tools. ai
phantom-deps phantom-dep:@babel/helper-simple-access AI (phantom-deps): Framework-scoped Babel helper; loaded by convention in build tools. ai
phantom-deps phantom-dep:@babel/helper-module-imports AI (phantom-deps): Framework-scoped Babel helper; loaded by convention in build tools. ai
phantom-deps phantom-dep:@babel/helper-module-transforms AI (phantom-deps): Framework-scoped Babel helper; loaded by convention in build tools. ai
phantom-deps phantom-dep:@babel/plugin-syntax-typescript AI (phantom-deps): Framework-scoped Babel plugin; loaded by convention in build tools. ai
phantom-deps phantom-dep:@babel/plugin-proposal-decorators AI (phantom-deps): Framework-scoped Babel plugin; loaded by convention in build tools. ai
phantom-deps phantom-dep:@babel/plugin-transform-react-jsx AI (phantom-deps): Framework-scoped Babel plugin; loaded by convention in build tools. ai
phantom-deps phantom-dep:@babel/plugin-transform-typescript AI (phantom-deps): Framework-scoped Babel plugin; loaded by convention in build tools. ai
phantom-deps phantom-dep:@babel/plugin-syntax-class-properties AI (phantom-deps): Framework-scoped Babel plugin; loaded by convention in build tools. ai
phantom-deps phantom-dep:@babel/plugin-syntax-import-assertions AI (phantom-deps): Framework-scoped Babel plugin; loaded by convention in build tools. ai
phantom-deps phantom-dep:@storm-software/esbuild AI (phantom-deps): Config-referenced tool; stable pattern for this build-tool framework. ai
phantom-deps phantom-dep:@babel/parser AI (phantom-deps): powerlines is a build framework that loads Babel plugins by convention; phantom Babel deps are expected and stable across versions. ai
dependencies unvetted-dep:babel-plugin-parameter-decorator AI (dependencies): Well-known Babel plugin for TypeScript decorator support; no security concerns for this build framework. ai
dependencies unvetted-dep:@storm-software/esbuild AI (dependencies): First-party Storm Software package from the same publisher org with 233 approved packages; stable for this package. ai
dependencies unvetted-dep:@storm-software/tsup AI (dependencies): First-party Storm Software package from the same publisher org with 233 approved packages; stable for this package. ai
phantom-deps phantom-dep:@alloy-js/babel-plugin-jsx-dom-expressions AI (phantom-deps): Config-referenced package for this build framework; phantom dep pattern is stable. ai
phantom-deps phantom-dep:babel-dead-code-elimination AI (phantom-deps): Config-referenced Babel plugin for this build framework; phantom dep pattern is stable. ai
phantom-deps phantom-dep:babel-plugin-parameter-decorator AI (phantom-deps): Config-referenced Babel plugin for this build framework; phantom dep pattern is stable. ai
phantom-deps phantom-dep:github-slugger AI (phantom-deps): Config-referenced package for this build framework; phantom dep pattern is stable. ai
phantom-deps phantom-dep:nanotar AI (phantom-deps): Config-referenced package for this build framework; phantom dep pattern is stable. ai
phantom-deps phantom-dep:@typescript-eslint/utils AI (phantom-deps): Config-referenced package for this build framework; phantom dep pattern is stable. ai
phantom-deps phantom-dep:@microsoft/api-extractor AI (phantom-deps): Config-referenced package for this build framework; phantom dep pattern is stable. ai
phantom-deps phantom-dep:@microsoft/tsdoc-config AI (phantom-deps): Config-referenced package for this build framework; phantom dep pattern is stable. ai
phantom-deps phantom-dep:@alloy-js/babel-preset AI (phantom-deps): Config-referenced package for this build framework; phantom dep pattern is stable. ai
phantom-deps phantom-dep:@alloy-js/babel-plugin AI (phantom-deps): Config-referenced package for this build framework; phantom dep pattern is stable. ai
phantom-deps phantom-dep:@babel/generator AI (phantom-deps): Framework-scoped Babel package loaded by convention; expected for this build framework. ai
phantom-deps phantom-dep:@babel/template AI (phantom-deps): Framework-scoped Babel package loaded by convention; expected for this build framework. ai
dependencies unvetted-dep:handlebars AI (dependencies): Handlebars is a well-known templating library used legitimately in this code-generation framework. Constraint ^4.7.8 starts at a patched version past known prototype pollution CVEs. ai
phantom-deps phantom-dep:oxc-resolver AI (phantom-deps): oxc-resolver is a runtime dep used via dynamic/config-driven loading in this plugin framework; not directly imported but legitimately declared. ai
phantom-deps phantom-dep:@cacheable/memory AI (phantom-deps): @cacheable/memory is a runtime dep used via dynamic/config-driven loading in this plugin framework; not directly imported but legitimately declared. ai
phantom-deps phantom-dep:unimport AI (phantom-deps): unimport is a runtime dep used via dynamic/config-driven loading in this plugin framework; not directly imported but legitimately declared. ai
dependencies unvetted-dep:@stryke/env AI (dependencies): @stryke/* packages are first-party Storm Software org packages, consistent with monorepo publishing pattern for this package family. ai
phantom-deps phantom-dep:@storm-software/config AI (phantom-deps): Referenced in config files but not directly imported is expected behavior for a config package in a monorepo build tool context. ai
phantom-deps phantom-dep:@babel/types AI (phantom-deps): @babel/types is a well-known package loaded by convention in build tooling; phantom dep finding is expected for this type of framework package. ai
dependencies unvetted-dep:@storm-software/config-tools AI (dependencies): @storm-software/* packages are first-party Storm Software org packages, consistent with monorepo publishing pattern. ai
dependencies unvetted-dep:@storm-software/config AI (dependencies): @storm-software/* packages are first-party Storm Software org packages, consistent with monorepo publishing pattern. ai
dependencies unvetted-dep:@powerlines/engine AI (dependencies): @powerlines/* packages are first-party packages from the same Storm Software monorepo as powerlines itself. ai
dependencies unvetted-dep:@powerlines/core AI (dependencies): @powerlines/* packages are first-party packages from the same Storm Software monorepo as powerlines itself. ai
dependencies unvetted-dep:@stryke/convert AI (dependencies): @stryke/* packages are first-party Storm Software org packages, consistent with monorepo publishing pattern for this package family. ai
dependencies unvetted-dep:@stryke/fs AI (dependencies): @stryke/* packages are first-party Storm Software org packages, consistent with monorepo publishing pattern for this package family. ai

Versions (showing 100 of 574)

Version Deps Published
0.37.41 72 / 19
0.37.40 72 / 19
0.37.38 72 / 19
0.37.37 72 / 19
0.37.36 72 / 19
0.37.35 72 / 19
0.37.34 72 / 19
0.37.33 72 / 19
0.37.32 72 / 19
0.37.31 72 / 19
0.37.30 72 / 19
0.37.29 72 / 19
0.37.28 72 / 19
0.37.27 72 / 19
0.37.26 72 / 19
0.37.25 72 / 19
0.37.24 72 / 19
0.37.23 72 / 19
0.37.22 72 / 19
0.37.21 72 / 19
0.37.20 72 / 19
0.37.19 72 / 19
0.37.18 72 / 19
0.37.17 72 / 19
0.37.16 72 / 19
0.37.15 72 / 19
0.37.14 72 / 19
0.37.13 72 / 19
0.37.12 72 / 19
0.37.11 72 / 19
0.37.10 72 / 19
0.37.9 72 / 19
0.37.8 72 / 19
0.37.7 72 / 19
0.37.6 72 / 19
0.37.5 72 / 19
0.37.4 72 / 19
0.37.3 72 / 19
0.37.2 72 / 19
0.37.1 72 / 19
0.37.0 72 / 19
0.36.29 71 / 17
0.36.28 71 / 17
0.36.27 71 / 17
0.36.26 71 / 17
0.36.25 71 / 17
0.36.24 71 / 17
0.36.23 71 / 17
0.36.22 71 / 17
0.36.21 71 / 17
0.36.20 71 / 17
0.36.19 71 / 17
0.36.18 71 / 17
0.36.17 71 / 17
0.36.16 71 / 17
0.36.15 71 / 17
0.36.14 71 / 17
0.36.13 71 / 17
0.36.12 70 / 17
0.36.11 70 / 17
0.36.10 70 / 17
0.36.9 70 / 17
0.36.8 70 / 17
0.36.7 70 / 17
0.36.6 71 / 17
0.36.5 71 / 17
0.36.4 71 / 17
0.36.3 71 / 17
0.36.2 71 / 17
0.36.1 71 / 17
0.36.0 71 / 17
0.35.2 71 / 17
0.35.1 71 / 17
0.35.0 71 / 17
0.34.9 71 / 17
0.34.8 71 / 17
0.34.7 71 / 17
0.34.6 71 / 17
0.34.5 71 / 17
0.34.4 71 / 17
0.34.3 71 / 17
0.34.2 71 / 17
0.34.1 71 / 17
0.34.0 71 / 17
0.33.2 71 / 17
0.33.1 71 / 17
0.33.0 71 / 17
0.32.8 71 / 17
0.32.7 71 / 17
0.32.6 71 / 17
0.32.5 71 / 17
0.32.4 71 / 17
0.32.3 71 / 17
0.32.2 71 / 17
0.32.1 71 / 17
0.32.0 71 / 17
0.31.6 71 / 17
0.31.5 71 / 17
0.31.4 71 / 17
0.31.3 71 / 17
Showing 100 of 574 Next page →

v0.37.41

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.37.40

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.37.38

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.37.37

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.37.36

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.37.35

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.37.34

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.37.33

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.37.32

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.37.31

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.37.30

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.37.29

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.37.28

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.37.27

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.37.26

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.37.25

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.37.24

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.37.23

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.37.22

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.37.21

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.37.20

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.37.19

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.37.18

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.37.17

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.37.16

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.37.15

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.37.14

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.37.13

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.37.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.37.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.37.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.37.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.37.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.37.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.37.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.37.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.37.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.37.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.37.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.37.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.36.29

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.36.28

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.36.27

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.36.26

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.36.25

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.36.24

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.36.23

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.36.22

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.36.21

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.36.20

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.36.19

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.36.18

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.36.17

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.36.16

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.36.13

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.36.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.36.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.36.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.36.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.36.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.36.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.36.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.36.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.36.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.36.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.36.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.36.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.35.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.35.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.35.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.34.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.34.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.34.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.34.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.34.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.34.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.34.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.34.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.33.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.33.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.33.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.32.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.32.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.32.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.32.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.32.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.32.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.32.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.32.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.32.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.31.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.31.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.31.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.31.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.