← Home

@powerlines/plugin-date

A package containing a Powerlines plugin for injecting static .env configuration values to the code so that they're accessible at runtime.

100
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

stormie-botsullivanpj

Keywords

powerlinesstorm-softwarepowerlines-plugin

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Publisher changed from stormie-bot to GitHub Actions with SLSA provenance attestation — this is a supply chain improvement (CI/CD automation), not a compromise indicator. ai
source-diff obfuscated-file:dist/deepkit/src/capnp.cjs AI (source-diff): Minified rolldown bundle output, not obfuscated malware. Code handles Cap'n Proto serialization for type reflection — legitimate build artifact for this package. ai
source-diff obfuscated-file:dist/alloy/src/create-plugin.cjs AI (source-diff): Minified rolldown bundle output. Code implements plugin creation with @alloy-js code generation — consistent with package purpose. ai
source-diff obfuscated-file:dist/plugin-env/src/components/env.cjs AI (source-diff): Minified rolldown bundle output. Code generates TypeScript env interfaces — legitimate build artifact. ai
source-diff obfuscated-file:dist/plugin-env/src/index.cjs AI (source-diff): Minified rolldown bundle output. Code implements env plugin configuration — legitimate build artifact. ai
source-diff obfuscated-file:dist/plugin-env/src/helpers/persistence.cjs AI (source-diff): Minified rolldown bundle output. Code handles Cap'n Proto serialization for env type persistence — legitimate build artifact. ai
source-diff obfuscated-file:dist/plugin-env/src/helpers/reflect.cjs AI (source-diff): Minified rolldown bundle output. Code creates reflection classes for env/secrets configuration — legitimate build artifact. ai
source-diff obfuscated-file:dist/deepkit/schemas/reflection.cjs AI (source-diff): Minified rolldown bundle output. Code defines Cap'n Proto struct classes for type reflection schemas — legitimate build artifact. ai
source-diff obfuscated-file:dist/deepkit/schemas/reflection2.cjs AI (source-diff): Minified rolldown bundle output. Code defines Cap'n Proto struct classes (updated version) — legitimate build artifact. ai
phantom-deps phantom-dep:@stryke/path AI (phantom-deps): Declared dependency referenced in config files; typical for monorepo build tooling. ai
phantom-deps phantom-dep:@powerlines/plugin-env AI (phantom-deps): Same-org scoped dependency; legitimate for plugin ecosystem integration. ai
phantom-deps phantom-dep:@storm-software/config-tools AI (phantom-deps): Declared dependency referenced in config files; expected for Storm Software monorepo packages. ai
phantom-deps phantom-dep:powerlines AI (phantom-deps): Legitimate dependency for Powerlines plugin; referenced in config and used indirectly through plugin system. ai
dependencies unvetted-dep:powerlines AI (dependencies): Part of the same Storm Software/Powerlines monorepo ecosystem; sibling package not yet greenflagged, not an independent risk. ai
dependencies unvetted-dep:@powerlines/plugin-env AI (dependencies): Sibling package in the same @powerlines monorepo; unvetted only because it hasn't been greenflagged yet, not due to independent risk. ai
dependencies unvetted-dep:@storm-software/config-tools AI (dependencies): Storm Software ecosystem package; consistent organizational identity across all findings, not an independent risk signal. ai
dependencies unvetted-dep:@stryke/path AI (dependencies): Storm Software ecosystem package (@stryke scope); consistent organizational identity, not an independent risk signal. ai

Versions (showing 100 of 373)

Version Deps Published
0.12.465 5 / 2
0.12.464 5 / 2
0.12.463 5 / 2
0.12.462 5 / 2
0.12.461 5 / 2
0.12.460 5 / 2
0.12.459 5 / 2
0.12.458 5 / 2
0.12.457 5 / 2
0.12.456 5 / 2
0.12.455 5 / 2
0.12.454 5 / 2
0.12.453 5 / 2
0.12.452 5 / 2
0.12.451 5 / 2
0.12.450 5 / 2
0.12.449 5 / 2
0.12.448 5 / 2
0.12.447 5 / 2
0.12.446 5 / 2
0.12.445 5 / 2
0.12.444 5 / 2
0.12.443 5 / 2
0.12.442 5 / 2
0.12.441 5 / 2
0.12.440 5 / 2
0.12.439 5 / 2
0.12.438 5 / 2
0.12.437 5 / 2
0.12.432 5 / 2
0.12.430 5 / 2
0.12.426 5 / 2
0.12.424 5 / 2
0.12.410 5 / 2
0.12.409 5 / 2
0.12.406 5 / 2
0.12.401 4 / 2
0.12.400 4 / 2
0.12.399 4 / 2
0.12.397 4 / 2
0.12.396 4 / 2
0.12.395 4 / 2
0.12.309 4 / 2
0.12.300 4 / 2
0.12.299 4 / 2
0.12.298 4 / 2
0.12.297 4 / 2
0.12.296 4 / 2
0.12.295 4 / 2
0.12.294 4 / 2
0.12.293 4 / 2
0.12.292 4 / 2
0.12.291 4 / 2
0.12.290 4 / 2
0.12.289 4 / 2
0.12.288 4 / 2
0.12.287 4 / 2
0.12.286 4 / 2
0.12.285 4 / 2
0.12.284 4 / 2
0.12.283 4 / 2
0.12.282 4 / 2
0.12.281 4 / 2
0.12.280 4 / 2
0.12.279 4 / 2
0.12.278 4 / 2
0.12.277 4 / 2
0.12.276 4 / 2
0.12.275 4 / 2
0.12.274 4 / 2
0.12.272 4 / 2
0.12.271 4 / 2
0.12.270 4 / 2
0.12.269 4 / 2
0.12.268 4 / 2
0.12.267 4 / 2
0.12.266 4 / 2
0.12.265 4 / 2
0.12.264 4 / 2
0.12.263 4 / 2
0.12.262 4 / 2
0.12.261 4 / 2
0.12.205 4 / 2
0.12.200 4 / 2
0.12.194 4 / 2
0.12.193 4 / 2
0.12.174 4 / 2
0.12.160 4 / 2
0.12.153 4 / 2
0.12.147 4 / 2
0.12.143 4 / 2
0.12.142 4 / 2
0.12.138 4 / 2
0.12.118 4 / 2
0.12.116 4 / 2
0.12.109 4 / 2
0.12.107 4 / 2
0.12.56 4 / 3
0.12.55 4 / 3
0.12.54 4 / 3
Showing 100 of 373 Next page →

v0.12.109

10 findings
HIGH Publisher changed: stormie-bot → GitHub Actions (on 2025-12-23) provenance

This version was published by a different npm account than previous versions on 2025-12-23. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/deepkit/src/capnp.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/alloy/src/create-plugin.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/plugin-env/src/components/env.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/plugin-env/src/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/plugin-env/src/helpers/persistence.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/plugin-env/src/helpers/reflect.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/deepkit/schemas/reflection.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/deepkit/schemas/reflection2.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.56

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.55

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.54

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.