← Home

@powerlines/plugin-rolldown

A package containing a Powerlines plugin to assist in developing other Powerlines plugins.

59
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

stormie-botsullivanpj

Keywords

rolldownpowerlinesstorm-softwarepowerlines-plugin

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@powerlines/unplugin AI (dependencies): Same org (@powerlines/storm-software); consistent with the package's own namespace and publishing pattern. ai
source-diff obfuscated-file:dist/unplugin-CLsmVZMo.cjs AI (source-diff): Standard minified bundle output for a build-tool plugin; no obfuscation or malicious payload present. ai
source-diff obfuscated-file:dist/index.mjs AI (source-diff): Standard minified bundle output for a build-tool plugin; no obfuscation or malicious payload present. ai
source-diff obfuscated-file:dist/unplugin-Rgj8lLxv.mjs AI (source-diff): Standard minified bundle output for a build-tool plugin; no obfuscation or malicious payload present. ai
phantom-deps phantom-dep:@stryke/helpers AI (phantom-deps): Internal org dep used in config files; stable false positive for this package. ai
phantom-deps phantom-dep:glob AI (phantom-deps): Declared as a runtime dep for config-level use; stable false positive for this package. ai
source-diff obfuscated-file:dist/powerlines/src/lib/contexts/api-context.mjs AI (source-diff): Minified ESM bundle output from rolldown; expected for a build tool plugin shipping compiled dist/ artifacts. ai
source-diff obfuscated-file:dist/powerlines/src/lib/contexts/api-context.cjs AI (source-diff): Minified CJS bundle output from rolldown; this is a rolldown plugin that ships bundled dist/ files. No malicious patterns in samples. ai
provenance publisher-changed AI (provenance): Transition from stormie-bot to GitHub Actions is an upgrade in CI/CD hygiene; SLSA provenance attestation confirms verified pipeline publishing. ai
source-diff obfuscated-file:dist/powerlines/src/internal/helpers/resolve-tsconfig.cjs AI (source-diff): Minified rolldown bundle output; TypeScript config resolution helpers. No malicious patterns. ai
source-diff obfuscated-file:dist/powerlines/src/lib/contexts/context.cjs AI (source-diff): Minified rolldown bundle output; standard plugin context implementation. No malicious patterns. ai
source-diff obfuscated-file:dist/powerlines/src/api.cjs AI (source-diff): Minified rolldown/rollup bundle output; code is readable JS with standard npm imports. No malicious patterns. SLSA provenance confirms CI/CD build. ai
source-diff obfuscated-file:dist/powerlines/src/lib/contexts/environment-context.cjs AI (source-diff): Minified rolldown bundle output; standard plugin environment context. No malicious patterns. ai
source-diff obfuscated-file:dist/powerlines/schemas/fs.cjs AI (source-diff): Minified rolldown bundle output; Cap'n Proto schema definitions. No malicious patterns. ai
source-diff obfuscated-file:dist/powerlines/src/lib/fs/vfs.cjs AI (source-diff): Minified rolldown bundle output; virtual filesystem implementation. No malicious patterns. ai
source-diff obfuscated-file:dist/powerlines/src/lib/build/rolldown.cjs AI (source-diff): Minified rolldown bundle output; build configuration helpers. No malicious patterns. ai
phantom-deps phantom-dep:@stryke/convert AI (phantom-deps): Utility dependency used in build configuration; phantom pattern is stable for this package. ai
phantom-deps phantom-dep:defu AI (phantom-deps): Legitimate build tool dependency used in plugin configuration; phantom pattern is expected for this package type. ai
phantom-deps phantom-dep:rolldown AI (phantom-deps): Core dependency for Rolldown plugin; referenced in build config rather than direct imports. ai
phantom-deps phantom-dep:unplugin AI (phantom-deps): Plugin framework dependency; used indirectly through plugin configuration. ai
phantom-deps phantom-dep:powerlines AI (phantom-deps): Parent framework dependency; referenced in plugin context rather than direct imports. ai
phantom-deps phantom-dep:@stryke/path AI (phantom-deps): Utility dependency used in build configuration; phantom pattern is stable for this package. ai
phantom-deps phantom-dep:@stryke/type-checks AI (phantom-deps): Utility dependency used in build configuration; phantom pattern is stable for this package. ai
dependencies unvetted-dep:@stryke/fs AI (dependencies): Same-org sibling package from Storm Software (@stryke scope); not a third-party unknown dependency. ai
phantom-deps phantom-dep:@powerlines/plugin-babel AI (phantom-deps): Same-org sibling package; indirect usage is expected in this plugin ecosystem. ai
phantom-deps phantom-dep:@stryke/types AI (phantom-deps): Same-org sibling package; type-only usage not directly imported is expected for type packages. ai
phantom-deps phantom-dep:@stryke/fs AI (phantom-deps): Same-org sibling package; indirect usage via config files is expected in this plugin ecosystem. ai
phantom-deps phantom-dep:jiti AI (phantom-deps): jiti is declared as a runtime dependency and used in config files; indirect usage pattern is normal for plugin ecosystems. ai
dependencies unvetted-dep:@powerlines/plugin-rollup AI (dependencies): Same-org sibling package from Storm Software (@powerlines scope); not a third-party unknown dependency. ai
dependencies unvetted-dep:@powerlines/plugin-babel AI (dependencies): Same-org sibling package from Storm Software (@powerlines scope); not a third-party unknown dependency. ai
dependencies unvetted-dep:@stryke/type-checks AI (dependencies): Same-org sibling package from Storm Software (@stryke scope); not a third-party unknown dependency. ai
dependencies unvetted-dep:@powerlines/core AI (dependencies): Same-org sibling package from Storm Software (@powerlines scope); not a third-party unknown dependency. ai
dependencies unvetted-dep:@stryke/convert AI (dependencies): Same-org sibling package from Storm Software (@stryke scope); not a third-party unknown dependency. ai
dependencies unvetted-dep:@stryke/types AI (dependencies): Same-org sibling package from Storm Software (@stryke scope); not a third-party unknown dependency. ai
dependencies unvetted-dep:@stryke/path AI (dependencies): Same-org sibling package from Storm Software (@stryke scope); not a third-party unknown dependency. ai

Versions (showing 59 of 463)

Version Deps Published
0.7.51 10 / 3
0.7.50 10 / 3
0.7.49 10 / 3
0.7.48 10 / 3
0.7.47 10 / 3
0.7.46 10 / 3
0.7.45 10 / 3
0.7.44 10 / 3
0.7.43 10 / 3
0.7.42 10 / 3
0.7.41 10 / 3
0.7.40 10 / 3
0.7.39 10 / 3
0.7.38 10 / 3
0.7.37 10 / 3
0.7.36 10 / 3
0.7.35 10 / 3
0.7.33 10 / 3
0.7.32 10 / 3
0.7.31 10 / 3
0.7.30 10 / 3
0.7.29 10 / 3
0.7.28 10 / 3
0.7.25 10 / 3
0.7.24 10 / 3
0.7.23 10 / 3
0.7.22 10 / 3
0.7.21 10 / 3
0.7.20 10 / 3
0.7.19 10 / 3
0.7.18 10 / 3
0.7.17 10 / 3
0.7.16 10 / 3
0.7.15 10 / 3
0.7.14 10 / 3
0.7.13 10 / 3
0.7.12 10 / 3
0.7.11 10 / 3
0.7.10 10 / 3
0.7.9 10 / 3
0.7.8 10 / 3
0.7.7 10 / 3
0.7.6 10 / 3
0.7.5 10 / 3
0.7.4 10 / 3
0.7.3 10 / 3
0.7.2 10 / 3
0.7.1 10 / 3
0.7.0 10 / 3
0.6.3 10 / 3
0.6.2 10 / 3
0.6.1 10 / 3
0.6.0 10 / 3
0.5.0 10 / 3
0.4.1 10 / 3
0.4.0 10 / 3
0.3.1 10 / 3
0.3.0 10 / 3
0.2.0 10 / 3

v0.7.51

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.50

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.49

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.48

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.47

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.46

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.45

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.44

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.43

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.42

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.41

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.40

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.39

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.38

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.37

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.36

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.35

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.33

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.32

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.31

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.30

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.29

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.28

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.25

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.24

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.23

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.22

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.21

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.20

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.19

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.18

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.17

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.16

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.15

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.13

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.