← Home

@powerlines/plugin-tsc

A package containing the TypeScript compiler plugin for Powerlines.

100
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

stormie-botsullivanpj

Keywords

tscpowerlinesstorm-softwarepowerlines-plugin

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance slsa-provenance AI (provenance): Package consistently publishes with SLSA provenance via Sigstore; this is a stable positive signal for this package. ai
provenance publisher-changed AI (provenance): Publisher changed from stormie-bot to GitHub Actions, consistent with legitimate migration to CI/CD publishing. SLSA provenance attestation confirms integrity. Stable pattern for this package going forward. ai
phantom-deps phantom-dep:defu AI (phantom-deps): defu is a declared runtime dependency; phantom detection is a false positive for this plugin package where indirect usage via config is expected. ai
phantom-deps phantom-dep:powerlines AI (phantom-deps): powerlines is a declared runtime dependency; phantom detection is a false positive for this plugin package that wraps the powerlines ecosystem. ai
dependencies unvetted-dep:powerlines AI (dependencies): powerlines is the core package of the same Storm Software ecosystem that @powerlines/plugin-tsc belongs to; an expected internal dependency, not a suspicious third-party one. ai
dependencies unvetted-dep:@stryke/path AI (dependencies): @stryke/path is a utility package from the same Storm Software org family; expected internal dependency for this ecosystem. ai

Versions (showing 100 of 473)

Version Deps Published
0.3.10 5 / 2
0.3.9 5 / 2
0.3.8 5 / 2
0.3.7 5 / 2
0.3.6 5 / 2
0.3.5 5 / 2
0.3.4 5 / 2
0.3.1 5 / 2
0.3.0 5 / 2
0.2.472 5 / 2
0.2.471 5 / 2
0.2.470 5 / 2
0.2.468 5 / 2
0.2.467 5 / 2
0.2.466 5 / 2
0.2.465 5 / 2
0.2.464 5 / 2
0.2.463 5 / 2
0.2.462 5 / 2
0.2.461 5 / 2
0.2.460 5 / 2
0.2.459 5 / 2
0.2.458 5 / 2
0.2.457 5 / 2
0.2.456 5 / 2
0.2.455 5 / 2
0.2.454 5 / 2
0.2.453 5 / 2
0.2.452 5 / 2
0.2.451 5 / 2
0.2.450 5 / 2
0.2.449 5 / 2
0.2.448 5 / 2
0.2.447 5 / 2
0.2.446 5 / 2
0.2.445 5 / 2
0.2.444 5 / 2
0.2.443 5 / 2
0.2.441 5 / 2
0.2.440 5 / 2
0.2.439 5 / 2
0.2.438 5 / 2
0.2.437 5 / 2
0.2.436 5 / 2
0.2.435 5 / 2
0.2.434 5 / 2
0.2.433 5 / 2
0.2.432 5 / 2
0.2.431 5 / 2
0.2.430 5 / 2
0.2.429 5 / 2
0.2.428 5 / 2
0.2.427 5 / 2
0.2.426 5 / 2
0.2.425 5 / 2
0.2.424 5 / 2
0.2.423 5 / 2
0.2.422 5 / 2
0.2.421 5 / 2
0.2.420 5 / 2
0.2.419 5 / 2
0.2.418 5 / 2
0.2.417 5 / 2
0.2.416 5 / 2
0.2.414 5 / 2
0.2.413 5 / 2
0.2.412 5 / 2
0.2.411 5 / 2
0.2.410 5 / 2
0.2.409 5 / 2
0.2.408 5 / 2
0.2.407 5 / 2
0.2.406 5 / 2
0.2.405 4 / 2
0.2.404 4 / 2
0.2.403 4 / 2
0.2.402 4 / 2
0.2.401 4 / 2
0.2.400 4 / 2
0.2.399 4 / 2
0.2.398 4 / 2
0.2.397 4 / 2
0.2.396 4 / 2
0.2.395 4 / 2
0.2.394 4 / 2
0.2.393 4 / 2
0.2.392 4 / 2
0.2.391 4 / 2
0.2.390 4 / 2
0.2.389 4 / 2
0.2.388 4 / 2
0.2.387 4 / 2
0.2.386 4 / 2
0.2.385 4 / 2
0.2.384 4 / 2
0.2.383 4 / 2
0.2.382 4 / 2
0.2.381 4 / 2
0.2.380 4 / 2
0.2.379 4 / 2
Showing 100 of 473 Next page →

v0.3.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.472

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.471

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.470

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.468

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.467

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.466

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.465

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.464

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.463

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.462

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.461

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.460

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.459

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.458

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.386

2 findings
HIGH Publisher changed: stormie-bot → GitHub Actions (on 2026-03-23) provenance

This version was published by a different npm account than previous versions on 2026-03-23. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.385

2 findings
HIGH Publisher changed: stormie-bot → GitHub Actions (on 2026-03-23) provenance

This version was published by a different npm account than previous versions on 2026-03-23. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.384

2 findings
HIGH Publisher changed: stormie-bot → GitHub Actions (on 2026-03-23) provenance

This version was published by a different npm account than previous versions on 2026-03-23. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.383

2 findings
HIGH Publisher changed: stormie-bot → GitHub Actions (on 2026-03-23) provenance

This version was published by a different npm account than previous versions on 2026-03-23. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.382

2 findings
HIGH Publisher changed: stormie-bot → GitHub Actions (on 2026-03-22) provenance

This version was published by a different npm account than previous versions on 2026-03-22. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.381

2 findings
HIGH Publisher changed: stormie-bot → GitHub Actions (on 2026-03-22) provenance

This version was published by a different npm account than previous versions on 2026-03-22. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.380

2 findings
HIGH Publisher changed: stormie-bot → GitHub Actions (on 2026-03-22) provenance

This version was published by a different npm account than previous versions on 2026-03-22. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.379

2 findings
HIGH Publisher changed: stormie-bot → GitHub Actions (on 2026-03-22) provenance

This version was published by a different npm account than previous versions on 2026-03-22. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.