@powerlines/plugin-unbuild
A package containing a Powerlines plugin to build projects using Unbuild.
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): stormie-bot is the Storm Software CI bot with 2775 approved packages; transition from GitHub Actions is expected automation account usage. | ai | |
| phantom-deps | phantom-dep:@stryke/helpers | AI (phantom-deps): Sibling org package used in config files; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@powerlines/unplugin | AI (phantom-deps): Same-org dependency; phantom detection is a false positive for this build-tool wrapper pattern. | ai | |
| dependencies | unvetted-dep:@storm-software/unbuild | AI (dependencies): @storm-software/unbuild is a first-party Storm Software dependency consistent with this package's purpose as a build plugin wrapper. Stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:powerlines | AI (phantom-deps): Build plugin pattern; deps referenced in config files passed to consumers rather than directly imported. Stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@stryke/types | AI (phantom-deps): Build plugin pattern; deps referenced in config files passed to consumers rather than directly imported. Stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@stryke/type-checks | AI (phantom-deps): Build plugin pattern; deps referenced in config files passed to consumers rather than directly imported. Stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@storm-software/unbuild | AI (phantom-deps): Intra-org dependency from same Storm Software organization; referenced in config files. Stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@stryke/path | AI (phantom-deps): Build plugin pattern; deps referenced in config files passed to consumers rather than directly imported. Stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:defu | AI (phantom-deps): Build plugin pattern; deps referenced in config files passed to consumers rather than directly imported. Stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:jiti | AI (phantom-deps): Build plugin pattern; deps referenced in config files passed to consumers rather than directly imported. Stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@stryke/fs | AI (phantom-deps): Build plugin pattern; deps referenced in config files passed to consumers rather than directly imported. Stable false positive for this package. | ai | |
| dependencies | unvetted-dep:@powerlines/plugin-rollup | AI (dependencies): Sibling package within the same Storm Software/powerlines monorepo; published via the same CI/CD pipeline with SLSA provenance. Not an independent supply chain risk. | ai | |
| dependencies | unvetted-dep:@powerlines/core | AI (dependencies): Sibling package within the same Storm Software/powerlines monorepo; published via the same CI/CD pipeline with SLSA provenance. Not an independent supply chain risk. | ai | |
| phantom-deps | phantom-dep:unplugin | AI (phantom-deps): unplugin is a declared runtime dep used in the plugin architecture; phantom detection is a false positive for this package's plugin pattern. | ai |
Versions (showing 100 of 579)
| Version | Deps | Published |
|---|---|---|
| 0.5.375 | 7 / 2 | |
| 0.5.374 | 7 / 2 | |
| 0.5.373 | 7 / 2 | |
| 0.5.372 | 7 / 2 | |
| 0.5.371 | 7 / 2 | |
| 0.5.370 | 7 / 2 | |
| 0.5.369 | 7 / 2 | |
| 0.5.368 | 7 / 2 | |
| 0.5.366 | 7 / 2 | |
| 0.5.365 | 7 / 2 | |
| 0.5.364 | 7 / 2 | |
| 0.5.363 | 7 / 2 | |
| 0.5.362 | 7 / 2 | |
| 0.5.361 | 7 / 2 | |
| 0.5.358 | 7 / 2 | |
| 0.5.357 | 7 / 2 | |
| 0.5.356 | 7 / 2 | |
| 0.5.355 | 7 / 2 | |
| 0.5.354 | 7 / 2 | |
| 0.5.353 | 7 / 2 | |
| 0.5.352 | 7 / 2 | |
| 0.5.351 | 7 / 2 | |
| 0.5.350 | 7 / 2 | |
| 0.5.349 | 7 / 2 | |
| 0.5.348 | 7 / 2 | |
| 0.5.347 | 7 / 2 | |
| 0.5.346 | 7 / 2 | |
| 0.5.345 | 7 / 2 | |
| 0.5.344 | 7 / 2 | |
| 0.5.343 | 7 / 2 | |
| 0.5.342 | 7 / 2 | |
| 0.5.340 | 7 / 2 | |
| 0.5.339 | 7 / 2 | |
| 0.5.338 | 7 / 2 | |
| 0.5.337 | 7 / 2 | |
| 0.5.336 | 7 / 2 | |
| 0.5.335 | 7 / 2 | |
| 0.5.334 | 7 / 2 | |
| 0.5.333 | 7 / 2 | |
| 0.5.332 | 7 / 2 | |
| 0.5.331 | 7 / 2 | |
| 0.5.330 | 7 / 2 | |
| 0.5.329 | 7 / 2 | |
| 0.5.328 | 7 / 2 | |
| 0.5.327 | 7 / 2 | |
| 0.5.326 | 7 / 2 | |
| 0.5.325 | 7 / 2 | |
| 0.5.324 | 7 / 2 | |
| 0.5.323 | 7 / 2 | |
| 0.5.322 | 7 / 2 | |
| 0.5.321 | 7 / 2 | |
| 0.5.320 | 7 / 2 | |
| 0.5.319 | 7 / 2 | |
| 0.5.318 | 7 / 2 | |
| 0.5.317 | 7 / 2 | |
| 0.5.316 | 7 / 2 | |
| 0.5.315 | 7 / 2 | |
| 0.5.314 | 7 / 2 | |
| 0.5.313 | 7 / 2 | |
| 0.5.312 | 7 / 2 | |
| 0.5.311 | 7 / 2 | |
| 0.5.310 | 7 / 2 | |
| 0.5.309 | 7 / 2 | |
| 0.5.308 | 7 / 2 | |
| 0.5.307 | 7 / 2 | |
| 0.5.306 | 6 / 2 | |
| 0.5.305 | 6 / 2 | |
| 0.5.304 | 6 / 2 | |
| 0.5.303 | 6 / 2 | |
| 0.5.302 | 7 / 1 | |
| 0.5.301 | 7 / 1 | |
| 0.5.300 | 2 / 2 | |
| 0.5.299 | 2 / 2 | |
| 0.5.298 | 2 / 2 | |
| 0.5.297 | 2 / 2 | |
| 0.5.296 | 2 / 2 | |
| 0.5.295 | 2 / 2 | |
| 0.5.294 | 2 / 2 | |
| 0.5.293 | 2 / 2 | |
| 0.5.292 | 2 / 2 | |
| 0.5.291 | 2 / 2 | |
| 0.5.290 | 2 / 2 | |
| 0.5.289 | 2 / 2 | |
| 0.5.288 | 2 / 2 | |
| 0.5.287 | 2 / 2 | |
| 0.5.286 | 2 / 2 | |
| 0.5.285 | 2 / 2 | |
| 0.5.284 | 2 / 2 | |
| 0.5.283 | 2 / 2 | |
| 0.5.282 | 2 / 2 | |
| 0.5.281 | 2 / 2 | |
| 0.5.280 | 2 / 2 | |
| 0.5.279 | 2 / 2 | |
| 0.5.278 | 2 / 2 | |
| 0.5.277 | 2 / 2 | |
| 0.5.276 | 2 / 2 | |
| 0.5.275 | 2 / 2 | |
| 0.5.274 | 2 / 2 | |
| 0.5.273 | 2 / 2 | |
| 0.5.272 | 2 / 2 |
v0.5.375
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.374
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.373
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.371
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.370
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.368
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.366
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.365
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.363
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.361
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.358
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.357
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.356
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.355
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.354
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.353
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.352
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.351
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.350
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.349
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.348
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.347
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.346
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.345
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.344
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.343
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.340
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.339
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.338
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.337
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.336
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.335
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.334
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.333
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.331
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.330
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.329
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.328
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.327
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.326
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.325
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.324
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.323
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.322
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.321
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.320
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.319
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.317
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.316
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.315
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.314
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.313
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.312
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.309
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.308
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.307
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.306
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.305
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.