← Home

@tanstack/react-start-client

83
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

tannerlinsleytkdodoalemtuzlakkevinvandyschiller-manuel

Keywords

reactlocationrouterroutingasyncasync routertypescript

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:cookie-es AI (phantom-deps): Used in server-side config context; stable false positive for this package. ai
phantom-deps phantom-dep:jsesc AI (phantom-deps): Used in bundler/config context, not direct import; stable pattern for this package. ai
phantom-deps phantom-dep:vinxi AI (phantom-deps): vinxi is a build/runtime framework dependency used in config; not a direct import by design. ai
phantom-deps phantom-dep:tiny-warning AI (phantom-deps): tiny-warning is a declared dependency; phantom-dep detection is a low-signal finding with no security implication. ai
provenance publisher-changed AI (provenance): TanStack moved to GitHub Actions CI/CD publishing with SLSA provenance; this is a legitimate and expected transition for the project. ai
maintainer-change maintainer-added AI (maintainer-change): lachlancollins is a known TanStack collaborator/maintainer across multiple TanStack packages. ai
provenance slsa-provenance AI (provenance): TanStack packages are consistently published via CI with SLSA provenance; this is expected and stable for all versions of this package. ai

Versions (showing 83 of 384)

Version Deps Published
1.131.7 6 / 2
1.131.6 6 / 2
1.131.5 6 / 2
1.131.4 6 / 2
1.131.3 6 / 2
1.131.2 6 / 2
1.130.17 6 / 2
1.130.12 6 / 2
1.130.11 6 / 2
1.130.10 6 / 2
1.130.9 6 / 2
1.130.8 6 / 2
1.130.7 6 / 2
1.130.6 6 / 2
1.130.5 6 / 2
1.130.2 6 / 2
1.130.1 6 / 2
1.130.0 6 / 2
1.129.9 6 / 2
1.129.8 6 / 2
1.129.7 6 / 2
1.129.5 6 / 2
1.129.4 6 / 2
1.129.3 6 / 2
1.129.2 6 / 2
1.129.0 6 / 2
1.128.8 6 / 2
1.128.7 6 / 2
1.128.6 6 / 2
1.128.4 6 / 2
1.128.3 6 / 2
1.128.0 6 / 2
1.127.9 6 / 2
1.127.8 6 / 2
1.127.7 6 / 2
1.127.3 6 / 2
1.127.2 6 / 2
1.127.1 7 / 3
1.127.0 7 / 3
1.126.2 7 / 3
1.125.6 7 / 3
1.125.4 7 / 3
1.125.3 7 / 3
1.125.1 7 / 3
1.125.0 7 / 3
1.124.2 7 / 3
1.124.0 7 / 3
1.123.2 7 / 3
1.123.0 7 / 3
1.122.0 7 / 3
1.121.41 7 / 3
1.121.40 7 / 3
1.121.39 7 / 3
1.121.34 7 / 3
1.121.33 7 / 3
1.121.27 7 / 3
1.121.24 7 / 3
1.121.23 7 / 3
1.121.21 7 / 3
1.121.20 7 / 3
1.121.19 7 / 3
1.121.18 7 / 3
1.121.17 7 / 3
1.121.16 7 / 3
1.121.14 7 / 3
1.121.12 7 / 3
1.121.2 7 / 3
1.121.0 7 / 3
1.120.20 8 / 3
1.120.18 8 / 3
1.120.17 8 / 3
1.120.16 8 / 3
1.120.13 8 / 3
1.120.12 8 / 3
1.120.9 8 / 3
1.120.7 8 / 3
1.120.5 8 / 3
1.120.4 8 / 3
1.120.3 8 / 3
1.120.2 8 / 3
1.120.0 8 / 3
1.119.0 8 / 3
1.117.1 8 / 3

v1.131.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.130.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.128.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.127.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.122.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.121.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.120.16

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.