← Home

@tanstack/react-start

100
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

tannerlinsleytkdodoalemtuzlakkevinvandyschiller-manuel

Keywords

reactlocationrouterroutingasyncasync routertypescript

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@tanstack/react-start-plugin AI (dependencies): First-party sibling package from TanStack monorepo; pinned to same release version. ai
dependencies unvetted-dep:@tanstack/start-server-functions-handler AI (dependencies): First-party TanStack monorepo sub-package; stable pattern across releases. ai
dependencies unvetted-dep:@tanstack/react-start-router-manifest AI (dependencies): First-party TanStack monorepo sub-package; stable pattern across releases. ai
dependencies unvetted-dep:@tanstack/start-server-functions-client AI (dependencies): First-party TanStack monorepo sub-package; stable pattern across releases. ai
dependencies unvetted-dep:@tanstack/start-server-functions-server AI (dependencies): First-party TanStack monorepo sub-package; stable pattern across releases. ai
dependencies unvetted-dep:@tanstack/start-api-routes AI (dependencies): First-party TanStack monorepo sub-package; stable pattern across releases. ai
dependencies unvetted-dep:@tanstack/react-start-config AI (dependencies): First-party TanStack monorepo sub-package; stable pattern across releases. ai
dependencies unvetted-dep:@tanstack/start-server-functions-ssr AI (dependencies): First-party TanStack monorepo sub-package; stable pattern across releases. ai
maintainer-change maintainer-added AI (maintainer-change): lachlancollins is a known TanStack collaborator; adding maintainers to a mature project is expected. ai
provenance publisher-changed AI (provenance): Transition from manual (tannerlinsley) to CI/CD (GitHub Actions) publishing with SLSA provenance. This is a security improvement, not a risk. ai
phantom-deps phantom-dep:@tanstack/router-utils AI (phantom-deps): Same-org sibling package from TanStack monorepo; phantom dep status is a packaging detail, not a security concern for this well-attested package. ai

Versions (showing 100 of 438)

Version Deps Published
1.166.9 8 / 0
1.166.8 8 / 0
1.166.7 8 / 0
1.166.6 8 / 0
1.166.4 8 / 0
1.166.3 8 / 0
1.166.2 8 / 0
1.166.1 8 / 0
1.166.0 8 / 0
1.165.0 8 / 0
1.164.1 8 / 0
1.164.0 8 / 0
1.163.5 8 / 0
1.163.4 8 / 0
1.163.3 8 / 0
1.163.2 8 / 0
1.163.1 8 / 0
1.163.0 8 / 0
1.162.9 8 / 0
1.162.8 8 / 0
1.162.7 8 / 0
1.162.6 8 / 0
1.162.5 8 / 0
1.162.4 8 / 0
1.162.3 8 / 0
1.162.2 8 / 0
1.162.1 8 / 0
1.162.0 8 / 0
1.161.4 8 / 0
1.161.3 8 / 0
1.161.1 8 / 0
1.161.0 8 / 0
1.160.2 8 / 0
1.160.1 8 / 0
1.160.0 8 / 0
1.159.14 8 / 0
1.159.13 8 / 0
1.159.12 8 / 0
1.159.11 8 / 0
1.159.10 8 / 0
1.159.9 8 / 0
1.159.8 8 / 0
1.159.7 8 / 0
1.159.6 8 / 0
1.159.5 8 / 0
1.159.4 8 / 0
1.159.3 8 / 0
1.159.2 8 / 0
1.159.0 8 / 0
1.158.4 8 / 0
1.158.3 8 / 0
1.158.2 8 / 0
1.158.1 8 / 0
1.158.0 8 / 0
1.157.19 8 / 0
1.157.18 8 / 0
1.157.17 8 / 0
1.157.16 8 / 0
1.157.15 8 / 0
1.157.14 8 / 0
1.157.13 8 / 0
1.157.12 8 / 0
1.157.11 8 / 0
1.157.10 8 / 0
1.157.9 8 / 0
1.157.8 8 / 0
1.157.7 8 / 0
1.157.6 8 / 0
1.157.5 8 / 0
1.157.4 8 / 0
1.157.3 8 / 0
1.157.2 8 / 0
1.157.1 8 / 0
1.157.0 8 / 0
1.156.0 8 / 0
1.155.0 8 / 0
1.154.14 8 / 0
1.154.13 8 / 0
1.154.12 8 / 0
1.154.11 8 / 0
1.154.10 8 / 0
1.154.8 8 / 0
1.154.7 8 / 0
1.154.6 8 / 0
1.154.5 8 / 0
1.154.4 8 / 0
1.154.3 8 / 0
1.154.2 8 / 0
1.154.1 8 / 0
1.154.0 8 / 0
1.153.2 8 / 0
1.153.1 8 / 0
1.153.0 8 / 0
1.152.0 8 / 0
1.151.6 8 / 0
1.151.5 8 / 0
1.151.4 8 / 0
1.151.3 8 / 0
1.151.2 8 / 0
1.151.1 8 / 0
Showing 100 of 438 Next page →

v1.163.0

2 findings
HIGH Publisher changed: tannerlinsley → GitHub Actions (on 2026-02-24) provenance

This version was published by a different npm account than previous versions on 2026-02-24. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.