@tanstack/router-devtools
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): TanStack publishes via GitHub Actions CI with SLSA attestation; this is the documented release process. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): lachlancollins is a known TanStack contributor; legitimate team expansion. | ai | |
| phantom-deps | phantom-dep:clsx | AI (phantom-deps): clsx is a declared runtime dependency; phantom-dep heuristic false positive for this package. | ai | |
| phantom-deps | phantom-dep:goober | AI (phantom-deps): goober is a declared runtime dependency; phantom-dep heuristic false positive for this package. | ai |
Versions (showing 14 of 314)
| Version | Deps | Published |
|---|---|---|
| 1.120.18 | 3 / 3 | |
| 1.120.17 | 3 / 3 | |
| 1.120.16 | 3 / 3 | |
| 1.120.15 | 3 / 3 | |
| 1.120.13 | 3 / 3 | |
| 1.120.12 | 3 / 3 | |
| 1.120.11 | 3 / 3 | |
| 1.120.10 | 3 / 3 | |
| 1.120.9 | 3 / 3 | |
| 1.120.8 | 3 / 3 | |
| 1.120.7 | 3 / 3 | |
| 1.120.6 | 3 / 3 | |
| 1.120.5 | 3 / 3 | |
| 1.120.4 | 3 / 3 |
v1.120.18
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.120.17
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.120.16
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.120.15
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.120.13
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.120.12
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.120.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.120.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.120.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.120.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.120.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.120.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.120.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.120.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.