← Home

@tanstack/solid-start-client

82
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

tannerlinsleytkdodoalemtuzlakkevinvandyschiller-manuel

Keywords

solidlocationrouterroutingasyncasync routertypescript

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:vinxi AI (phantom-deps): vinxi is a declared dependency used in config/build context; phantom-dep heuristic is a false positive here. ai
phantom-deps phantom-dep:jsesc AI (phantom-deps): Build-time dep referenced in config; not a runtime import concern for this package. ai
phantom-deps phantom-dep:cookie-es AI (phantom-deps): Declared dependency used in config context; stable false positive for this package. ai
phantom-deps phantom-dep:tiny-invariant AI (phantom-deps): tiny-invariant is a declared runtime dependency used via build output; phantom-dep finding is a false positive for this package's build structure. ai
phantom-deps phantom-dep:tiny-warning AI (phantom-deps): tiny-warning is a declared runtime dependency used via build output; phantom-dep finding is a false positive for this package's build structure. ai
provenance publisher-changed AI (provenance): TanStack migrated to GitHub Actions CI/CD publishing with SLSA provenance attestation — this is a legitimate and security-improving automation transition, not a compromise. ai
maintainer-change maintainer-added AI (maintainer-change): lachlancollins is a known TanStack contributor; addition is consistent with legitimate team growth in this active open-source project. ai
dependencies unvetted-dep:@tanstack/router-core AI (dependencies): First-party TanStack monorepo dependency; part of the same release train as this package. Not a third-party risk. ai
dependencies unvetted-dep:@tanstack/start-client-core AI (dependencies): First-party TanStack monorepo dependency; part of the same release train as this package. Not a third-party risk. ai
dependencies unvetted-dep:@tanstack/solid-router AI (dependencies): First-party TanStack monorepo dependency; part of the same release train as this package. Not a third-party risk. ai

Versions (showing 82 of 384)

Version Deps Published
1.131.8 6 / 3
1.131.7 6 / 3
1.131.6 6 / 3
1.131.5 6 / 3
1.131.4 6 / 3
1.131.3 6 / 3
1.131.2 6 / 3
1.130.17 6 / 3
1.130.12 6 / 3
1.130.11 6 / 3
1.130.10 6 / 3
1.130.9 6 / 3
1.130.8 6 / 3
1.130.7 6 / 3
1.130.6 6 / 3
1.130.5 6 / 3
1.130.2 6 / 3
1.130.1 6 / 3
1.130.0 6 / 3
1.129.9 6 / 3
1.129.8 6 / 3
1.129.7 6 / 3
1.129.5 6 / 3
1.129.4 6 / 3
1.129.3 6 / 3
1.129.2 6 / 3
1.129.0 6 / 3
1.128.8 6 / 3
1.128.7 6 / 3
1.128.6 6 / 3
1.128.4 6 / 3
1.128.3 6 / 3
1.128.0 6 / 3
1.127.9 6 / 3
1.127.8 6 / 3
1.127.3 6 / 3
1.127.2 6 / 3
1.127.1 7 / 4
1.127.0 7 / 4
1.126.2 7 / 4
1.125.7 7 / 4
1.125.6 7 / 4
1.125.4 7 / 4
1.125.3 7 / 4
1.125.2 7 / 4
1.125.1 7 / 4
1.125.0 7 / 4
1.124.2 7 / 4
1.124.0 7 / 4
1.123.2 7 / 4
1.123.0 7 / 4
1.122.0 7 / 4
1.121.41 7 / 4
1.121.40 7 / 4
1.121.39 7 / 4
1.121.34 7 / 4
1.121.33 7 / 4
1.121.27 7 / 4
1.121.24 7 / 4
1.121.23 7 / 4
1.121.21 7 / 4
1.121.20 7 / 4
1.121.19 7 / 4
1.121.18 7 / 4
1.121.17 7 / 4
1.121.16 7 / 4
1.121.15 7 / 4
1.121.14 7 / 4
1.121.12 7 / 4
1.121.3 7 / 4
1.121.2 7 / 4
1.121.0 7 / 4
1.120.19 8 / 4
1.120.17 8 / 4
1.120.15 8 / 4
1.120.8 8 / 4
1.120.7 8 / 4
1.120.3 8 / 4
1.120.2 8 / 4
1.120.1 8 / 4
1.119.0 8 / 4
1.117.1 8 / 4

v1.131.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.129.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.128.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.127.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.125.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.121.34

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.121.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.117.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.