← Home

@tanstack/solid-start-client

100
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

tannerlinsleytkdodoalemtuzlakkevinvandyschiller-manuel

Keywords

solidlocationrouterroutingasyncasync routertypescript

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:vinxi AI (phantom-deps): vinxi is a declared dependency used in config/build context; phantom-dep heuristic is a false positive here. ai
phantom-deps phantom-dep:jsesc AI (phantom-deps): Build-time dep referenced in config; not a runtime import concern for this package. ai
phantom-deps phantom-dep:cookie-es AI (phantom-deps): Declared dependency used in config context; stable false positive for this package. ai
phantom-deps phantom-dep:tiny-invariant AI (phantom-deps): tiny-invariant is a declared runtime dependency used via build output; phantom-dep finding is a false positive for this package's build structure. ai
phantom-deps phantom-dep:tiny-warning AI (phantom-deps): tiny-warning is a declared runtime dependency used via build output; phantom-dep finding is a false positive for this package's build structure. ai
provenance publisher-changed AI (provenance): TanStack migrated to GitHub Actions CI/CD publishing with SLSA provenance attestation — this is a legitimate and security-improving automation transition, not a compromise. ai
maintainer-change maintainer-added AI (maintainer-change): lachlancollins is a known TanStack contributor; addition is consistent with legitimate team growth in this active open-source project. ai
dependencies unvetted-dep:@tanstack/router-core AI (dependencies): First-party TanStack monorepo dependency; part of the same release train as this package. Not a third-party risk. ai
dependencies unvetted-dep:@tanstack/start-client-core AI (dependencies): First-party TanStack monorepo dependency; part of the same release train as this package. Not a third-party risk. ai
dependencies unvetted-dep:@tanstack/solid-router AI (dependencies): First-party TanStack monorepo dependency; part of the same release train as this package. Not a third-party risk. ai

Versions (showing 100 of 384)

Version Deps Published
1.134.15 5 / 3
1.134.13 5 / 3
1.134.12 5 / 3
1.134.11 5 / 3
1.134.10 5 / 3
1.134.9 5 / 3
1.134.8 5 / 3
1.134.4 5 / 3
1.134.1 5 / 3
1.133.36 5 / 3
1.133.35 5 / 3
1.133.34 5 / 3
1.133.31 5 / 3
1.133.30 5 / 3
1.133.28 5 / 3
1.133.27 5 / 3
1.133.25 5 / 3
1.133.24 5 / 3
1.133.23 5 / 3
1.133.22 5 / 3
1.133.20 5 / 3
1.133.19 5 / 3
1.133.18 5 / 3
1.133.15 5 / 3
1.133.13 5 / 3
1.133.12 5 / 3
1.133.10 5 / 3
1.133.8 5 / 3
1.133.7 5 / 3
1.133.5 5 / 3
1.133.3 5 / 3
1.133.2 5 / 3
1.132.54 5 / 3
1.132.49 5 / 3
1.132.48 5 / 3
1.132.47 5 / 3
1.132.45 5 / 3
1.132.43 5 / 3
1.132.41 5 / 3
1.132.37 5 / 3
1.132.36 5 / 3
1.132.33 5 / 3
1.132.32 5 / 3
1.132.31 5 / 3
1.132.29 5 / 3
1.132.27 5 / 3
1.132.26 5 / 3
1.132.25 5 / 3
1.132.23 5 / 3
1.132.21 5 / 3
1.132.19 5 / 3
1.132.17 5 / 3
1.132.16 5 / 3
1.132.15 5 / 3
1.132.12 5 / 3
1.132.11 5 / 3
1.132.10 5 / 3
1.132.7 5 / 3
1.132.6 5 / 3
1.132.4 5 / 3
1.132.3 5 / 3
1.132.2 5 / 3
1.132.1 6 / 3
1.132.0 6 / 3
1.131.50 6 / 3
1.131.49 6 / 3
1.131.48 6 / 3
1.131.47 6 / 3
1.131.46 6 / 3
1.131.44 6 / 3
1.131.41 6 / 3
1.131.40 6 / 3
1.131.39 6 / 3
1.131.38 6 / 3
1.131.37 6 / 3
1.131.36 6 / 3
1.131.35 6 / 3
1.131.34 6 / 3
1.131.33 6 / 3
1.131.32 6 / 3
1.131.31 6 / 3
1.131.30 6 / 3
1.131.29 6 / 3
1.131.28 6 / 3
1.131.27 6 / 3
1.131.26 6 / 3
1.131.25 6 / 3
1.131.24 6 / 3
1.131.23 6 / 3
1.131.22 6 / 3
1.131.21 6 / 3
1.131.20 6 / 3
1.131.19 6 / 3
1.131.18 6 / 3
1.131.17 6 / 3
1.131.16 6 / 3
1.131.14 6 / 3
1.131.13 6 / 3
1.131.12 6 / 3
1.131.9 6 / 3
Showing 100 of 384 Next page →

v1.134.15

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.134.13

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.134.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.134.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.134.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.134.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.134.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.134.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.134.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.133.36

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.133.35

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.133.34

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.133.31

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.133.30

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.133.20

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.133.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.132.31

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.132.21

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.131.36

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.131.29

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.131.18

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.