← Home

@tanstack/solid-start

100
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

tannerlinsleytkdodoalemtuzlakkevinvandyschiller-manuel

Keywords

solidlocationrouterroutingasyncasync routertypescript

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@tanstack/solid-start-plugin AI (dependencies): Internal @tanstack monorepo dependency released in lockstep; same publisher, no independent risk. ai
dependencies unvetted-dep:@tanstack/start-api-routes AI (dependencies): Internal TanStack monorepo sub-package, co-published with same version. ai
dependencies unvetted-dep:@tanstack/solid-start-config AI (dependencies): Internal TanStack monorepo sub-package, co-published with same version. ai
dependencies unvetted-dep:@tanstack/start-server-functions-ssr AI (dependencies): Internal TanStack monorepo sub-package, co-published with same version. ai
dependencies unvetted-dep:@tanstack/solid-start-router-manifest AI (dependencies): Internal TanStack monorepo sub-package, co-published with same version. ai
dependencies unvetted-dep:@tanstack/start-server-functions-server AI (dependencies): Internal TanStack monorepo sub-package, co-published alongside this release. ai
dependencies unvetted-dep:@tanstack/start-server-functions-handler AI (dependencies): Internal TanStack monorepo sub-package, co-published with same version. ai
dependencies unvetted-dep:@tanstack/start-server-functions-client AI (dependencies): Internal TanStack monorepo sub-package, co-published with same version. ai
provenance publisher-changed AI (provenance): TanStack/router migrated to GitHub Actions CI/CD publishing with SLSA provenance attestation — this is a supply chain improvement, not a compromise signal. Stable for this package going forward. ai
maintainer-change maintainer-added AI (maintainer-change): lachlancollins is a known TanStack contributor. Adding maintainers to an active OSS project is routine and expected. ai

Versions (showing 100 of 422)

Version Deps Published
1.150.0 7 / 2
1.149.4 7 / 2
1.149.3 7 / 2
1.149.2 7 / 2
1.149.1 7 / 2
1.149.0 7 / 2
1.148.0 7 / 2
1.147.3 7 / 2
1.147.2 7 / 2
1.147.1 7 / 2
1.147.0 7 / 2
1.146.3 7 / 2
1.146.2 7 / 2
1.146.1 7 / 2
1.146.0 7 / 2
1.145.11 7 / 2
1.145.10 7 / 2
1.145.9 7 / 2
1.145.8 7 / 2
1.145.7 7 / 2
1.145.6 7 / 2
1.145.5 7 / 2
1.145.4 7 / 2
1.145.3 7 / 2
1.145.2 7 / 2
1.145.1 7 / 2
1.145.0 7 / 2
1.144.0 7 / 2
1.143.12 7 / 2
1.143.11 7 / 2
1.143.10 7 / 2
1.143.9 7 / 2
1.143.8 7 / 2
1.143.7 7 / 2
1.143.6 7 / 2
1.143.5 7 / 2
1.143.4 7 / 2
1.143.3 7 / 2
1.143.2 7 / 2
1.143.1 7 / 2
1.143.0 7 / 2
1.142.13 7 / 2
1.142.12 7 / 2
1.142.11 7 / 2
1.142.10 7 / 2
1.142.9 7 / 2
1.142.8 7 / 2
1.142.7 7 / 2
1.142.6 7 / 2
1.142.5 7 / 2
1.142.4 7 / 2
1.142.3 7 / 2
1.142.2 7 / 2
1.142.1 7 / 2
1.142.0 7 / 2
1.141.9 7 / 2
1.141.8 7 / 2
1.141.7 7 / 2
1.141.6 7 / 2
1.141.5 7 / 2
1.141.4 7 / 2
1.141.3 7 / 2
1.141.2 7 / 2
1.141.1 7 / 2
1.141.0 7 / 2
1.140.5 7 / 2
1.140.4 7 / 2
1.140.3 7 / 2
1.140.2 7 / 2
1.140.1 7 / 2
1.140.0 7 / 2
1.139.14 7 / 2
1.139.13 7 / 2
1.139.12 7 / 2
1.139.11 7 / 2
1.139.10 7 / 2
1.139.9 7 / 2
1.139.8 7 / 2
1.139.7 7 / 2
1.139.6 7 / 2
1.139.5 7 / 2
1.139.4 7 / 2
1.139.3 7 / 2
1.139.2 7 / 2
1.139.1 7 / 2
1.139.0 7 / 2
1.138.0 7 / 2
1.137.0 7 / 2
1.136.18 7 / 2
1.136.17 7 / 2
1.136.16 7 / 2
1.136.15 7 / 2
1.136.14 7 / 2
1.136.13 7 / 2
1.136.12 7 / 2
1.136.11 7 / 2
1.136.10 7 / 2
1.136.9 7 / 2
1.136.8 7 / 2
1.136.7 7 / 2
Showing 100 of 422 Next page →

v1.146.3

2 findings
HIGH Publisher changed: tannerlinsley → GitHub Actions (on 2026-01-09) provenance

This version was published by a different npm account than previous versions on 2026-01-09. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.145.1

2 findings
HIGH Publisher changed: tannerlinsley → GitHub Actions (on 2025-12-30) provenance

This version was published by a different npm account than previous versions on 2025-12-30. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.142.7

2 findings
HIGH Publisher changed: tannerlinsley → GitHub Actions (on 2025-12-21) provenance

This version was published by a different npm account than previous versions on 2025-12-21. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.142.6

2 findings
HIGH Publisher changed: tannerlinsley → GitHub Actions (on 2025-12-21) provenance

This version was published by a different npm account than previous versions on 2025-12-21. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.142.4

2 findings
HIGH Publisher changed: tannerlinsley → GitHub Actions (on 2025-12-21) provenance

This version was published by a different npm account than previous versions on 2025-12-21. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.142.3

2 findings
HIGH Publisher changed: tannerlinsley → GitHub Actions (on 2025-12-20) provenance

This version was published by a different npm account than previous versions on 2025-12-20. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.142.2

2 findings
HIGH Publisher changed: tannerlinsley → GitHub Actions (on 2025-12-20) provenance

This version was published by a different npm account than previous versions on 2025-12-20. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.142.1

2 findings
HIGH Publisher changed: tannerlinsley → GitHub Actions (on 2025-12-20) provenance

This version was published by a different npm account than previous versions on 2025-12-20. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.