← Home

@tanstack/solid-start

100
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

tannerlinsleytkdodoalemtuzlakkevinvandyschiller-manuel

Keywords

solidlocationrouterroutingasyncasync routertypescript

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@tanstack/solid-start-plugin AI (dependencies): Internal @tanstack monorepo dependency released in lockstep; same publisher, no independent risk. ai
dependencies unvetted-dep:@tanstack/start-api-routes AI (dependencies): Internal TanStack monorepo sub-package, co-published with same version. ai
dependencies unvetted-dep:@tanstack/solid-start-config AI (dependencies): Internal TanStack monorepo sub-package, co-published with same version. ai
dependencies unvetted-dep:@tanstack/start-server-functions-ssr AI (dependencies): Internal TanStack monorepo sub-package, co-published with same version. ai
dependencies unvetted-dep:@tanstack/solid-start-router-manifest AI (dependencies): Internal TanStack monorepo sub-package, co-published with same version. ai
dependencies unvetted-dep:@tanstack/start-server-functions-server AI (dependencies): Internal TanStack monorepo sub-package, co-published alongside this release. ai
dependencies unvetted-dep:@tanstack/start-server-functions-handler AI (dependencies): Internal TanStack monorepo sub-package, co-published with same version. ai
dependencies unvetted-dep:@tanstack/start-server-functions-client AI (dependencies): Internal TanStack monorepo sub-package, co-published with same version. ai
provenance publisher-changed AI (provenance): TanStack/router migrated to GitHub Actions CI/CD publishing with SLSA provenance attestation — this is a supply chain improvement, not a compromise signal. Stable for this package going forward. ai
maintainer-change maintainer-added AI (maintainer-change): lachlancollins is a known TanStack contributor. Adding maintainers to an active OSS project is routine and expected. ai

Versions (showing 100 of 422)

Version Deps Published
1.166.5 7 / 2
1.166.4 7 / 2
1.166.3 7 / 2
1.166.2 7 / 2
1.166.1 7 / 2
1.166.0 7 / 2
1.165.0 7 / 2
1.164.1 7 / 2
1.164.0 7 / 2
1.163.5 7 / 2
1.163.4 7 / 2
1.163.3 7 / 2
1.163.2 7 / 2
1.163.1 7 / 2
1.163.0 7 / 2
1.162.9 7 / 2
1.162.8 7 / 2
1.162.7 7 / 2
1.162.6 7 / 2
1.162.5 7 / 2
1.162.4 7 / 2
1.162.3 7 / 2
1.162.2 7 / 2
1.162.1 7 / 2
1.162.0 7 / 2
1.161.4 7 / 2
1.161.3 7 / 2
1.161.1 7 / 2
1.161.0 7 / 2
1.160.2 7 / 2
1.160.1 7 / 2
1.160.0 7 / 2
1.159.14 7 / 2
1.159.13 7 / 2
1.159.12 7 / 2
1.159.11 7 / 2
1.159.10 7 / 2
1.159.9 7 / 2
1.159.8 7 / 2
1.159.7 7 / 2
1.159.6 7 / 2
1.159.5 7 / 2
1.159.4 7 / 2
1.159.3 7 / 2
1.159.2 7 / 2
1.159.1 7 / 2
1.159.0 7 / 2
1.158.4 7 / 2
1.158.3 7 / 2
1.158.2 7 / 2
1.158.1 7 / 2
1.158.0 7 / 2
1.157.19 7 / 2
1.157.18 7 / 2
1.157.17 7 / 2
1.157.16 7 / 2
1.157.15 7 / 2
1.157.14 7 / 2
1.157.13 7 / 2
1.157.12 7 / 2
1.157.11 7 / 2
1.157.10 7 / 2
1.157.9 7 / 2
1.157.8 7 / 2
1.157.7 7 / 2
1.157.6 7 / 2
1.157.5 7 / 2
1.157.4 7 / 2
1.157.3 7 / 2
1.157.2 7 / 2
1.157.1 7 / 2
1.157.0 7 / 2
1.156.0 7 / 2
1.155.0 7 / 2
1.154.14 7 / 2
1.154.13 7 / 2
1.154.12 7 / 2
1.154.11 7 / 2
1.154.10 7 / 2
1.154.9 7 / 2
1.154.8 7 / 2
1.154.7 7 / 2
1.154.6 7 / 2
1.154.5 7 / 2
1.154.4 7 / 2
1.154.3 7 / 2
1.154.2 7 / 2
1.154.1 7 / 2
1.154.0 7 / 2
1.153.2 7 / 2
1.153.1 7 / 2
1.153.0 7 / 2
1.152.0 7 / 2
1.151.6 7 / 2
1.151.5 7 / 2
1.151.4 7 / 2
1.151.3 7 / 2
1.151.2 7 / 2
1.151.1 7 / 2
1.151.0 7 / 2
Showing 100 of 422 Next page →

v1.163.3

2 findings
HIGH Publisher changed: tannerlinsley → GitHub Actions (on 2026-02-27) provenance

This version was published by a different npm account than previous versions on 2026-02-27. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.163.2

2 findings
HIGH Publisher changed: tannerlinsley → GitHub Actions (on 2026-02-25) provenance

This version was published by a different npm account than previous versions on 2026-02-25. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.157.12

2 findings
HIGH Publisher changed: tannerlinsley → GitHub Actions (on 2026-01-25) provenance

This version was published by a different npm account than previous versions on 2026-01-25. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.157.1

2 findings
HIGH Publisher changed: tannerlinsley → GitHub Actions (on 2026-01-24) provenance

This version was published by a different npm account than previous versions on 2026-01-24. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.154.4

2 findings
HIGH Publisher changed: tannerlinsley → GitHub Actions (on 2026-01-21) provenance

This version was published by a different npm account than previous versions on 2026-01-21. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.151.2

2 findings
HIGH Publisher changed: tannerlinsley → GitHub Actions (on 2026-01-18) provenance

This version was published by a different npm account than previous versions on 2026-01-18. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.