← Home

@tanstack/start-server-core

81
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

tannerlinsleytkdodoalemtuzlakkevinvandyschiller-manuel

Keywords

reactlocationrouterroutingasyncasync routertypescript

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
maintainer-change maintainer-removed AI (maintainer-change): TanStack publishes via GitHub Actions CI; individual maintainer list changes are expected org hygiene, not takeover signals. ai
publish-pattern new-deps-added AI (publish-pattern): fetchdts is a legitimate TS utility dep; package has SLSA provenance and strong ecosystem trust. ai
dependencies unvetted-dep:fetchdts AI (dependencies): fetchdts is a type-fetching utility with no runtime execution risk; TanStack publisher context makes supply-chain concern low. ai
maintainer-change maintainer-added AI (maintainer-change): lachlancollins is a known TanStack contributor; adding maintainers to a major ecosystem project is routine. ai
provenance publisher-changed AI (provenance): Transition from personal npm publish (tannerlinsley) to GitHub Actions CI/CD with SLSA provenance. This is the expected modern publishing pattern for TanStack packages. ai
publish-pattern dormant-publish AI (publish-pattern): Package has 417 versions, 5.7M weekly downloads, and SLSA provenance. Dormancy signal is a false positive for this actively maintained TanStack sub-package. ai
dependencies unvetted-dep:h3-v2 AI (dependencies): h3-v2 is a deliberate npm alias for [email protected], a known HTTP framework used intentionally by TanStack Start. This aliasing pattern is stable for this package. ai
bogus-package bogus-package AI (bogus-package): TanStack packages intentionally have minimal READMEs pointing to tanstack.com docs. This is a stable pattern across all TanStack packages, not a spam/phishing indicator. ai

Versions (showing 81 of 181)

Version Deps Published
1.131.5 9 / 4
1.131.4 9 / 4
1.131.3 9 / 4
1.131.2 9 / 4
1.130.17 9 / 4
1.130.12 9 / 4
1.130.11 9 / 4
1.130.10 9 / 4
1.130.9 9 / 4
1.130.8 9 / 4
1.130.7 9 / 4
1.130.6 9 / 4
1.130.5 9 / 4
1.130.3 9 / 4
1.130.2 9 / 4
1.130.1 9 / 4
1.130.0 9 / 4
1.129.9 9 / 4
1.129.8 9 / 4
1.129.7 9 / 4
1.129.5 9 / 4
1.129.4 9 / 4
1.129.3 9 / 4
1.129.2 9 / 4
1.129.0 9 / 4
1.128.8 8 / 4
1.128.7 8 / 4
1.128.6 8 / 4
1.128.4 8 / 4
1.128.3 8 / 4
1.128.1 8 / 4
1.128.0 8 / 4
1.127.8 8 / 4
1.127.3 8 / 4
1.127.2 8 / 4
1.127.0 9 / 5
1.126.2 9 / 5
1.126.1 9 / 5
1.125.4 9 / 5
1.125.3 9 / 5
1.125.1 9 / 5
1.125.0 9 / 5
1.124.2 9 / 5
1.124.0 9 / 5
1.123.2 9 / 5
1.123.0 9 / 5
1.122.0 9 / 5
1.121.40 9 / 5
1.121.39 9 / 5
1.121.34 9 / 5
1.121.33 9 / 5
1.121.32 9 / 5
1.121.30 9 / 5
1.121.27 9 / 4
1.121.26 9 / 4
1.121.23 9 / 4
1.121.21 9 / 4
1.121.20 9 / 4
1.121.19 9 / 4
1.121.18 9 / 4
1.121.17 9 / 4
1.121.16 9 / 4
1.121.14 9 / 4
1.121.12 9 / 4
1.121.10 9 / 4
1.121.2 9 / 4
1.121.0 9 / 4
1.120.19 8 / 3
1.120.17 8 / 3
1.120.16 8 / 3
1.120.15 8 / 3
1.120.13 8 / 3
1.120.10 8 / 3
1.120.9 8 / 3
1.120.8 8 / 3
1.120.7 8 / 3
1.120.5 8 / 3
1.120.4 8 / 3
1.120.3 8 / 3
1.119.0 8 / 3
1.117.1 8 / 3

v1.130.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.128.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.121.34

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.120.19

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.120.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.120.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.120.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.120.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.119.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.117.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.