← Home

@nx/storybook

The Nx Plugin for Storybook contains executors and generators for allowing your workspace to use the powerful Storybook integration testing & documenting capabilities.

50
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

nrwlownernrwl-jasonjack-nrwlmaxklessjameshenry

Keywords

AngularReactWebStorybookCypressCLIFront-endTesting

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:env-spread AI (semgrep): Spreading process.env when spawning Storybook CLI subprocess is standard and expected for this build tool. ai
phantom-deps phantom-dep:tslib AI (phantom-deps): tslib is a declared runtime dep used as a TypeScript helper; phantom-dep heuristic false positive. ai
semgrep semgrep:child-process-import AI (semgrep): Used in migration generators to invoke package manager CLI commands; standard pattern for Nx plugins. ai
semgrep semgrep:dynamic-require AI (semgrep): Resolves a fixed path ('storybook/package.json') to read version; not user-controlled input. ai

Versions (showing 50 of 50)

Version Deps Published
22.7.5 7 / 2
22.7.4 7 / 2
22.7.3 7 / 2
22.7.2 7 / 2
22.7.1 7 / 2
22.7.0 7 / 2
22.6.5 7 / 2
22.6.4 7 / 2
22.6.3 7 / 2
22.6.2 7 / 2
22.6.1 7 / 2
22.6.0 7 / 2
22.5.4 7 / 2
22.5.3 7 / 2
22.5.2 7 / 2
22.5.1 7 / 2
22.5.0 7 / 2
22.4.5 7 / 2
22.4.4 7 / 2
22.4.3 7 / 2
22.4.2 7 / 2
22.4.1 7 / 2
22.4.0 7 / 2
22.3.3 7 / 2
22.3.2 7 / 2
22.3.1 7 / 2
22.3.0 7 / 2
22.2.7 7 / 2
22.2.6 7 / 2
22.2.5 7 / 2
22.2.4 7 / 2
22.2.3 7 / 2
22.2.2 7 / 2
22.2.1 7 / 2
22.2.0 7 / 2
22.1.3 7 / 2
22.1.2 7 / 2
22.1.1 7 / 2
22.1.0 7 / 2
22.0.4 7 / 1
22.0.3 7 / 1
22.0.2 7 / 1
22.0.1 7 / 1
22.0.0 7 / 1
21.6.11 7 / 1
21.6.10 7 / 1
21.6.9 7 / 1
21.3.12 7 / 0
20.8.4 7 / 0
20.8.3 7 / 0

v22.7.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v22.7.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v22.7.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v22.7.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v22.7.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v22.6.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v22.6.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v22.6.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v22.6.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v22.6.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v22.6.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v22.5.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v22.5.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v22.5.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v22.5.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v22.5.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v22.4.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v22.4.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v22.4.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v22.4.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v22.4.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v22.4.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v22.3.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v22.3.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v22.3.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v22.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v22.2.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v22.2.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v22.2.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v22.2.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v22.2.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v22.2.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v22.2.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v22.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v22.1.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v22.1.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v22.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v22.1.0

2 findings
HIGH env-spread: src/generators/migrate-9/calling-storybook-cli.js:72 semgrep

Spreading entire process.env into an object — may capture all secrets 70 | stdio: 'inherit', 71 | windowsHide: false, > 72 | env: { 73 | ...process.env, 74 | STORYBOOK_PROJECT_ROOT: storybookProjectInfo.configDir,

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v22.0.4

2 findings
HIGH env-spread: src/generators/migrate-9/calling-storybook-cli.js:72 semgrep

Spreading entire process.env into an object — may capture all secrets 70 | stdio: 'inherit', 71 | windowsHide: false, > 72 | env: { 73 | ...process.env, 74 | STORYBOOK_PROJECT_ROOT: storybookProjectInfo.configDir,

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v22.0.3

2 findings
HIGH env-spread: src/generators/migrate-9/calling-storybook-cli.js:72 semgrep

Spreading entire process.env into an object — may capture all secrets 70 | stdio: 'inherit', 71 | windowsHide: false, > 72 | env: { 73 | ...process.env, 74 | STORYBOOK_PROJECT_ROOT: storybookProjectInfo.configDir,

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v22.0.2

2 findings
HIGH env-spread: src/generators/migrate-9/calling-storybook-cli.js:72 semgrep

Spreading entire process.env into an object — may capture all secrets 70 | stdio: 'inherit', 71 | windowsHide: false, > 72 | env: { 73 | ...process.env, 74 | STORYBOOK_PROJECT_ROOT: storybookProjectInfo.configDir,

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v22.0.1

2 findings
HIGH env-spread: src/generators/migrate-9/calling-storybook-cli.js:72 semgrep

Spreading entire process.env into an object — may capture all secrets 70 | stdio: 'inherit', 71 | windowsHide: false, > 72 | env: { 73 | ...process.env, 74 | STORYBOOK_PROJECT_ROOT: storybookProjectInfo.configDir,

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v22.0.0

2 findings
HIGH env-spread: src/generators/migrate-9/calling-storybook-cli.js:72 semgrep

Spreading entire process.env into an object — may capture all secrets 70 | stdio: 'inherit', 71 | windowsHide: false, > 72 | env: { 73 | ...process.env, 74 | STORYBOOK_PROJECT_ROOT: storybookProjectInfo.configDir,

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v21.6.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v21.6.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v21.6.9

2 findings
HIGH env-spread: src/generators/migrate-9/calling-storybook-cli.js:72 semgrep

Spreading entire process.env into an object — may capture all secrets 70 | stdio: 'inherit', 71 | windowsHide: false, > 72 | env: { 73 | ...process.env, 74 | STORYBOOK_PROJECT_ROOT: storybookProjectInfo.configDir,

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v21.3.12

2 findings
HIGH env-spread: src/generators/migrate-9/calling-storybook-cli.js:72 semgrep

Spreading entire process.env into an object — may capture all secrets 70 | stdio: 'inherit', 71 | windowsHide: false, > 72 | env: { 73 | ...process.env, 74 | STORYBOOK_PROJECT_ROOT: storybookProjectInfo.configDir,

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v20.8.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v20.8.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.