← Home

@storm-software/build-tools

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

stormie-botsullivanpj

Keywords

monorepoopen-systemstormstorm-opsstorm-stackstormstacksullivanpj

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition from stormie-bot to GitHub Actions reflects a CI/CD automation migration. SLSA provenance attestation confirms legitimate pipeline publishing for this package. ai
phantom-deps phantom-dep:resolve-from AI (phantom-deps): resolve-from is explicitly declared as a runtime dependency in package.json; the phantom-dep finding is a false positive for this package. ai

Versions (showing 51 of 555)

View all versions
Version Deps Published
0.158.269 5 / 6
0.158.268 5 / 6
0.158.267 5 / 6
0.158.266 5 / 6
0.158.265 5 / 6
0.158.264 5 / 6
0.158.261 5 / 6
0.158.259 5 / 6
0.158.258 5 / 6
0.158.252 5 / 6
0.158.251 5 / 6
0.158.250 5 / 6
0.158.249 5 / 6
0.158.246 5 / 6
0.158.245 5 / 6
0.158.244 5 / 6
0.158.243 5 / 6
0.158.242 5 / 6
0.158.241 5 / 6
0.158.240 5 / 6
0.158.239 5 / 6
0.158.238 5 / 6
0.158.237 5 / 6
0.158.236 5 / 6
0.158.235 5 / 6
0.158.234 5 / 6
0.158.233 5 / 6
0.158.232 5 / 6
0.158.231 5 / 6
0.158.230 5 / 6
0.158.229 5 / 6
0.158.228 5 / 6
0.158.227 5 / 6
0.158.226 5 / 6
0.158.225 5 / 6
0.158.224 5 / 6
0.158.223 5 / 6
0.158.222 5 / 6
0.158.221 5 / 6
0.158.220 5 / 6
0.158.219 5 / 6
0.158.218 5 / 6
0.158.217 5 / 6
0.158.216 5 / 6
0.158.215 5 / 6
0.158.214 5 / 6
0.158.213 5 / 6
0.158.212 5 / 6
0.158.211 5 / 6
0.158.210 5 / 6
0.158.209 5 / 6

v0.158.269

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.158.268

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.158.267

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.158.266

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.158.265

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.158.264

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.158.261

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.158.259

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.158.258

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.158.252

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.158.251

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.158.250

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.158.249

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.158.246

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.158.245

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.158.244

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.158.243

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.158.242

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.158.241

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.158.240

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.158.239

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.