@storm-software/config
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Publisher changed from stormie-bot to GitHub Actions as part of a legitimate CI/CD migration; SLSA provenance attestation confirms builds are tied to the official GitHub Actions pipeline. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Minor cosmetic signals (off-topic README, no keywords) in an 810-day-old established package with 620 versions; not indicative of spam or malicious intent. | ai |
Versions (showing 51 of 714)
| Version | Deps | Published |
|---|---|---|
| 1.138.46 | 0 / 2 | |
| 1.138.45 | 0 / 2 | |
| 1.138.44 | 0 / 2 | |
| 1.138.43 | 0 / 2 | |
| 1.138.42 | 0 / 2 | |
| 1.138.41 | 0 / 2 | |
| 1.138.38 | 0 / 2 | |
| 1.138.36 | 0 / 2 | |
| 1.138.35 | 0 / 2 | |
| 1.138.29 | 0 / 2 | |
| 1.138.28 | 0 / 2 | |
| 1.138.27 | 0 / 2 | |
| 1.138.26 | 0 / 2 | |
| 1.138.23 | 0 / 2 | |
| 1.138.22 | 0 / 2 | |
| 1.138.21 | 0 / 2 | |
| 1.138.20 | 0 / 2 | |
| 1.138.19 | 0 / 2 | |
| 1.138.18 | 0 / 2 | |
| 1.138.17 | 0 / 2 | |
| 1.138.16 | 0 / 2 | |
| 1.138.15 | 0 / 2 | |
| 1.138.14 | 0 / 2 | |
| 1.138.13 | 0 / 2 | |
| 1.138.12 | 0 / 2 | |
| 1.138.11 | 0 / 2 | |
| 1.138.10 | 0 / 2 | |
| 1.138.9 | 0 / 2 | |
| 1.138.8 | 0 / 2 | |
| 1.138.7 | 0 / 2 | |
| 1.138.6 | 0 / 2 | |
| 1.138.5 | 0 / 2 | |
| 1.138.4 | 0 / 2 | |
| 1.138.3 | 0 / 2 | |
| 1.138.2 | 0 / 2 | |
| 1.138.1 | 0 / 2 | |
| 1.138.0 | 0 / 2 | |
| 1.137.94 | 0 / 2 | |
| 1.137.93 | 0 / 2 | |
| 1.137.92 | 0 / 2 | |
| 1.137.91 | 0 / 2 | |
| 1.137.90 | 0 / 2 | |
| 1.137.89 | 0 / 2 | |
| 1.137.88 | 0 / 2 | |
| 1.137.87 | 0 / 2 | |
| 1.137.86 | 0 / 2 | |
| 1.137.85 | 0 / 2 | |
| 1.137.84 | 0 / 2 | |
| 1.137.83 | 0 / 2 | |
| 1.137.82 | 0 / 2 | |
| 1.137.81 | 0 / 2 |
v1.138.46
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.138.45
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.138.44
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.138.43
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.138.42
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.138.41
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.138.38
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.138.36
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.138.35
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.138.29
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.138.28
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.138.27
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.138.26
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.138.23
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.138.22
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.138.21
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.138.20
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.138.19
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.138.18
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.138.17
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.138.16
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.