@storm-software/config-tools
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Publisher changed from stormie-bot to GitHub Actions with SLSA provenance attestation; this is a legitimate CI/CD pipeline transition for this monorepo package, not a compromise signal. | ai | |
| semgrep | semgrep:env-bulk-read | AI (semgrep): This is a config-tools library; reading prefixed env vars (STORM_EXTENSION_*) is core functionality, not credential harvesting. Pattern is stable across versions. | ai | |
| phantom-deps | phantom-dep:jiti | AI (phantom-deps): jiti is declared as a runtime dep and used for dynamic config file loading — a standard pattern in config libraries. Not a security concern. | ai | |
| phantom-deps | phantom-dep:giget | AI (phantom-deps): giget is a declared dep used for config scaffolding; phantom detection reflects indirect/dynamic usage pattern typical of config tooling. | ai | |
| phantom-deps | phantom-dep:sqlite | AI (phantom-deps): sqlite declared as dep; phantom detection reflects indirect usage. No security concern for a config-tools package. | ai | |
| phantom-deps | phantom-dep:date-fns | AI (phantom-deps): date-fns declared as dep; phantom detection reflects indirect/bundled usage. No security concern. | ai |
Versions (showing 51 of 807)
| Version | Deps | Published |
|---|---|---|
| 1.190.109 | 10 / 3 | |
| 1.190.108 | 10 / 3 | |
| 1.190.107 | 10 / 3 | |
| 1.190.106 | 10 / 3 | |
| 1.190.105 | 10 / 3 | |
| 1.190.104 | 10 / 3 | |
| 1.190.101 | 10 / 3 | |
| 1.190.99 | 10 / 3 | |
| 1.190.98 | 10 / 3 | |
| 1.190.92 | 10 / 3 | |
| 1.190.91 | 10 / 3 | |
| 1.190.90 | 10 / 3 | |
| 1.190.89 | 10 / 3 | |
| 1.190.86 | 10 / 3 | |
| 1.190.85 | 10 / 3 | |
| 1.190.84 | 10 / 3 | |
| 1.190.83 | 10 / 3 | |
| 1.190.82 | 10 / 3 | |
| 1.190.81 | 10 / 3 | |
| 1.190.80 | 10 / 3 | |
| 1.190.79 | 10 / 3 | |
| 1.190.78 | 10 / 3 | |
| 1.190.77 | 10 / 3 | |
| 1.190.76 | 10 / 3 | |
| 1.190.75 | 10 / 3 | |
| 1.190.74 | 10 / 3 | |
| 1.190.73 | 10 / 3 | |
| 1.190.72 | 10 / 3 | |
| 1.190.71 | 10 / 3 | |
| 1.190.70 | 10 / 3 | |
| 1.190.69 | 10 / 3 | |
| 1.190.68 | 10 / 3 | |
| 1.190.67 | 10 / 3 | |
| 1.190.66 | 10 / 3 | |
| 1.190.65 | 10 / 3 | |
| 1.190.64 | 10 / 3 | |
| 1.190.63 | 10 / 3 | |
| 1.190.62 | 10 / 3 | |
| 1.190.61 | 10 / 3 | |
| 1.190.60 | 10 / 3 | |
| 1.190.59 | 10 / 3 | |
| 1.190.58 | 10 / 3 | |
| 1.190.57 | 10 / 3 | |
| 1.190.56 | 10 / 3 | |
| 1.190.55 | 10 / 3 | |
| 1.190.54 | 10 / 3 | |
| 1.190.53 | 10 / 3 | |
| 1.190.52 | 10 / 3 | |
| 1.190.51 | 10 / 3 | |
| 1.190.50 | 10 / 3 | |
| 1.190.49 | 10 / 3 |
v1.190.109
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.190.108
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.190.107
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.190.106
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.190.105
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.190.104
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.190.101
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.190.99
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.190.98
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.190.92
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.190.91
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.190.90
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.190.89
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.190.86
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.190.85
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.190.84
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.190.83
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.190.82
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.190.81
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.190.80
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.190.79
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.