← Home

@storm-software/git-tools

Tools for managing Git repositories within a Nx workspace.

51
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

stormie-bot

Keywords

storm-softwaremonorepostorm-opssullivanpjcommitlintcommitizensemantic-releaselefthooklint-staged

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:api-obfuscation-reflect AI (semgrep): Standard lazy-init proxy pattern in bundled output; not evasion. ai
dependencies unvetted-dep:any-shell-escape AI (dependencies): any-shell-escape is a small, well-known utility appropriate for a git tools package. ai
semgrep semgrep:child-process-import AI (semgrep): Expected for a git tooling package that shells out to run git commands. ai
phantom-deps phantom-dep:@storm-software/config-tools AI (phantom-deps): Same-org dependency; phantom-dep heuristic false positive for monorepo packages. ai
phantom-deps phantom-dep:zod AI (phantom-deps): Listed as peerDependency; phantom-dep heuristic fires incorrectly here. ai
phantom-deps phantom-dep:@nx/js AI (phantom-deps): Build tooling dep; phantom-dep heuristic false positive. ai
semgrep semgrep:env-spread AI (semgrep): Git/CI tooling that runs subprocesses legitimately needs to forward process.env; stable pattern for this package. ai
phantom-deps phantom-dep:tsconfig-paths AI (phantom-deps): Stable false positive for this package's bundled build. ai
phantom-deps phantom-dep:@inquirer/prompts AI (phantom-deps): Stable false positive for this package's bundled build. ai
phantom-deps phantom-dep:@commitlint/ensure AI (phantom-deps): Stable false positive for this package's bundled build. ai
phantom-deps phantom-dep:@textlint/ast-node-types AI (phantom-deps): Stable false positive for this package's bundled build. ai
phantom-deps phantom-dep:jsonc-parser AI (phantom-deps): Stable false positive for this package's bundled build. ai
semgrep semgrep:env-bulk-read AI (semgrep): Config loader filters env keys by known prefix; not exfiltration. ai

Versions (showing 51 of 182)

View all versions
Version Deps Published
2.131.116 29 / 6
2.131.115 29 / 6
2.131.114 29 / 6
2.131.113 29 / 6
2.131.112 29 / 6
2.131.109 29 / 6
2.131.107 29 / 6
2.131.106 29 / 6
2.131.100 29 / 6
2.131.99 29 / 6
2.131.98 29 / 6
2.131.97 29 / 6
2.131.94 29 / 6
2.131.93 29 / 6
2.131.92 29 / 6
2.131.91 29 / 6
2.131.90 29 / 6
2.131.89 29 / 6
2.131.88 29 / 6
2.131.87 29 / 6
2.131.86 29 / 6
2.131.85 29 / 6
2.131.84 29 / 6
2.131.83 29 / 6
2.131.82 29 / 6
2.131.81 29 / 6
2.131.80 29 / 6
2.131.79 29 / 6
2.131.78 29 / 6
2.131.77 29 / 6
2.131.76 29 / 6
2.131.75 29 / 6
2.131.74 29 / 6
2.131.73 29 / 6
2.131.72 29 / 6
2.131.71 29 / 6
2.131.69 29 / 6
2.131.68 29 / 6
2.131.67 29 / 6
2.131.66 29 / 6
2.131.65 29 / 6
2.131.64 29 / 6
2.131.63 29 / 6
2.131.62 29 / 6
2.131.61 29 / 6
2.131.60 29 / 6
2.131.59 29 / 6
2.131.58 29 / 6
2.131.57 29 / 6
2.131.56 29 / 6
2.131.55 29 / 6

v2.131.116

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.131.115

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.131.114

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.131.113

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.131.112

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.131.109

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.131.107

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.131.106

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.131.100

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.131.99

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.131.98

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.131.97

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.131.94

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.131.93

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.131.92

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.131.91

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.131.90

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.131.89

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.131.88

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.131.87

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.131.86

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.