@storm-software/git-tools
Tools for managing Git repositories within a Nx workspace.
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Standard lazy-init proxy pattern in bundled output; not evasion. | ai | |
| dependencies | unvetted-dep:any-shell-escape | AI (dependencies): any-shell-escape is a small, well-known utility appropriate for a git tools package. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): Expected for a git tooling package that shells out to run git commands. | ai | |
| phantom-deps | phantom-dep:@storm-software/config-tools | AI (phantom-deps): Same-org dependency; phantom-dep heuristic false positive for monorepo packages. | ai | |
| phantom-deps | phantom-dep:zod | AI (phantom-deps): Listed as peerDependency; phantom-dep heuristic fires incorrectly here. | ai | |
| phantom-deps | phantom-dep:@nx/js | AI (phantom-deps): Build tooling dep; phantom-dep heuristic false positive. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): Git/CI tooling that runs subprocesses legitimately needs to forward process.env; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:tsconfig-paths | AI (phantom-deps): Stable false positive for this package's bundled build. | ai | |
| phantom-deps | phantom-dep:@inquirer/prompts | AI (phantom-deps): Stable false positive for this package's bundled build. | ai | |
| phantom-deps | phantom-dep:@commitlint/ensure | AI (phantom-deps): Stable false positive for this package's bundled build. | ai | |
| phantom-deps | phantom-dep:@textlint/ast-node-types | AI (phantom-deps): Stable false positive for this package's bundled build. | ai | |
| phantom-deps | phantom-dep:jsonc-parser | AI (phantom-deps): Stable false positive for this package's bundled build. | ai | |
| semgrep | semgrep:env-bulk-read | AI (semgrep): Config loader filters env keys by known prefix; not exfiltration. | ai |
Versions (showing 51 of 182)
| Version | Deps | Published |
|---|---|---|
| 2.131.116 | 29 / 6 | |
| 2.131.115 | 29 / 6 | |
| 2.131.114 | 29 / 6 | |
| 2.131.113 | 29 / 6 | |
| 2.131.112 | 29 / 6 | |
| 2.131.109 | 29 / 6 | |
| 2.131.107 | 29 / 6 | |
| 2.131.106 | 29 / 6 | |
| 2.131.100 | 29 / 6 | |
| 2.131.99 | 29 / 6 | |
| 2.131.98 | 29 / 6 | |
| 2.131.97 | 29 / 6 | |
| 2.131.94 | 29 / 6 | |
| 2.131.93 | 29 / 6 | |
| 2.131.92 | 29 / 6 | |
| 2.131.91 | 29 / 6 | |
| 2.131.90 | 29 / 6 | |
| 2.131.89 | 29 / 6 | |
| 2.131.88 | 29 / 6 | |
| 2.131.87 | 29 / 6 | |
| 2.131.86 | 29 / 6 | |
| 2.131.85 | 29 / 6 | |
| 2.131.84 | 29 / 6 | |
| 2.131.83 | 29 / 6 | |
| 2.131.82 | 29 / 6 | |
| 2.131.81 | 29 / 6 | |
| 2.131.80 | 29 / 6 | |
| 2.131.79 | 29 / 6 | |
| 2.131.78 | 29 / 6 | |
| 2.131.77 | 29 / 6 | |
| 2.131.76 | 29 / 6 | |
| 2.131.75 | 29 / 6 | |
| 2.131.74 | 29 / 6 | |
| 2.131.73 | 29 / 6 | |
| 2.131.72 | 29 / 6 | |
| 2.131.71 | 29 / 6 | |
| 2.131.69 | 29 / 6 | |
| 2.131.68 | 29 / 6 | |
| 2.131.67 | 29 / 6 | |
| 2.131.66 | 29 / 6 | |
| 2.131.65 | 29 / 6 | |
| 2.131.64 | 29 / 6 | |
| 2.131.63 | 29 / 6 | |
| 2.131.62 | 29 / 6 | |
| 2.131.61 | 29 / 6 | |
| 2.131.60 | 29 / 6 | |
| 2.131.59 | 29 / 6 | |
| 2.131.58 | 29 / 6 | |
| 2.131.57 | 29 / 6 | |
| 2.131.56 | 29 / 6 | |
| 2.131.55 | 29 / 6 |
v2.131.116
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.131.115
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.131.114
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.131.113
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.131.112
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.131.109
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.131.107
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.131.106
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.131.100
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.131.99
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.131.98
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.131.97
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.131.94
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.131.93
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.131.92
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.131.91
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.131.90
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.131.89
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.131.88
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.131.87
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.131.86
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.