@storm-software/git-tools
Tools for managing Git repositories within a Nx workspace.
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Standard lazy-init proxy pattern in bundled output; not evasion. | ai | |
| dependencies | unvetted-dep:any-shell-escape | AI (dependencies): any-shell-escape is a small, well-known utility appropriate for a git tools package. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): Expected for a git tooling package that shells out to run git commands. | ai | |
| phantom-deps | phantom-dep:@storm-software/config-tools | AI (phantom-deps): Same-org dependency; phantom-dep heuristic false positive for monorepo packages. | ai | |
| phantom-deps | phantom-dep:zod | AI (phantom-deps): Listed as peerDependency; phantom-dep heuristic fires incorrectly here. | ai | |
| phantom-deps | phantom-dep:@nx/js | AI (phantom-deps): Build tooling dep; phantom-dep heuristic false positive. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): Git/CI tooling that runs subprocesses legitimately needs to forward process.env; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:tsconfig-paths | AI (phantom-deps): Stable false positive for this package's bundled build. | ai | |
| phantom-deps | phantom-dep:@inquirer/prompts | AI (phantom-deps): Stable false positive for this package's bundled build. | ai | |
| phantom-deps | phantom-dep:@commitlint/ensure | AI (phantom-deps): Stable false positive for this package's bundled build. | ai | |
| phantom-deps | phantom-dep:@textlint/ast-node-types | AI (phantom-deps): Stable false positive for this package's bundled build. | ai | |
| phantom-deps | phantom-dep:jsonc-parser | AI (phantom-deps): Stable false positive for this package's bundled build. | ai | |
| semgrep | semgrep:env-bulk-read | AI (semgrep): Config loader filters env keys by known prefix; not exfiltration. | ai |
Versions (showing 100 of 182)
| Version | Deps | Published |
|---|---|---|
| 2.131.116 | 29 / 6 | |
| 2.131.115 | 29 / 6 | |
| 2.131.114 | 29 / 6 | |
| 2.131.113 | 29 / 6 | |
| 2.131.112 | 29 / 6 | |
| 2.131.109 | 29 / 6 | |
| 2.131.107 | 29 / 6 | |
| 2.131.106 | 29 / 6 | |
| 2.131.100 | 29 / 6 | |
| 2.131.99 | 29 / 6 | |
| 2.131.98 | 29 / 6 | |
| 2.131.97 | 29 / 6 | |
| 2.131.94 | 29 / 6 | |
| 2.131.93 | 29 / 6 | |
| 2.131.92 | 29 / 6 | |
| 2.131.91 | 29 / 6 | |
| 2.131.90 | 29 / 6 | |
| 2.131.89 | 29 / 6 | |
| 2.131.88 | 29 / 6 | |
| 2.131.87 | 29 / 6 | |
| 2.131.86 | 29 / 6 | |
| 2.131.85 | 29 / 6 | |
| 2.131.84 | 29 / 6 | |
| 2.131.83 | 29 / 6 | |
| 2.131.82 | 29 / 6 | |
| 2.131.81 | 29 / 6 | |
| 2.131.80 | 29 / 6 | |
| 2.131.79 | 29 / 6 | |
| 2.131.78 | 29 / 6 | |
| 2.131.77 | 29 / 6 | |
| 2.131.76 | 29 / 6 | |
| 2.131.75 | 29 / 6 | |
| 2.131.74 | 29 / 6 | |
| 2.131.73 | 29 / 6 | |
| 2.131.72 | 29 / 6 | |
| 2.131.71 | 29 / 6 | |
| 2.131.69 | 29 / 6 | |
| 2.131.68 | 29 / 6 | |
| 2.131.67 | 29 / 6 | |
| 2.131.66 | 29 / 6 | |
| 2.131.65 | 29 / 6 | |
| 2.131.64 | 29 / 6 | |
| 2.131.63 | 29 / 6 | |
| 2.131.62 | 29 / 6 | |
| 2.131.61 | 29 / 6 | |
| 2.131.60 | 29 / 6 | |
| 2.131.59 | 29 / 6 | |
| 2.131.58 | 29 / 6 | |
| 2.131.57 | 29 / 6 | |
| 2.131.56 | 29 / 6 | |
| 2.131.55 | 29 / 6 | |
| 2.131.53 | 29 / 6 | |
| 2.131.52 | 29 / 6 | |
| 2.131.51 | 29 / 6 | |
| 2.131.50 | 29 / 6 | |
| 2.131.49 | 29 / 6 | |
| 2.131.48 | 29 / 6 | |
| 2.131.47 | 29 / 6 | |
| 2.131.46 | 29 / 6 | |
| 2.131.45 | 29 / 6 | |
| 2.131.44 | 29 / 6 | |
| 2.131.43 | 29 / 6 | |
| 2.131.42 | 29 / 6 | |
| 2.131.41 | 29 / 6 | |
| 2.131.40 | 29 / 6 | |
| 2.131.39 | 29 / 6 | |
| 2.131.38 | 29 / 6 | |
| 2.131.37 | 29 / 6 | |
| 2.131.36 | 29 / 6 | |
| 2.131.35 | 29 / 6 | |
| 2.131.34 | 29 / 6 | |
| 2.131.33 | 30 / 6 | |
| 2.131.32 | 28 / 8 | |
| 2.131.31 | 28 / 8 | |
| 2.131.29 | 28 / 8 | |
| 2.131.28 | 28 / 8 | |
| 2.131.27 | 28 / 8 | |
| 2.131.26 | 28 / 8 | |
| 2.131.25 | 28 / 8 | |
| 2.131.24 | 28 / 8 | |
| 2.131.23 | 28 / 8 | |
| 2.131.22 | 28 / 8 | |
| 2.131.21 | 28 / 8 | |
| 2.131.20 | 28 / 8 | |
| 2.131.19 | 28 / 8 | |
| 2.131.18 | 28 / 8 | |
| 2.131.17 | 28 / 8 | |
| 2.131.16 | 28 / 8 | |
| 2.131.15 | 28 / 8 | |
| 2.131.14 | 28 / 8 | |
| 2.131.12 | 28 / 8 | |
| 2.131.11 | 28 / 8 | |
| 2.131.10 | 28 / 8 | |
| 2.131.9 | 28 / 8 | |
| 2.131.8 | 28 / 8 | |
| 2.131.7 | 28 / 8 | |
| 2.131.6 | 28 / 7 | |
| 2.130.40 | 26 / 7 | |
| 2.130.39 | 26 / 7 | |
| 2.130.38 | 26 / 7 |
v2.131.116
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.131.115
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.131.114
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.131.113
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.131.112
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.131.109
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.131.107
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.131.106
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.131.100
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.131.99
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.131.98
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.131.97
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.131.94
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.131.93
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.131.92
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.131.91
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.131.90
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.131.89
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.131.88
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.131.87
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.131.86
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.