@storm-software/linting-tools
⚡ A package containing various linting tools used to validate syntax, enforce design standards, and format code in a Storm workspace.
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:bin/dist-UNI6WBNY.js | AI (source-diff): ESM counterpart of the same tsup bundle; same rationale as the CJS variant. | ai | |
| source-diff | obfuscated-file:bin/dist-CKGJU76Y.cjs | AI (source-diff): Standard tsup bundle output for a CLI linting tool; consistent with package's build pattern across 854 versions. | ai | |
| source-diff | obfuscated-file:bin/dist-4NPPYNEO.js | AI (source-diff): Standard tsup-bundled ESM CLI output; minification is expected in bin/ artifacts. | ai | |
| source-diff | obfuscated-file:bin/dist-W2LWBS72.cjs | AI (source-diff): Standard tsup-bundled CLI output for a linting tools package; minification is expected in bin/ artifacts. | ai | |
| source-diff | obfuscated-file:bin/dist-EYKW3DH5.cjs | AI (source-diff): Standard tsup/bundler output; minified but not obfuscated — readable module paths and no malicious patterns. | ai | |
| source-diff | obfuscated-file:bin/dist-PJ4KGJZQ.js | AI (source-diff): ESM counterpart of the same bundled CLI output; same reasoning applies. | ai | |
| source-diff | obfuscated-file:bin/dist-TEEZZYBG.js | AI (source-diff): ESM counterpart of the same bundled CLI artifact; expected minified output. | ai | |
| source-diff | obfuscated-file:bin/dist-FQXVMSLF.cjs | AI (source-diff): Bundled CLI artifact from tsup build; consistent with linting tool packaging across all versions. | ai | |
| source-diff | obfuscated-file:bin/dist-TA6D52DW.js | AI (source-diff): ESM counterpart of the same CLI bundle; same rationale as the CJS variant. | ai | |
| source-diff | obfuscated-file:bin/dist-SXWKXAUN.cjs | AI (source-diff): Standard tsup/rollup bundle output for storm-lint CLI; readable module references confirm legitimate bundling. | ai | |
| source-diff | obfuscated-file:bin/dist-ZJ5AUXFT.js | AI (source-diff): ESM counterpart of the same bundled CLI output; consistent with this package's build pipeline. | ai | |
| source-diff | obfuscated-file:bin/dist-LZUZSGPH.cjs | AI (source-diff): Standard tsup/esbuild bundle output for a linting CLI; hashed filenames are normal for this package's build pipeline. | ai | |
| source-diff | obfuscated-file:bin/dist-52RMLTE5.cjs | AI (source-diff): Standard tsup-bundled CLI artifact; minification is expected for this linting tools package. | ai | |
| source-diff | obfuscated-file:bin/dist-FWSAV5L3.js | AI (source-diff): Standard tsup-bundled CLI artifact; minification is expected for this linting tools package. | ai | |
| source-diff | obfuscated-file:bin/dist-CCESLB2R.js | AI (source-diff): Standard tsup-bundled CLI artifact (ESM variant); minification is expected for this linting tools package. | ai | |
| source-diff | obfuscated-file:bin/dist-MHNJ3OEL.cjs | AI (source-diff): Standard tsup-bundled CLI artifact; minification is expected for this linting tools package. | ai | |
| source-diff | obfuscated-file:bin/dist-4FGVKHWK.js | AI (source-diff): ESM counterpart of the same tsup bundle; same rationale applies. | ai | |
| source-diff | obfuscated-file:bin/dist-NL63INKN.cjs | AI (source-diff): Standard tsup/esbuild bundle output; readable module paths confirm legitimate bundled dependencies. | ai | |
| source-diff | obfuscated-file:bin/dist-KGN7PNLO.js | AI (source-diff): Standard tsup ESM bundle output; same pattern as CJS counterpart, stable for this package. | ai | |
| source-diff | obfuscated-file:bin/dist-RMMG4RJ4.cjs | AI (source-diff): Standard tsup bundle output for a linting CLI; pattern is stable across versions of this package. | ai | |
| source-diff | obfuscated-file:bin/dist-RWDY5X6T.js | AI (source-diff): Standard tsup/esbuild bundle output for a linting CLI; not obfuscation. | ai | |
| source-diff | obfuscated-file:bin/dist-Z5LQ3WIL.cjs | AI (source-diff): Standard tsup/esbuild bundle output for a linting CLI; not obfuscation. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): Linting tool that spawns external linters; child_process is expected and stable across versions. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): Subprocess env passing is standard for build/lint tools; no exfiltration pattern present. | ai | |
| phantom-deps | phantom-dep:@angular-devkit/architect | AI (phantom-deps): Declared runtime dep; referenced in config files as documented. | ai | |
| phantom-deps | phantom-dep:jiti | AI (phantom-deps): jiti is a declared runtime dependency used indirectly via config loading. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Reflect.get in Proxy/polyfill pattern; standard in bundled third-party libs. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Base64 decode in bundled utility code; no network send or obfuscation context. | ai | |
| semgrep | semgrep:env-bulk-read | AI (semgrep): Reads debug_ prefixed env vars only; standard debug library pattern. | ai |
Versions (showing 100 of 187)
v1.133.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.133.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.133.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.133.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.133.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.133.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.133.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.133.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.133.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.133.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.133.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.133.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.132.137
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.132.136
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.132.135
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.132.134
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.132.133
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.132.132
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.132.131
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.132.130
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.132.129
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.132.128
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.132.127
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.132.126
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.132.125
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.132.124
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.132.123
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.132.122
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.132.121
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.132.120
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.132.119
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.132.118
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.132.117
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.132.116
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.132.115
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.132.114
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.132.113
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.132.112
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.132.111
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.132.110
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.132.109
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.132.108
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.132.107
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.132.106
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.132.105
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.132.104
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.132.103
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.