← Home

@storm-software/linting-tools

⚡ A package containing various linting tools used to validate syntax, enforce design standards, and format code in a Storm workspace.

100
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

stormie-bot

Keywords

storm-softwaremonorepostorm-opssullivanpjmanypkgls-lintcspellbiomealextaplosyncpackzizmor

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:bin/dist-UNI6WBNY.js AI (source-diff): ESM counterpart of the same tsup bundle; same rationale as the CJS variant. ai
source-diff obfuscated-file:bin/dist-CKGJU76Y.cjs AI (source-diff): Standard tsup bundle output for a CLI linting tool; consistent with package's build pattern across 854 versions. ai
source-diff obfuscated-file:bin/dist-4NPPYNEO.js AI (source-diff): Standard tsup-bundled ESM CLI output; minification is expected in bin/ artifacts. ai
source-diff obfuscated-file:bin/dist-W2LWBS72.cjs AI (source-diff): Standard tsup-bundled CLI output for a linting tools package; minification is expected in bin/ artifacts. ai
source-diff obfuscated-file:bin/dist-EYKW3DH5.cjs AI (source-diff): Standard tsup/bundler output; minified but not obfuscated — readable module paths and no malicious patterns. ai
source-diff obfuscated-file:bin/dist-PJ4KGJZQ.js AI (source-diff): ESM counterpart of the same bundled CLI output; same reasoning applies. ai
source-diff obfuscated-file:bin/dist-TEEZZYBG.js AI (source-diff): ESM counterpart of the same bundled CLI artifact; expected minified output. ai
source-diff obfuscated-file:bin/dist-FQXVMSLF.cjs AI (source-diff): Bundled CLI artifact from tsup build; consistent with linting tool packaging across all versions. ai
source-diff obfuscated-file:bin/dist-TA6D52DW.js AI (source-diff): ESM counterpart of the same CLI bundle; same rationale as the CJS variant. ai
source-diff obfuscated-file:bin/dist-SXWKXAUN.cjs AI (source-diff): Standard tsup/rollup bundle output for storm-lint CLI; readable module references confirm legitimate bundling. ai
source-diff obfuscated-file:bin/dist-ZJ5AUXFT.js AI (source-diff): ESM counterpart of the same bundled CLI output; consistent with this package's build pipeline. ai
source-diff obfuscated-file:bin/dist-LZUZSGPH.cjs AI (source-diff): Standard tsup/esbuild bundle output for a linting CLI; hashed filenames are normal for this package's build pipeline. ai
source-diff obfuscated-file:bin/dist-52RMLTE5.cjs AI (source-diff): Standard tsup-bundled CLI artifact; minification is expected for this linting tools package. ai
source-diff obfuscated-file:bin/dist-FWSAV5L3.js AI (source-diff): Standard tsup-bundled CLI artifact; minification is expected for this linting tools package. ai
source-diff obfuscated-file:bin/dist-CCESLB2R.js AI (source-diff): Standard tsup-bundled CLI artifact (ESM variant); minification is expected for this linting tools package. ai
source-diff obfuscated-file:bin/dist-MHNJ3OEL.cjs AI (source-diff): Standard tsup-bundled CLI artifact; minification is expected for this linting tools package. ai
source-diff obfuscated-file:bin/dist-4FGVKHWK.js AI (source-diff): ESM counterpart of the same tsup bundle; same rationale applies. ai
source-diff obfuscated-file:bin/dist-NL63INKN.cjs AI (source-diff): Standard tsup/esbuild bundle output; readable module paths confirm legitimate bundled dependencies. ai
source-diff obfuscated-file:bin/dist-KGN7PNLO.js AI (source-diff): Standard tsup ESM bundle output; same pattern as CJS counterpart, stable for this package. ai
source-diff obfuscated-file:bin/dist-RMMG4RJ4.cjs AI (source-diff): Standard tsup bundle output for a linting CLI; pattern is stable across versions of this package. ai
source-diff obfuscated-file:bin/dist-RWDY5X6T.js AI (source-diff): Standard tsup/esbuild bundle output for a linting CLI; not obfuscation. ai
source-diff obfuscated-file:bin/dist-Z5LQ3WIL.cjs AI (source-diff): Standard tsup/esbuild bundle output for a linting CLI; not obfuscation. ai
semgrep semgrep:child-process-import AI (semgrep): Linting tool that spawns external linters; child_process is expected and stable across versions. ai
semgrep semgrep:env-spread AI (semgrep): Subprocess env passing is standard for build/lint tools; no exfiltration pattern present. ai
phantom-deps phantom-dep:@angular-devkit/architect AI (phantom-deps): Declared runtime dep; referenced in config files as documented. ai
phantom-deps phantom-dep:jiti AI (phantom-deps): jiti is a declared runtime dependency used indirectly via config loading. ai
semgrep semgrep:api-obfuscation-reflect AI (semgrep): Reflect.get in Proxy/polyfill pattern; standard in bundled third-party libs. ai
semgrep semgrep:base64-decode AI (semgrep): Base64 decode in bundled utility code; no network send or obfuscation context. ai
semgrep semgrep:env-bulk-read AI (semgrep): Reads debug_ prefixed env vars only; standard debug library pattern. ai

Versions (showing 100 of 187)

Version Deps Published
1.133.67 2 / 28
1.133.66 2 / 28
1.133.65 2 / 28
1.133.64 2 / 28
1.133.63 2 / 28
1.133.62 2 / 28
1.133.61 2 / 28
1.133.60 2 / 28
1.133.59 2 / 28
1.133.58 2 / 28
1.133.57 2 / 28
1.133.56 2 / 28
1.133.55 2 / 28
1.133.54 2 / 28
1.133.53 2 / 28
1.133.52 2 / 28
1.133.51 2 / 28
1.133.50 2 / 28
1.133.49 2 / 28
1.133.48 2 / 28
1.133.47 2 / 28
1.133.46 2 / 28
1.133.45 2 / 28
1.133.44 2 / 28
1.133.43 2 / 28
1.133.41 2 / 28
1.133.40 2 / 28
1.133.39 2 / 28
1.133.38 2 / 28
1.133.37 2 / 28
1.133.36 2 / 28
1.133.35 2 / 28
1.133.32 2 / 28
1.133.31 2 / 28
1.133.30 2 / 28
1.133.29 2 / 28
1.133.28 2 / 28
1.133.27 2 / 28
1.133.26 2 / 28
1.133.25 2 / 28
1.133.24 2 / 28
1.133.23 2 / 28
1.133.22 2 / 28
1.133.21 2 / 28
1.133.20 2 / 28
1.133.19 2 / 28
1.133.18 2 / 28
1.133.17 2 / 28
1.133.16 2 / 28
1.133.15 2 / 28
1.133.14 2 / 28
1.133.13 2 / 28
1.133.12 2 / 28
1.133.11 2 / 28
1.133.10 2 / 28
1.133.9 2 / 28
1.133.8 2 / 28
1.133.7 2 / 28
1.133.6 2 / 28
1.133.5 2 / 28
1.133.4 2 / 28
1.133.3 2 / 28
1.133.2 2 / 28
1.133.1 2 / 28
1.133.0 2 / 28
1.132.137 2 / 28
1.132.136 2 / 28
1.132.135 2 / 28
1.132.134 2 / 28
1.132.133 2 / 28
1.132.132 2 / 28
1.132.131 2 / 28
1.132.130 2 / 28
1.132.129 2 / 28
1.132.128 2 / 28
1.132.127 2 / 28
1.132.126 2 / 28
1.132.125 2 / 28
1.132.124 2 / 28
1.132.123 2 / 28
1.132.122 2 / 28
1.132.121 2 / 28
1.132.120 2 / 28
1.132.119 2 / 28
1.132.118 2 / 28
1.132.117 2 / 28
1.132.116 2 / 28
1.132.115 2 / 28
1.132.114 2 / 28
1.132.113 2 / 28
1.132.112 2 / 28
1.132.111 2 / 28
1.132.110 2 / 28
1.132.109 2 / 28
1.132.108 2 / 28
1.132.107 2 / 28
1.132.106 2 / 28
1.132.105 2 / 28
1.132.104 2 / 28
1.132.103 2 / 28
Showing 100 of 187 Next page →

v1.133.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.133.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.133.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.133.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.133.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.133.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.133.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.133.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.133.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.133.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.133.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.133.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.132.137

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.132.136

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.132.135

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.132.134

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.132.133

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.132.132

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.132.131

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.132.130

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.132.129

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.132.128

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.132.127

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.132.126

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.132.125

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.132.124

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.132.123

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.132.122

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.132.121

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.132.120

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.132.119

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.132.118

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.132.117

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.132.116

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.132.115

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.132.114

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.132.113

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.132.112

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.132.111

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.132.110

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.132.109

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.132.108

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.132.107

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.132.106

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.132.105

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.132.104

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.132.103

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.