@storm-software/npm-tools
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions CI publishing is confirmed by SLSA provenance attestation; consistent with org-level automation. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Established monorepo package with SLSA provenance; README signals are monorepo boilerplate artifacts, not spam. | ai | |
| phantom-deps | phantom-dep:@storm-software/config | AI (phantom-deps): Same-org dependency; likely used transitively or in type-only context within this monorepo package. | ai |
Versions (showing 51 of 295)
| Version | Deps | Published |
|---|---|---|
| 0.6.227 | 4 / 2 | |
| 0.6.226 | 4 / 2 | |
| 0.6.225 | 4 / 2 | |
| 0.6.224 | 4 / 2 | |
| 0.6.223 | 4 / 2 | |
| 0.6.222 | 4 / 2 | |
| 0.6.219 | 4 / 2 | |
| 0.6.217 | 4 / 2 | |
| 0.6.216 | 4 / 2 | |
| 0.6.210 | 4 / 2 | |
| 0.6.209 | 4 / 2 | |
| 0.6.208 | 4 / 2 | |
| 0.6.207 | 4 / 2 | |
| 0.6.204 | 4 / 2 | |
| 0.6.203 | 4 / 2 | |
| 0.6.202 | 4 / 2 | |
| 0.6.201 | 4 / 2 | |
| 0.6.200 | 4 / 2 | |
| 0.6.199 | 4 / 2 | |
| 0.6.198 | 4 / 2 | |
| 0.6.197 | 4 / 2 | |
| 0.6.196 | 4 / 2 | |
| 0.6.195 | 2 / 2 | |
| 0.6.194 | 2 / 2 | |
| 0.6.193 | 2 / 2 | |
| 0.6.192 | 2 / 2 | |
| 0.6.191 | 2 / 2 | |
| 0.6.190 | 2 / 2 | |
| 0.6.189 | 2 / 2 | |
| 0.6.188 | 2 / 2 | |
| 0.6.187 | 2 / 2 | |
| 0.6.186 | 2 / 2 | |
| 0.6.184 | 2 / 2 | |
| 0.6.183 | 2 / 2 | |
| 0.6.182 | 2 / 2 | |
| 0.6.181 | 2 / 2 | |
| 0.6.179 | 2 / 2 | |
| 0.6.178 | 2 / 2 | |
| 0.6.177 | 2 / 2 | |
| 0.6.176 | 2 / 2 | |
| 0.6.175 | 2 / 2 | |
| 0.6.174 | 2 / 2 | |
| 0.6.173 | 2 / 2 | |
| 0.6.172 | 2 / 2 | |
| 0.6.171 | 2 / 2 | |
| 0.6.170 | 2 / 2 | |
| 0.6.169 | 2 / 2 | |
| 0.6.168 | 2 / 2 | |
| 0.6.167 | 2 / 2 | |
| 0.6.166 | 2 / 2 | |
| 0.6.165 | 2 / 2 |
v0.6.227
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.226
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.225
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.224
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.223
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.222
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.219
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.217
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.216
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.210
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.209
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.208
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.207
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.204
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.203
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.202
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.201
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.200
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.199
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.198
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.197
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.