@storm-software/prettier
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | source-size-tripled | AI (source-diff): Size increase reflects added config JSON files (all.json, jsdoc.json, etc.) visible in package exports — not injected payload. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): prettier-plugin-packagejson is a well-known prettier plugin; replaces prettier-plugin-pkg, benign swap. | ai | |
| provenance | publisher-changed | AI (provenance): Transition from stormie-bot to GitHub Actions CI is consistent with automation; SLSA attestation confirms legitimate pipeline. | ai | |
| phantom-deps | phantom-dep:prettier-plugin-pkg | AI (phantom-deps): prettier-plugin-pkg is a config-file-referenced prettier plugin; not directly imported by design in a prettier config package. | ai | |
| dependencies | unvetted-dep:prettier-plugin-toml | AI (dependencies): Well-known prettier plugin; stable dependency for this config package. | ai | |
| dependencies | unvetted-dep:prettier-plugin-sh | AI (dependencies): Well-known prettier plugin; stable dependency for this config package. | ai | |
| dependencies | unvetted-dep:prettier-plugin-jsdoc | AI (dependencies): Well-known prettier plugin; stable dependency for this config package. | ai | |
| phantom-deps | phantom-dep:prettier-plugin-toml | AI (phantom-deps): Prettier plugins are loaded via config, not direct imports; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:prettier-plugin-organize-imports | AI (phantom-deps): Prettier plugins are loaded via config, not direct imports; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:prettier-plugin-packagejson | AI (phantom-deps): Prettier plugins are loaded via config, not direct imports; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:prettier-plugin-jsdoc | AI (phantom-deps): Prettier plugins are loaded via config, not direct imports; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:prettier-plugin-sh | AI (phantom-deps): Prettier plugins are loaded via config, not direct imports; stable pattern for this package. | ai |
Versions (showing 51 of 581)
| Version | Deps | Published |
|---|---|---|
| 0.59.162 | 5 / 6 | |
| 0.59.161 | 5 / 6 | |
| 0.59.160 | 5 / 6 | |
| 0.59.159 | 5 / 6 | |
| 0.59.158 | 5 / 6 | |
| 0.59.157 | 5 / 6 | |
| 0.59.154 | 5 / 6 | |
| 0.59.152 | 5 / 6 | |
| 0.59.151 | 5 / 6 | |
| 0.59.145 | 5 / 6 | |
| 0.59.144 | 5 / 6 | |
| 0.59.143 | 5 / 6 | |
| 0.59.142 | 5 / 6 | |
| 0.59.139 | 5 / 6 | |
| 0.59.138 | 5 / 6 | |
| 0.59.137 | 5 / 6 | |
| 0.59.136 | 5 / 6 | |
| 0.59.135 | 5 / 6 | |
| 0.59.134 | 5 / 6 | |
| 0.59.133 | 5 / 6 | |
| 0.59.132 | 5 / 6 | |
| 0.59.131 | 5 / 6 | |
| 0.59.130 | 5 / 6 | |
| 0.59.129 | 5 / 6 | |
| 0.59.128 | 5 / 6 | |
| 0.59.127 | 5 / 6 | |
| 0.59.126 | 5 / 6 | |
| 0.59.125 | 5 / 6 | |
| 0.59.124 | 5 / 6 | |
| 0.59.123 | 5 / 6 | |
| 0.59.122 | 5 / 6 | |
| 0.59.121 | 5 / 6 | |
| 0.59.120 | 5 / 6 | |
| 0.59.119 | 5 / 6 | |
| 0.59.118 | 5 / 6 | |
| 0.59.117 | 5 / 6 | |
| 0.59.116 | 5 / 6 | |
| 0.59.115 | 5 / 6 | |
| 0.59.114 | 5 / 6 | |
| 0.59.113 | 5 / 6 | |
| 0.59.112 | 5 / 6 | |
| 0.59.111 | 5 / 6 | |
| 0.59.110 | 5 / 6 | |
| 0.59.109 | 5 / 6 | |
| 0.59.108 | 5 / 6 | |
| 0.59.107 | 5 / 6 | |
| 0.59.106 | 5 / 6 | |
| 0.59.105 | 5 / 6 | |
| 0.59.104 | 5 / 6 | |
| 0.59.103 | 5 / 6 | |
| 0.59.102 | 5 / 6 |
v0.59.162
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.59.161
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.59.160
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.59.159
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.59.158
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.59.157
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.59.154
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.59.152
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.59.151
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.59.145
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.59.144
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.59.143
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.59.142
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.59.139
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.59.138
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.59.137
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.59.136
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.59.135
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.59.134
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.59.133
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.59.132
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.