@storm-software/pulumi-tools
Tools for managing Pulumi infrastructure within a Nx workspace.
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:env-spread | AI (semgrep): Pulumi executor intentionally passes full env to child process; standard pattern for infrastructure tooling. | ai | |
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions publisher is consistent with CI/CD automation; backed by SLSA provenance attestation. | ai | |
| phantom-deps | phantom-dep:@pulumi/awsx | AI (phantom-deps): Package is declared as a runtime dep and referenced in config; not directly imported is expected for optional Pulumi provider usage. | ai |
Versions (showing 51 of 491)
| Version | Deps | Published |
|---|---|---|
| 0.22.291 | 9 / 4 | |
| 0.22.290 | 9 / 4 | |
| 0.22.289 | 9 / 4 | |
| 0.22.288 | 9 / 4 | |
| 0.22.287 | 9 / 4 | |
| 0.22.284 | 9 / 4 | |
| 0.22.282 | 9 / 4 | |
| 0.22.281 | 9 / 4 | |
| 0.22.275 | 9 / 4 | |
| 0.22.274 | 9 / 4 | |
| 0.22.273 | 9 / 4 | |
| 0.22.272 | 9 / 4 | |
| 0.22.269 | 9 / 4 | |
| 0.22.268 | 9 / 4 | |
| 0.22.267 | 9 / 4 | |
| 0.22.266 | 9 / 4 | |
| 0.22.265 | 9 / 4 | |
| 0.22.264 | 9 / 4 | |
| 0.22.263 | 9 / 4 | |
| 0.22.262 | 9 / 4 | |
| 0.22.261 | 9 / 4 | |
| 0.22.260 | 9 / 4 | |
| 0.22.259 | 9 / 4 | |
| 0.22.258 | 9 / 4 | |
| 0.22.257 | 9 / 4 | |
| 0.22.256 | 9 / 4 | |
| 0.22.255 | 9 / 4 | |
| 0.22.254 | 9 / 4 | |
| 0.22.253 | 9 / 4 | |
| 0.22.252 | 9 / 4 | |
| 0.22.251 | 9 / 4 | |
| 0.22.250 | 9 / 4 | |
| 0.22.249 | 9 / 4 | |
| 0.22.248 | 9 / 4 | |
| 0.22.246 | 9 / 4 | |
| 0.22.244 | 9 / 4 | |
| 0.22.243 | 9 / 4 | |
| 0.22.242 | 9 / 4 | |
| 0.22.241 | 9 / 4 | |
| 0.22.240 | 9 / 4 | |
| 0.22.239 | 9 / 4 | |
| 0.22.238 | 9 / 4 | |
| 0.22.237 | 9 / 4 | |
| 0.22.236 | 9 / 4 | |
| 0.22.235 | 9 / 4 | |
| 0.22.234 | 9 / 4 | |
| 0.22.233 | 9 / 4 | |
| 0.22.232 | 9 / 4 | |
| 0.22.231 | 9 / 4 | |
| 0.22.230 | 9 / 4 | |
| 0.22.227 | 9 / 4 |
v0.22.291
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.22.290
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.22.289
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.22.288
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.22.287
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.22.284
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.22.282
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.22.281
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.22.275
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.22.274
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.22.273
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.22.272
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.22.269
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.22.268
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.22.267
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.22.266
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.22.265
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.22.264
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.22.263
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.22.262
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.22.261
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.