@storm-software/tsdown
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): SLSA provenance attestation present; gitHead absence is a minor metadata gap, not a supply chain risk for this publisher. | ai | |
| provenance | publisher-changed | AI (provenance): Transition from stormie-bot to GitHub Actions CI publisher; SLSA provenance attestation confirms legitimate CI/CD pipeline. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New deps are first-party Storm Software monorepo packages; consistent with internal refactoring pattern across 459 versions. | ai | |
| phantom-deps | phantom-dep:rolldown | AI (phantom-deps): Declared runtime dep; bundler integration, stable false positive. | ai | |
| phantom-deps | phantom-dep:commander | AI (phantom-deps): Declared runtime dep; CLI binary uses commander, stable false positive. | ai | |
| phantom-deps | phantom-dep:tsup | AI (phantom-deps): Declared runtime dep in package.json; used via config/build toolchain, not direct import. | ai | |
| phantom-deps | phantom-dep:source-map | AI (phantom-deps): Declared runtime dep; source map handling in build output, stable false positive. | ai | |
| phantom-deps | phantom-dep:@storm-software/config-tools | AI (phantom-deps): Same-org dep declared in dependencies; stable false positive for this package family. | ai | |
| phantom-deps | phantom-dep:es-toolkit | AI (phantom-deps): Declared runtime dep; utility library used in build toolchain. | ai | |
| phantom-deps | phantom-dep:globby | AI (phantom-deps): Declared runtime dep; used in config/build utilities, stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:chokidar | AI (phantom-deps): Declared runtime dep; used in watch/build toolchain, stable false positive. | ai |
Versions (showing 51 of 528)
| Version | Deps | Published |
|---|---|---|
| 0.45.270 | 12 / 8 | |
| 0.45.269 | 12 / 8 | |
| 0.45.268 | 12 / 8 | |
| 0.45.267 | 12 / 8 | |
| 0.45.266 | 12 / 8 | |
| 0.45.265 | 12 / 8 | |
| 0.45.262 | 12 / 8 | |
| 0.45.260 | 12 / 8 | |
| 0.45.259 | 12 / 8 | |
| 0.45.253 | 12 / 8 | |
| 0.45.252 | 12 / 8 | |
| 0.45.251 | 12 / 8 | |
| 0.45.250 | 12 / 8 | |
| 0.45.247 | 12 / 8 | |
| 0.45.246 | 12 / 8 | |
| 0.45.245 | 12 / 8 | |
| 0.45.244 | 12 / 8 | |
| 0.45.243 | 12 / 8 | |
| 0.45.242 | 12 / 8 | |
| 0.45.241 | 12 / 8 | |
| 0.45.240 | 12 / 8 | |
| 0.45.239 | 12 / 8 | |
| 0.45.238 | 12 / 8 | |
| 0.45.237 | 12 / 8 | |
| 0.45.236 | 12 / 8 | |
| 0.45.235 | 12 / 8 | |
| 0.45.234 | 12 / 8 | |
| 0.45.233 | 12 / 8 | |
| 0.45.232 | 12 / 8 | |
| 0.45.231 | 12 / 8 | |
| 0.45.230 | 11 / 9 | |
| 0.45.229 | 11 / 9 | |
| 0.45.228 | 11 / 9 | |
| 0.45.227 | 11 / 9 | |
| 0.45.226 | 11 / 9 | |
| 0.45.225 | 11 / 9 | |
| 0.45.224 | 11 / 9 | |
| 0.45.223 | 11 / 9 | |
| 0.45.222 | 11 / 9 | |
| 0.45.221 | 11 / 9 | |
| 0.45.220 | 11 / 9 | |
| 0.45.219 | 11 / 9 | |
| 0.45.218 | 11 / 9 | |
| 0.45.217 | 11 / 9 | |
| 0.45.216 | 11 / 9 | |
| 0.45.215 | 11 / 9 | |
| 0.45.214 | 11 / 9 | |
| 0.45.213 | 11 / 9 | |
| 0.45.212 | 11 / 9 | |
| 0.45.211 | 11 / 9 | |
| 0.45.210 | 11 / 9 |
v0.45.270
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.45.269
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.45.268
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.45.267
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.45.266
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.45.265
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.45.262
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.45.260
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.45.259
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.45.253
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.45.252
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.45.251
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.45.250
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.45.247
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.45.246
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.45.245
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.45.244
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.45.243
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.45.242
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.45.241
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.45.240
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.45.239
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.