← Home

@storm-software/tsdown

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

stormie-botsullivanpj

Keywords

acidiccyclone-uitsdownmonorepostormstorm-opsstorm-stacksullivanpj

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): SLSA provenance attestation present; gitHead absence is a minor metadata gap, not a supply chain risk for this publisher. ai
provenance publisher-changed AI (provenance): Transition from stormie-bot to GitHub Actions CI publisher; SLSA provenance attestation confirms legitimate CI/CD pipeline. ai
publish-pattern new-deps-added AI (publish-pattern): New deps are first-party Storm Software monorepo packages; consistent with internal refactoring pattern across 459 versions. ai
phantom-deps phantom-dep:rolldown AI (phantom-deps): Declared runtime dep; bundler integration, stable false positive. ai
phantom-deps phantom-dep:commander AI (phantom-deps): Declared runtime dep; CLI binary uses commander, stable false positive. ai
phantom-deps phantom-dep:tsup AI (phantom-deps): Declared runtime dep in package.json; used via config/build toolchain, not direct import. ai
phantom-deps phantom-dep:source-map AI (phantom-deps): Declared runtime dep; source map handling in build output, stable false positive. ai
phantom-deps phantom-dep:@storm-software/config-tools AI (phantom-deps): Same-org dep declared in dependencies; stable false positive for this package family. ai
phantom-deps phantom-dep:es-toolkit AI (phantom-deps): Declared runtime dep; utility library used in build toolchain. ai
phantom-deps phantom-dep:globby AI (phantom-deps): Declared runtime dep; used in config/build utilities, stable false positive for this package. ai
phantom-deps phantom-dep:chokidar AI (phantom-deps): Declared runtime dep; used in watch/build toolchain, stable false positive. ai

Versions (showing 51 of 528)

View all versions
Version Deps Published
0.45.270 12 / 8
0.45.269 12 / 8
0.45.268 12 / 8
0.45.267 12 / 8
0.45.266 12 / 8
0.45.265 12 / 8
0.45.262 12 / 8
0.45.260 12 / 8
0.45.259 12 / 8
0.45.253 12 / 8
0.45.252 12 / 8
0.45.251 12 / 8
0.45.250 12 / 8
0.45.247 12 / 8
0.45.246 12 / 8
0.45.245 12 / 8
0.45.244 12 / 8
0.45.243 12 / 8
0.45.242 12 / 8
0.45.241 12 / 8
0.45.240 12 / 8
0.45.239 12 / 8
0.45.238 12 / 8
0.45.237 12 / 8
0.45.236 12 / 8
0.45.235 12 / 8
0.45.234 12 / 8
0.45.233 12 / 8
0.45.232 12 / 8
0.45.231 12 / 8
0.45.230 11 / 9
0.45.229 11 / 9
0.45.228 11 / 9
0.45.227 11 / 9
0.45.226 11 / 9
0.45.225 11 / 9
0.45.224 11 / 9
0.45.223 11 / 9
0.45.222 11 / 9
0.45.221 11 / 9
0.45.220 11 / 9
0.45.219 11 / 9
0.45.218 11 / 9
0.45.217 11 / 9
0.45.216 11 / 9
0.45.215 11 / 9
0.45.214 11 / 9
0.45.213 11 / 9
0.45.212 11 / 9
0.45.211 11 / 9
0.45.210 11 / 9

v0.45.270

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.45.269

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.45.268

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.45.267

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.45.266

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.45.265

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.45.262

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.45.260

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.45.259

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.45.253

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.45.252

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.45.251

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.45.250

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.45.247

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.45.246

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.45.245

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.45.244

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.45.243

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.45.242

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.45.241

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.45.240

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.45.239

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.