@storm-software/tsup
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Transition from stormie-bot to GitHub Actions CI/CD is confirmed by SLSA provenance attestation; consistent with org-wide automation migration. | ai | |
| typosquat | typosquat.levenshtein:yup | AI (typosquat): Scoped @storm-software/tsup is a tsup wrapper, not a yup typosquat; Levenshtein match is coincidental. | ai | |
| phantom-deps | phantom-dep:@storm-software/config-tools | AI (phantom-deps): Same-org dependency; likely used transitively or in build config rather than direct import. | ai |
Versions (showing 51 of 255)
| Version | Deps | Published |
|---|---|---|
| 0.2.266 | 2 / 4 | |
| 0.2.265 | 2 / 4 | |
| 0.2.264 | 2 / 4 | |
| 0.2.263 | 2 / 4 | |
| 0.2.262 | 2 / 4 | |
| 0.2.259 | 2 / 4 | |
| 0.2.257 | 2 / 4 | |
| 0.2.256 | 2 / 4 | |
| 0.2.250 | 2 / 4 | |
| 0.2.249 | 2 / 4 | |
| 0.2.248 | 2 / 4 | |
| 0.2.247 | 2 / 4 | |
| 0.2.244 | 2 / 4 | |
| 0.2.243 | 2 / 4 | |
| 0.2.242 | 2 / 4 | |
| 0.2.241 | 2 / 4 | |
| 0.2.240 | 2 / 4 | |
| 0.2.239 | 2 / 4 | |
| 0.2.238 | 2 / 4 | |
| 0.2.237 | 2 / 4 | |
| 0.2.236 | 2 / 4 | |
| 0.2.235 | 2 / 4 | |
| 0.2.234 | 2 / 4 | |
| 0.2.233 | 2 / 4 | |
| 0.2.232 | 2 / 4 | |
| 0.2.231 | 2 / 4 | |
| 0.2.230 | 2 / 4 | |
| 0.2.229 | 2 / 4 | |
| 0.2.228 | 2 / 4 | |
| 0.2.227 | 2 / 4 | |
| 0.2.226 | 2 / 4 | |
| 0.2.225 | 2 / 4 | |
| 0.2.224 | 2 / 4 | |
| 0.2.223 | 2 / 4 | |
| 0.2.222 | 2 / 4 | |
| 0.2.221 | 2 / 4 | |
| 0.2.220 | 2 / 4 | |
| 0.2.219 | 2 / 4 | |
| 0.2.218 | 2 / 4 | |
| 0.2.217 | 2 / 4 | |
| 0.2.216 | 2 / 4 | |
| 0.2.215 | 2 / 4 | |
| 0.2.214 | 2 / 4 | |
| 0.2.213 | 2 / 4 | |
| 0.2.212 | 2 / 4 | |
| 0.2.211 | 2 / 4 | |
| 0.2.210 | 2 / 4 | |
| 0.2.209 | 2 / 4 | |
| 0.2.208 | 2 / 4 | |
| 0.2.207 | 2 / 4 | |
| 0.2.206 | 2 / 4 |
v0.2.266
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.265
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.264
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.263
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.262
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.259
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.257
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.256
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.250
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.249
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.248
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.247
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.244
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.243
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.242
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.241
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.240
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.239
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.238
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.237
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.