@storm-software/unbuild
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Storm-ops monorepo migrated publishing to GitHub Actions CI; SLSA attestation confirms legitimate pipeline. | ai | |
| phantom-deps | phantom-dep:@storm-software/config-tools | AI (phantom-deps): Same-org dependency; phantom-dep heuristic is a false positive here. | ai | |
| phantom-deps | phantom-dep:jiti | AI (phantom-deps): jiti is a declared runtime dep used in config loading; phantom-dep heuristic fires on indirect usage. | ai | |
| phantom-deps | phantom-dep:pkg-types | AI (phantom-deps): pkg-types is a declared runtime dep; phantom-dep heuristic is a false positive for config-file usage. | ai | |
| typosquat | typosquat.levenshtein:esbuild | AI (typosquat): @storm-software/unbuild wraps the 'unbuild' build tool and depends on esbuild directly — not a typosquat. Scoped package name is clearly intentional. | ai | |
| semgrep | semgrep:env-bulk-read | AI (semgrep): env-bulk-read filters by a STORM_EXTENSION_ prefix — standard namespaced config reading in a build tool, not credential harvesting. | ai |
Versions (showing 51 of 517)
| Version | Deps | Published |
|---|---|---|
| 0.57.269 | 13 / 7 | |
| 0.57.268 | 13 / 7 | |
| 0.57.267 | 13 / 7 | |
| 0.57.266 | 13 / 7 | |
| 0.57.265 | 13 / 7 | |
| 0.57.262 | 13 / 7 | |
| 0.57.260 | 13 / 7 | |
| 0.57.259 | 13 / 7 | |
| 0.57.253 | 13 / 7 | |
| 0.57.252 | 13 / 7 | |
| 0.57.251 | 13 / 7 | |
| 0.57.250 | 13 / 7 | |
| 0.57.247 | 13 / 7 | |
| 0.57.246 | 13 / 7 | |
| 0.57.245 | 13 / 7 | |
| 0.57.244 | 13 / 7 | |
| 0.57.243 | 13 / 7 | |
| 0.57.242 | 13 / 7 | |
| 0.57.241 | 13 / 7 | |
| 0.57.240 | 13 / 7 | |
| 0.57.239 | 13 / 7 | |
| 0.57.238 | 13 / 7 | |
| 0.57.237 | 13 / 7 | |
| 0.57.236 | 13 / 7 | |
| 0.57.235 | 13 / 7 | |
| 0.57.234 | 13 / 7 | |
| 0.57.233 | 13 / 7 | |
| 0.57.232 | 13 / 7 | |
| 0.57.231 | 13 / 7 | |
| 0.57.230 | 13 / 6 | |
| 0.57.229 | 13 / 6 | |
| 0.57.228 | 13 / 6 | |
| 0.57.227 | 13 / 6 | |
| 0.57.226 | 13 / 6 | |
| 0.57.225 | 13 / 6 | |
| 0.57.223 | 13 / 6 | |
| 0.57.222 | 13 / 6 | |
| 0.57.221 | 13 / 6 | |
| 0.57.220 | 13 / 6 | |
| 0.57.219 | 13 / 6 | |
| 0.57.218 | 13 / 6 | |
| 0.57.217 | 13 / 6 | |
| 0.57.216 | 13 / 6 | |
| 0.57.215 | 13 / 6 | |
| 0.57.214 | 13 / 6 | |
| 0.57.213 | 13 / 6 | |
| 0.57.212 | 13 / 6 | |
| 0.57.211 | 13 / 6 | |
| 0.57.210 | 13 / 6 | |
| 0.57.209 | 13 / 6 | |
| 0.57.208 | 13 / 6 |
v0.57.269
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.57.268
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.57.267
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.57.266
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.57.265
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.57.262
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.57.260
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.57.259
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.57.253
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.57.252
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.57.251
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.57.250
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.57.247
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.57.246
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.57.245
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.57.244
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.57.243
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.57.242
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.57.241
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.57.240
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.57.239
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.