@storm-software/untyped
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | encoded-string-file:bin/untyped.cjs | AI (source-diff): Base64 string is llhttp WASM binary bundled via undici — standard pattern, not obfuscation. | ai | |
| source-diff | encoded-string-file:bin/untyped.js | AI (source-diff): Same llhttp WASM base64 blob in ESM build; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:nx | AI (phantom-deps): nx is declared as a dependency and referenced in config/CLI files; not a security concern for this build utility package. | ai | |
| dependencies | unvetted-dep:nx | AI (dependencies): nx is a well-known monorepo build tool from Nrwl; its use in Storm Software build utilities is expected and legitimate across all versions. | ai | |
| phantom-deps | phantom-dep:knitwork | AI (phantom-deps): knitwork is a legitimate code-generation utility; phantom-dep finding is a code quality note, not a security risk for this package. | ai | |
| phantom-deps | phantom-dep:commander | AI (phantom-deps): commander is a well-known CLI framework; used in bin entry points. Not a security concern for this package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): README link dump reflects Storm Software's ecosystem-wide documentation style across 412 versions; not a phishing indicator for this established monorepo package. | ai | |
| semgrep | semgrep:env-bulk-read | AI (semgrep): env-bulk-read is used to read namespaced STORM_EXTENSION_* config vars — a legitimate config-library pattern stable across versions of this package. | ai | |
| phantom-deps | phantom-dep:@storm-software/config-tools | AI (phantom-deps): Same-org dependency (@storm-software scope); declared but bundled/indirectly used — stable false positive for this monorepo package. | ai |
Versions (showing 51 of 417)
| Version | Deps | Published |
|---|---|---|
| 0.24.251 | 5 / 3 | |
| 0.24.250 | 5 / 3 | |
| 0.24.249 | 5 / 3 | |
| 0.24.248 | 5 / 3 | |
| 0.24.247 | 5 / 3 | |
| 0.24.246 | 5 / 3 | |
| 0.24.243 | 5 / 3 | |
| 0.24.241 | 5 / 3 | |
| 0.24.240 | 5 / 3 | |
| 0.24.234 | 5 / 3 | |
| 0.24.233 | 5 / 3 | |
| 0.24.232 | 5 / 3 | |
| 0.24.231 | 5 / 3 | |
| 0.24.228 | 5 / 3 | |
| 0.24.227 | 5 / 3 | |
| 0.24.226 | 5 / 3 | |
| 0.24.225 | 5 / 3 | |
| 0.24.224 | 5 / 3 | |
| 0.24.223 | 5 / 3 | |
| 0.24.222 | 5 / 3 | |
| 0.24.221 | 5 / 3 | |
| 0.24.220 | 5 / 3 | |
| 0.24.219 | 5 / 3 | |
| 0.24.218 | 5 / 3 | |
| 0.24.217 | 5 / 3 | |
| 0.24.216 | 5 / 3 | |
| 0.24.215 | 5 / 3 | |
| 0.24.214 | 5 / 3 | |
| 0.24.213 | 5 / 3 | |
| 0.24.212 | 5 / 3 | |
| 0.24.211 | 5 / 3 | |
| 0.24.210 | 5 / 3 | |
| 0.24.209 | 5 / 3 | |
| 0.24.208 | 5 / 3 | |
| 0.24.207 | 5 / 3 | |
| 0.24.206 | 5 / 3 | |
| 0.24.205 | 5 / 3 | |
| 0.24.204 | 5 / 3 | |
| 0.24.203 | 5 / 3 | |
| 0.24.202 | 5 / 3 | |
| 0.24.201 | 5 / 3 | |
| 0.24.200 | 5 / 3 | |
| 0.24.199 | 5 / 3 | |
| 0.24.198 | 5 / 3 | |
| 0.24.197 | 5 / 3 | |
| 0.24.196 | 5 / 3 | |
| 0.24.195 | 5 / 3 | |
| 0.24.194 | 5 / 3 | |
| 0.24.193 | 5 / 3 | |
| 0.24.192 | 5 / 3 | |
| 0.24.191 | 5 / 3 |
v0.24.251
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.24.250
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.24.249
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.24.248
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.24.247
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.24.246
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.24.243
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.24.241
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.24.240
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.24.234
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.24.233
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.24.232
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.24.231
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.24.228
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.24.227
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.24.226
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.24.225
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.24.224
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.24.223
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.24.222
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.24.221
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.24.220
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.