← Home

@storm-software/untyped

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

stormie-botsullivanpj

Keywords

acidiccyclone-uiuntypedmonorepostormstorm-opsstorm-stacksullivanpj

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff encoded-string-file:bin/untyped.cjs AI (source-diff): Base64 string is llhttp WASM binary bundled via undici — standard pattern, not obfuscation. ai
source-diff encoded-string-file:bin/untyped.js AI (source-diff): Same llhttp WASM base64 blob in ESM build; stable false positive for this package. ai
phantom-deps phantom-dep:nx AI (phantom-deps): nx is declared as a dependency and referenced in config/CLI files; not a security concern for this build utility package. ai
dependencies unvetted-dep:nx AI (dependencies): nx is a well-known monorepo build tool from Nrwl; its use in Storm Software build utilities is expected and legitimate across all versions. ai
phantom-deps phantom-dep:knitwork AI (phantom-deps): knitwork is a legitimate code-generation utility; phantom-dep finding is a code quality note, not a security risk for this package. ai
phantom-deps phantom-dep:commander AI (phantom-deps): commander is a well-known CLI framework; used in bin entry points. Not a security concern for this package. ai
bogus-package bogus-package AI (bogus-package): README link dump reflects Storm Software's ecosystem-wide documentation style across 412 versions; not a phishing indicator for this established monorepo package. ai
semgrep semgrep:env-bulk-read AI (semgrep): env-bulk-read is used to read namespaced STORM_EXTENSION_* config vars — a legitimate config-library pattern stable across versions of this package. ai
phantom-deps phantom-dep:@storm-software/config-tools AI (phantom-deps): Same-org dependency (@storm-software scope); declared but bundled/indirectly used — stable false positive for this monorepo package. ai

Versions (showing 51 of 417)

View all versions
Version Deps Published
0.24.251 5 / 3
0.24.250 5 / 3
0.24.249 5 / 3
0.24.248 5 / 3
0.24.247 5 / 3
0.24.246 5 / 3
0.24.243 5 / 3
0.24.241 5 / 3
0.24.240 5 / 3
0.24.234 5 / 3
0.24.233 5 / 3
0.24.232 5 / 3
0.24.231 5 / 3
0.24.228 5 / 3
0.24.227 5 / 3
0.24.226 5 / 3
0.24.225 5 / 3
0.24.224 5 / 3
0.24.223 5 / 3
0.24.222 5 / 3
0.24.221 5 / 3
0.24.220 5 / 3
0.24.219 5 / 3
0.24.218 5 / 3
0.24.217 5 / 3
0.24.216 5 / 3
0.24.215 5 / 3
0.24.214 5 / 3
0.24.213 5 / 3
0.24.212 5 / 3
0.24.211 5 / 3
0.24.210 5 / 3
0.24.209 5 / 3
0.24.208 5 / 3
0.24.207 5 / 3
0.24.206 5 / 3
0.24.205 5 / 3
0.24.204 5 / 3
0.24.203 5 / 3
0.24.202 5 / 3
0.24.201 5 / 3
0.24.200 5 / 3
0.24.199 5 / 3
0.24.198 5 / 3
0.24.197 5 / 3
0.24.196 5 / 3
0.24.195 5 / 3
0.24.194 5 / 3
0.24.193 5 / 3
0.24.192 5 / 3
0.24.191 5 / 3

v0.24.251

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.24.250

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.24.249

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.24.248

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.24.247

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.24.246

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.24.243

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.24.241

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.24.240

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.24.234

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.24.233

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.24.232

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.24.231

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.24.228

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.24.227

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.24.226

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.24.225

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.24.224

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.24.223

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.24.222

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.24.221

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.24.220

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.