← Home

@storm-software/workspace-tools

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

stormie-bot

Keywords

monoreponxstorm-softwarestorm-opsstormsullivanpj

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@actions/core AI (phantom-deps): Declared but not directly imported; used in CI/CD config context consistent with a workspace-tools package. ai
source-diff large-new-source-files AI (source-diff): High-velocity monorepo package; large file additions are routine across its 1367 versions. ai
dependencies unvetted-dep:@samchon/openapi AI (dependencies): Known OpenAPI library; phantom-dep finding confirms it's config-only usage. ai
dependencies unvetted-dep:@size-limit/file AI (dependencies): Part of size-limit ecosystem; no risk indicators. ai
dependencies unvetted-dep:@nx/js AI (dependencies): Well-known Nx ecosystem package; stable dependency for this workspace-tools package. ai
dependencies unvetted-dep:@size-limit/esbuild-why AI (dependencies): Part of size-limit ecosystem; no risk indicators. ai
dependencies unvetted-dep:@size-limit/esbuild AI (dependencies): Part of size-limit ecosystem; no risk indicators. ai
dependencies unvetted-dep:size-limit AI (dependencies): Established size-limit tooling; no malware indicators. ai
phantom-deps phantom-dep:@storm-software/tsdown AI (phantom-deps): Same-org dep used in config files; stable pattern for this package. ai
phantom-deps phantom-dep:@microsoft/api-extractor AI (phantom-deps): Referenced in config files only; stable false positive for this package. ai
phantom-deps phantom-dep:@storm-software/esbuild AI (phantom-deps): Same-org dep used in config files; stable pattern for this package. ai
phantom-deps phantom-dep:@storm-software/unbuild AI (phantom-deps): Same-org dep used in config files; stable pattern for this package. ai
phantom-deps phantom-dep:@storm-software/prettier AI (phantom-deps): Same-org dep used in config files; stable pattern for this package. ai
phantom-deps phantom-dep:@storm-software/npm-tools AI (phantom-deps): Same-org dep used in config files; stable pattern for this package. ai
phantom-deps phantom-dep:@storm-software/pnpm-tools AI (phantom-deps): Same-org dep used in config files; stable pattern for this package. ai
phantom-deps phantom-dep:@samchon/openapi AI (phantom-deps): Referenced in config files only; stable false positive for this package. ai
phantom-deps phantom-dep:markdownlint-cli2 AI (phantom-deps): Declared as peer dep and used in config; stable false positive for this package. ai

Versions (showing 51 of 568)

View all versions
Version Deps Published
1.296.89 23 / 15
1.296.88 23 / 15
1.296.87 23 / 15
1.296.86 23 / 15
1.296.85 23 / 15
1.296.84 23 / 15
1.296.81 23 / 14
1.296.79 23 / 14
1.296.78 23 / 14
1.296.72 23 / 14
1.296.71 23 / 14
1.296.70 23 / 14
1.296.69 23 / 14
1.296.66 23 / 14
1.296.65 23 / 14
1.296.64 23 / 14
1.296.63 23 / 14
1.296.62 23 / 14
1.296.61 23 / 14
1.296.60 23 / 14
1.296.59 23 / 14
1.296.58 23 / 14
1.296.57 23 / 14
1.296.56 23 / 14
1.296.55 23 / 14
1.296.54 23 / 14
1.296.53 23 / 14
1.296.52 23 / 14
1.296.51 23 / 14
1.296.50 23 / 14
1.296.49 23 / 10
1.296.48 23 / 10
1.296.47 23 / 10
1.296.46 26 / 10
1.296.45 26 / 10
1.296.44 26 / 10
1.296.43 26 / 10
1.296.42 26 / 10
1.296.41 26 / 10
1.296.40 26 / 10
1.296.39 26 / 10
1.296.38 26 / 10
1.296.37 26 / 10
1.296.36 26 / 10
1.296.35 26 / 10
1.296.34 26 / 10
1.296.33 26 / 10
1.296.32 26 / 10
1.296.31 26 / 10
1.296.30 26 / 10
1.296.29 26 / 10

v1.296.89

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.296.88

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.296.87

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.296.86

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.296.85

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.296.84

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.296.81

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.296.79

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.296.78

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.296.72

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.296.71

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.296.70

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.296.69

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.296.66

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.296.65

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.296.64

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.296.63

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.296.62

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.296.61

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.296.60

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.296.59

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.296.58

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.