@storm-software/workspace-tools
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@actions/core | AI (phantom-deps): Declared but not directly imported; used in CI/CD config context consistent with a workspace-tools package. | ai | |
| source-diff | large-new-source-files | AI (source-diff): High-velocity monorepo package; large file additions are routine across its 1367 versions. | ai | |
| dependencies | unvetted-dep:@samchon/openapi | AI (dependencies): Known OpenAPI library; phantom-dep finding confirms it's config-only usage. | ai | |
| dependencies | unvetted-dep:@size-limit/file | AI (dependencies): Part of size-limit ecosystem; no risk indicators. | ai | |
| dependencies | unvetted-dep:@nx/js | AI (dependencies): Well-known Nx ecosystem package; stable dependency for this workspace-tools package. | ai | |
| dependencies | unvetted-dep:@size-limit/esbuild-why | AI (dependencies): Part of size-limit ecosystem; no risk indicators. | ai | |
| dependencies | unvetted-dep:@size-limit/esbuild | AI (dependencies): Part of size-limit ecosystem; no risk indicators. | ai | |
| dependencies | unvetted-dep:size-limit | AI (dependencies): Established size-limit tooling; no malware indicators. | ai | |
| phantom-deps | phantom-dep:@storm-software/tsdown | AI (phantom-deps): Same-org dep used in config files; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@microsoft/api-extractor | AI (phantom-deps): Referenced in config files only; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@storm-software/esbuild | AI (phantom-deps): Same-org dep used in config files; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@storm-software/unbuild | AI (phantom-deps): Same-org dep used in config files; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@storm-software/prettier | AI (phantom-deps): Same-org dep used in config files; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@storm-software/npm-tools | AI (phantom-deps): Same-org dep used in config files; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@storm-software/pnpm-tools | AI (phantom-deps): Same-org dep used in config files; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@samchon/openapi | AI (phantom-deps): Referenced in config files only; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:markdownlint-cli2 | AI (phantom-deps): Declared as peer dep and used in config; stable false positive for this package. | ai |
Versions (showing 51 of 293)
| Version | Deps | Published |
|---|---|---|
| 1.296.18 | 26 / 10 | |
| 1.296.17 | 26 / 10 | |
| 1.296.16 | 26 / 10 | |
| 1.296.15 | 26 / 10 | |
| 1.296.14 | 26 / 10 | |
| 1.296.13 | 26 / 10 | |
| 1.296.12 | 26 / 10 | |
| 1.296.11 | 26 / 10 | |
| 1.296.10 | 26 / 10 | |
| 1.296.9 | 26 / 10 | |
| 1.296.8 | 26 / 10 | |
| 1.296.7 | 26 / 10 | |
| 1.296.6 | 26 / 10 | |
| 1.296.5 | 26 / 10 | |
| 1.296.4 | 26 / 10 | |
| 1.296.3 | 26 / 10 | |
| 1.296.1 | 26 / 10 | |
| 1.295.87 | 25 / 10 | |
| 1.295.84 | 25 / 10 | |
| 1.295.83 | 25 / 10 | |
| 1.295.82 | 25 / 10 | |
| 1.295.81 | 25 / 10 | |
| 1.295.80 | 25 / 10 | |
| 1.295.79 | 25 / 10 | |
| 1.295.78 | 25 / 10 | |
| 1.295.77 | 25 / 10 | |
| 1.295.76 | 25 / 10 | |
| 1.295.75 | 25 / 10 | |
| 1.295.74 | 25 / 10 | |
| 1.295.73 | 25 / 10 | |
| 1.295.71 | 25 / 10 | |
| 1.295.65 | 25 / 9 | |
| 1.295.62 | 25 / 9 | |
| 1.295.61 | 25 / 9 | |
| 1.295.60 | 25 / 9 | |
| 1.295.59 | 25 / 9 | |
| 1.295.58 | 25 / 9 | |
| 1.295.57 | 25 / 9 | |
| 1.295.56 | 25 / 9 | |
| 1.295.55 | 25 / 9 | |
| 1.295.54 | 25 / 9 | |
| 1.295.53 | 25 / 9 | |
| 1.295.52 | 25 / 9 | |
| 1.295.51 | 25 / 9 | |
| 1.295.50 | 25 / 9 | |
| 1.295.49 | 25 / 9 | |
| 1.295.48 | 25 / 9 | |
| 1.295.47 | 25 / 9 | |
| 1.295.46 | 25 / 9 | |
| 1.295.45 | 25 / 9 | |
| 1.295.44 | 25 / 9 |
v1.296.18
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.296.17
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.296.16
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.296.15
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.296.14
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.296.13
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.296.12
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.296.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.296.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.296.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.296.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.296.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.296.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.296.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.296.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.296.3
2 findingsThis version was published by a different npm account than previous versions on 2026-05-21. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.296.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.295.87
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.295.84
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.295.83
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.295.82
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.295.81
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.295.80
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.295.79
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.295.78
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.295.77
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.295.76
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.295.75
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.295.74
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.295.73
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.295.71
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.295.65
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.295.62
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.295.60
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.295.59
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.295.58
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.295.57
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.295.56
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.295.55
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.295.54
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.295.53
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.295.52
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.295.51
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.295.50
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.295.49
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.295.48
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.295.47
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.295.46
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.295.45
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.295.44
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.