@storm-software/workspace-tools
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@actions/core | AI (phantom-deps): Declared but not directly imported; used in CI/CD config context consistent with a workspace-tools package. | ai | |
| source-diff | large-new-source-files | AI (source-diff): High-velocity monorepo package; large file additions are routine across its 1367 versions. | ai | |
| dependencies | unvetted-dep:@samchon/openapi | AI (dependencies): Known OpenAPI library; phantom-dep finding confirms it's config-only usage. | ai | |
| dependencies | unvetted-dep:@size-limit/file | AI (dependencies): Part of size-limit ecosystem; no risk indicators. | ai | |
| dependencies | unvetted-dep:@nx/js | AI (dependencies): Well-known Nx ecosystem package; stable dependency for this workspace-tools package. | ai | |
| dependencies | unvetted-dep:@size-limit/esbuild-why | AI (dependencies): Part of size-limit ecosystem; no risk indicators. | ai | |
| dependencies | unvetted-dep:@size-limit/esbuild | AI (dependencies): Part of size-limit ecosystem; no risk indicators. | ai | |
| dependencies | unvetted-dep:size-limit | AI (dependencies): Established size-limit tooling; no malware indicators. | ai | |
| phantom-deps | phantom-dep:@storm-software/tsdown | AI (phantom-deps): Same-org dep used in config files; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@microsoft/api-extractor | AI (phantom-deps): Referenced in config files only; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@storm-software/esbuild | AI (phantom-deps): Same-org dep used in config files; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@storm-software/unbuild | AI (phantom-deps): Same-org dep used in config files; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@storm-software/prettier | AI (phantom-deps): Same-org dep used in config files; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@storm-software/npm-tools | AI (phantom-deps): Same-org dep used in config files; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@storm-software/pnpm-tools | AI (phantom-deps): Same-org dep used in config files; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@samchon/openapi | AI (phantom-deps): Referenced in config files only; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:markdownlint-cli2 | AI (phantom-deps): Declared as peer dep and used in config; stable false positive for this package. | ai |
Versions (showing 51 of 568)
| Version | Deps | Published |
|---|---|---|
| 1.296.89 | 23 / 15 | |
| 1.296.88 | 23 / 15 | |
| 1.296.87 | 23 / 15 | |
| 1.296.86 | 23 / 15 | |
| 1.296.85 | 23 / 15 | |
| 1.296.84 | 23 / 15 | |
| 1.296.81 | 23 / 14 | |
| 1.296.79 | 23 / 14 | |
| 1.296.78 | 23 / 14 | |
| 1.296.72 | 23 / 14 | |
| 1.296.71 | 23 / 14 | |
| 1.296.70 | 23 / 14 | |
| 1.296.69 | 23 / 14 | |
| 1.296.66 | 23 / 14 | |
| 1.296.65 | 23 / 14 | |
| 1.296.64 | 23 / 14 | |
| 1.296.63 | 23 / 14 | |
| 1.296.62 | 23 / 14 | |
| 1.296.61 | 23 / 14 | |
| 1.296.60 | 23 / 14 | |
| 1.296.59 | 23 / 14 | |
| 1.296.58 | 23 / 14 | |
| 1.296.57 | 23 / 14 | |
| 1.296.56 | 23 / 14 | |
| 1.296.55 | 23 / 14 | |
| 1.296.54 | 23 / 14 | |
| 1.296.53 | 23 / 14 | |
| 1.296.52 | 23 / 14 | |
| 1.296.51 | 23 / 14 | |
| 1.296.50 | 23 / 14 | |
| 1.296.49 | 23 / 10 | |
| 1.296.48 | 23 / 10 | |
| 1.296.47 | 23 / 10 | |
| 1.296.46 | 26 / 10 | |
| 1.296.45 | 26 / 10 | |
| 1.296.44 | 26 / 10 | |
| 1.296.43 | 26 / 10 | |
| 1.296.42 | 26 / 10 | |
| 1.296.41 | 26 / 10 | |
| 1.296.40 | 26 / 10 | |
| 1.296.39 | 26 / 10 | |
| 1.296.38 | 26 / 10 | |
| 1.296.37 | 26 / 10 | |
| 1.296.36 | 26 / 10 | |
| 1.296.35 | 26 / 10 | |
| 1.296.34 | 26 / 10 | |
| 1.296.33 | 26 / 10 | |
| 1.296.32 | 26 / 10 | |
| 1.296.31 | 26 / 10 | |
| 1.296.30 | 26 / 10 | |
| 1.296.29 | 26 / 10 |
v1.296.89
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.296.88
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.296.87
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.296.86
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.296.85
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.296.84
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.296.81
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.296.79
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.296.78
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.296.72
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.296.71
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.296.70
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.296.69
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.296.66
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.296.65
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.296.64
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.296.63
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.296.62
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.296.61
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.296.60
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.296.59
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.296.58
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.