← Home

@storm-software/workspace-tools

100
Versions
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures gitHead linked

Maintainers

stormie-bot

Keywords

monoreponxstorm-softwarestorm-opsstormsullivanpj

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@actions/core AI (phantom-deps): Declared but not directly imported; used in CI/CD config context consistent with a workspace-tools package. ai
source-diff large-new-source-files AI (source-diff): High-velocity monorepo package; large file additions are routine across its 1367 versions. ai
dependencies unvetted-dep:@samchon/openapi AI (dependencies): Known OpenAPI library; phantom-dep finding confirms it's config-only usage. ai
dependencies unvetted-dep:@size-limit/file AI (dependencies): Part of size-limit ecosystem; no risk indicators. ai
dependencies unvetted-dep:@nx/js AI (dependencies): Well-known Nx ecosystem package; stable dependency for this workspace-tools package. ai
dependencies unvetted-dep:@size-limit/esbuild-why AI (dependencies): Part of size-limit ecosystem; no risk indicators. ai
dependencies unvetted-dep:@size-limit/esbuild AI (dependencies): Part of size-limit ecosystem; no risk indicators. ai
dependencies unvetted-dep:size-limit AI (dependencies): Established size-limit tooling; no malware indicators. ai
phantom-deps phantom-dep:@storm-software/tsdown AI (phantom-deps): Same-org dep used in config files; stable pattern for this package. ai
phantom-deps phantom-dep:@microsoft/api-extractor AI (phantom-deps): Referenced in config files only; stable false positive for this package. ai
phantom-deps phantom-dep:@storm-software/esbuild AI (phantom-deps): Same-org dep used in config files; stable pattern for this package. ai
phantom-deps phantom-dep:@storm-software/unbuild AI (phantom-deps): Same-org dep used in config files; stable pattern for this package. ai
phantom-deps phantom-dep:@storm-software/prettier AI (phantom-deps): Same-org dep used in config files; stable pattern for this package. ai
phantom-deps phantom-dep:@storm-software/npm-tools AI (phantom-deps): Same-org dep used in config files; stable pattern for this package. ai
phantom-deps phantom-dep:@storm-software/pnpm-tools AI (phantom-deps): Same-org dep used in config files; stable pattern for this package. ai
phantom-deps phantom-dep:@samchon/openapi AI (phantom-deps): Referenced in config files only; stable false positive for this package. ai
phantom-deps phantom-dep:markdownlint-cli2 AI (phantom-deps): Declared as peer dep and used in config; stable false positive for this package. ai

Versions (showing 100 of 568)

Version Deps Published
1.275.6 24 / 8
1.275.5 24 / 8
1.275.4 24 / 8
1.275.3 24 / 8
1.275.2 24 / 8
1.275.1 24 / 8
1.275.0 24 / 8
1.274.8 24 / 8
1.274.7 24 / 8
1.274.6 24 / 8
1.274.5 24 / 8
1.274.4 24 / 8
1.274.3 24 / 8
1.274.2 24 / 8
1.274.1 24 / 8
1.274.0 24 / 8
1.273.10 24 / 8
1.273.9 24 / 8
1.273.7 24 / 8
1.273.6 24 / 8
1.273.5 24 / 8
1.273.4 24 / 8
1.273.3 24 / 8
1.273.2 24 / 8
1.273.1 24 / 8
1.273.0 24 / 8
1.272.1 24 / 8
1.272.0 24 / 8
1.271.2 24 / 8
1.271.1 24 / 8
1.271.0 24 / 8
1.267.22 21 / 8
1.267.21 21 / 8
1.267.20 21 / 8
1.267.19 21 / 8
1.267.18 21 / 8
1.267.17 21 / 8
1.267.16 21 / 8
1.267.15 21 / 8
1.267.14 21 / 8
1.267.13 21 / 8
1.267.12 21 / 8
1.267.11 21 / 8
1.267.10 21 / 8
1.267.9 21 / 8
1.267.8 21 / 8
1.267.7 21 / 8
1.267.6 21 / 8
1.267.5 21 / 8
1.267.4 21 / 8
1.267.3 21 / 8
1.267.2 21 / 8
1.267.1 21 / 8
1.267.0 21 / 8
1.266.10 21 / 8
1.266.9 21 / 8
1.266.6 21 / 8
1.266.5 21 / 8
1.266.4 21 / 8
1.266.3 21 / 8
1.266.2 21 / 8
1.266.1 21 / 8
1.266.0 21 / 8
1.265.14 21 / 8
1.265.13 21 / 8
1.265.12 21 / 8
1.265.11 22 / 7
1.265.10 22 / 7
1.265.9 22 / 7
1.265.8 22 / 7
1.265.7 22 / 7
1.265.6 22 / 7
1.265.5 22 / 7
1.265.4 22 / 7
1.265.3 22 / 7
1.265.2 22 / 7
1.265.1 22 / 7
1.265.0 22 / 7
1.264.27 22 / 7
1.264.26 22 / 7
1.264.25 22 / 7
1.264.24 22 / 7
1.264.23 22 / 7
1.264.22 22 / 7
1.264.21 22 / 7
1.264.20 22 / 7
1.264.19 22 / 7
1.264.18 22 / 7
1.264.17 22 / 7
1.264.16 22 / 7
1.264.15 22 / 7
1.264.14 22 / 7
1.264.13 22 / 7
1.264.12 22 / 7
1.264.11 22 / 7
1.264.10 22 / 7
1.264.9 22 / 7
1.264.8 22 / 7
1.264.7 22 / 7
1.264.6 22 / 7
Showing 100 of 568 Next page →

v1.266.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.266.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.266.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.266.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.266.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.266.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.266.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.266.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.266.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.265.14

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.265.13

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.265.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.265.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.265.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.265.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.265.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.265.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.265.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.265.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.265.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.265.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.265.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.265.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.265.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.264.27

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.264.26

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.264.25

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.264.24

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.264.23

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.264.22

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.264.21

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.264.20

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.264.19

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.264.18

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.264.17

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.264.16

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.264.15

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.264.14

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.264.13

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.264.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.264.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.264.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.264.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.264.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.264.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.264.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.