← Home

@stryke/crypto

A package containing cryptographic utilities used by Storm Software.

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

sullivanpjstormie-bot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition from stormie-bot to GitHub Actions CI is consistent with SLSA-attested automated publishing from the same org. ai
source-diff obfuscated-file:dist/base-64-Bh0chPX9.cjs AI (source-diff): Minified build artifact for base64 utility; code is readable and benign, no network/exfil behavior. ai
source-diff obfuscated-file:dist/base-64-n6I9tGzK.mjs AI (source-diff): ESM counterpart of the same minified base64 build artifact; same benign assessment. ai
bogus-package bogus-package AI (bogus-package): README quality issues (link dump, off-topic) are a known pattern for this org's packages; not a security signal. ai
typosquat typosquat.levenshtein:bcrypt AI (typosquat): Legitimate @stryke org monorepo package; not impersonating bcrypt. ai
phantom-deps phantom-dep:@stryke/type-checks AI (phantom-deps): Same-org sibling dep; may be used indirectly or in platform-specific entry points. ai
phantom-deps phantom-dep:@stryke/convert AI (phantom-deps): Same-org sibling dep; may be used indirectly or in platform-specific entry points. ai
phantom-deps phantom-dep:@stryke/json AI (phantom-deps): Same-org sibling dep; may be used indirectly or in platform-specific entry points. ai

Versions (showing 51 of 89)

View all versions
Version Deps Published
0.6.46 3 / 3
0.6.45 3 / 3
0.6.44 3 / 3
0.6.43 3 / 3
0.6.42 3 / 3
0.6.41 3 / 3
0.6.40 3 / 3
0.6.39 3 / 3
0.6.38 3 / 3
0.6.37 3 / 3
0.6.36 3 / 3
0.6.35 3 / 3
0.6.34 3 / 3
0.6.33 3 / 3
0.6.32 3 / 3
0.6.31 3 / 3
0.6.30 3 / 3
0.6.29 3 / 3
0.6.28 3 / 3
0.6.27 3 / 3
0.6.26 3 / 3
0.6.25 3 / 3
0.6.24 3 / 3
0.6.23 3 / 3
0.6.22 3 / 3
0.6.21 3 / 3
0.6.20 3 / 3
0.6.19 3 / 3
0.6.18 3 / 3
0.6.17 3 / 3
0.6.16 3 / 3
0.6.15 3 / 3
0.6.14 3 / 3
0.6.13 3 / 3
0.6.12 3 / 3
0.6.11 3 / 3
0.6.10 3 / 3
0.6.9 3 / 3
0.6.8 3 / 3
0.6.7 3 / 3
0.6.6 3 / 3
0.6.3 3 / 3
0.6.2 3 / 3
0.6.1 3 / 3
0.6.0 3 / 3
0.5.44 2 / 2
0.5.43 2 / 2
0.5.42 2 / 2
0.5.41 2 / 2
0.5.39 2 / 2
0.5.38 2 / 2

v0.6.46

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.45

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.44

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.43

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.42

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.41

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.40

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.