← Home

@stryke/env

100
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

sullivanpjstormie-bot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
bogus-package bogus-package AI (bogus-package): Low-score cosmetic signals (off-topic README, no keywords) on an established 441-day-old package with 173 versions; not indicative of spam or malice. ai
provenance publisher-changed AI (provenance): Transition from stormie-bot to GitHub Actions with SLSA provenance attestation is a legitimate CI/CD pipeline improvement for the storm-software/stryke org; not a compromise indicator. ai
source-diff obfuscated-file:dist/string-format/src/acronyms.cjs AI (source-diff): File is a minified acronym dictionary (plain data object), not obfuscated code. Long lines are from bundling a large data file; no malicious patterns present. ai
source-diff obfuscated-file:dist/string-format/src/acronyms.mjs AI (source-diff): ESM variant of the same minified acronym dictionary. Fully readable data, no obfuscation or malicious patterns. ai
source-diff obfuscated-file:dist/environment-checks-ghgIrof1.cjs AI (source-diff): Minified bundler output (tsdown/rollup) for environment-checks entry point. Content is legitimate env detection logic. Pattern is stable for this package's build system. ai
source-diff obfuscated-file:dist/get-env-paths-CRQWNX3i.cjs AI (source-diff): Minified bundler output for get-env-paths entry point. Content is an acronym dictionary and path utilities — no malicious patterns. ai
source-diff obfuscated-file:dist/get-env-paths-DUHBXxwb.mjs AI (source-diff): ESM variant of the same get-env-paths bundle. Identical benign content to the CJS counterpart; standard dual-format build output. ai
phantom-deps phantom-dep:@stryke/path AI (phantom-deps): Same-org sibling package in the storm-software/stryke monorepo; phantom dep detection is a false positive for intra-monorepo dependencies. ai
phantom-deps phantom-dep:@stryke/fs AI (phantom-deps): Same-org sibling package in the storm-software/stryke monorepo; phantom dep detection is a false positive for intra-monorepo dependencies. ai
phantom-deps phantom-dep:@stryke/string-format AI (phantom-deps): Same-org sibling package in the storm-software/stryke monorepo; phantom dep detection is a false positive for intra-monorepo dependencies. ai
phantom-deps phantom-dep:@stryke/convert AI (phantom-deps): Same-org sibling package in the storm-software/stryke monorepo; phantom dep detection is a false positive for intra-monorepo dependencies. ai
dependencies unvetted-dep:@stryke/fs AI (dependencies): Same-org sibling package from the storm-software/stryke monorepo; not an external unvetted dependency. ai
typosquat typosquat.levenshtein:ajv AI (typosquat): Scoped @stryke monorepo package; Levenshtein match to 'ajv' is coincidental. Package is an env utility with no relation to ajv's JSON schema validation domain. ai

Versions (showing 100 of 168)

Version Deps Published
0.20.102 6 / 2
0.20.101 6 / 2
0.20.100 6 / 2
0.20.99 6 / 2
0.20.98 6 / 2
0.20.97 6 / 2
0.20.96 6 / 2
0.20.95 6 / 2
0.20.94 6 / 2
0.20.93 6 / 2
0.20.92 6 / 2
0.20.91 6 / 2
0.20.90 6 / 2
0.20.89 6 / 2
0.20.88 6 / 2
0.20.87 6 / 2
0.20.86 6 / 2
0.20.85 6 / 2
0.20.84 6 / 2
0.20.83 6 / 2
0.20.82 6 / 2
0.20.81 6 / 2
0.20.80 6 / 2
0.20.79 6 / 2
0.20.78 6 / 2
0.20.77 6 / 2
0.20.76 6 / 2
0.20.75 6 / 2
0.20.74 6 / 2
0.20.73 6 / 2
0.20.72 6 / 2
0.20.71 6 / 2
0.20.70 6 / 2
0.20.67 6 / 2
0.20.66 6 / 2
0.20.65 6 / 2
0.20.64 6 / 2
0.20.63 6 / 2
0.20.62 6 / 2
0.20.61 6 / 2
0.20.60 6 / 2
0.20.59 6 / 2
0.20.57 6 / 2
0.20.56 6 / 2
0.20.55 6 / 2
0.20.54 6 / 2
0.20.53 6 / 2
0.20.52 6 / 2
0.20.51 6 / 2
0.20.50 6 / 2
0.20.49 6 / 2
0.20.48 6 / 2
0.20.47 6 / 2
0.20.46 6 / 2
0.20.45 6 / 2
0.20.44 6 / 2
0.20.43 6 / 2
0.20.42 6 / 2
0.20.41 6 / 2
0.20.40 6 / 2
0.20.39 6 / 2
0.20.38 6 / 2
0.20.37 6 / 2
0.20.36 6 / 2
0.20.35 6 / 2
0.20.34 6 / 2
0.20.33 6 / 2
0.20.26 6 / 1
0.20.25 6 / 1
0.20.24 6 / 1
0.20.23 6 / 1
0.20.22 6 / 1
0.20.21 6 / 1
0.20.20 6 / 1
0.20.19 6 / 1
0.20.18 6 / 1
0.20.17 6 / 1
0.20.16 6 / 1
0.20.15 6 / 1
0.20.14 6 / 1
0.20.13 6 / 1
0.20.12 6 / 1
0.20.11 6 / 1
0.20.10 6 / 1
0.20.9 6 / 1
0.20.8 6 / 1
0.20.7 6 / 1
0.20.6 6 / 1
0.20.5 6 / 1
0.20.4 6 / 1
0.20.3 6 / 1
0.20.2 6 / 1
0.20.1 6 / 1
0.20.0 6 / 1
0.19.12 6 / 1
0.19.11 6 / 1
0.19.10 6 / 1
0.19.9 6 / 1
0.19.8 6 / 1
0.19.7 6 / 1
Showing 100 of 168 Next page →

v0.20.102

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20.101

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20.100

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20.99

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20.98

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20.97

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20.96

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20.95

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20.94

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: GitHub Actions → stormie-bot (on 2026-05-25, known maintainer) provenance

This version was published by a different npm account (stormie-bot) than the most recent previously approved version (GitHub Actions) on 2026-05-25, but stormie-bot is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.20.93

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20.92

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20.91

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20.90

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20.89

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20.88

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20.86

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20.85

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20.84

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20.83

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20.82

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20.45

3 findings
HIGH New obfuscated file: dist/string-format/src/acronyms.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/string-format/src/acronyms.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20.44

3 findings
HIGH New obfuscated file: dist/string-format/src/acronyms.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/string-format/src/acronyms.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20.43

3 findings
HIGH New obfuscated file: dist/string-format/src/acronyms.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/string-format/src/acronyms.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20.42

3 findings
HIGH New obfuscated file: dist/string-format/src/acronyms.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/string-format/src/acronyms.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20.40

3 findings
HIGH New obfuscated file: dist/string-format/src/acronyms.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/string-format/src/acronyms.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20.38

3 findings
HIGH New obfuscated file: dist/string-format/src/acronyms.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/string-format/src/acronyms.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20.35

4 findings
HIGH New obfuscated file: dist/environment-checks-ghgIrof1.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/get-env-paths-CRQWNX3i.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/get-env-paths-DUHBXxwb.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20.34

4 findings
HIGH New obfuscated file: dist/environment-checks-ghgIrof1.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/get-env-paths-CRQWNX3i.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/get-env-paths-DUHBXxwb.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20.33

4 findings
HIGH New obfuscated file: dist/environment-checks-ghgIrof1.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/get-env-paths-CRQWNX3i.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/get-env-paths-DUHBXxwb.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20.24

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20.18

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.19.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.19.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.19.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.19.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.19.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.19.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.