← Home

@stryke/hash

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

sullivanpjstormie-bot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition from stormie-bot to GitHub Actions is a CI/CD migration within the same storm-software org, corroborated by SLSA provenance attestation on this and likely future versions. ai
publish-pattern new-deps-added AI (publish-pattern): All new deps (@stryke/fs, @stryke/json, @stryke/type-checks) are same-org @stryke scoped packages from the storm-software/stryke monorepo — routine internal dependency additions. ai
typosquat typosquat.levenshtein:hapi AI (typosquat): @stryke/hash is a scoped hashing utility in the storm-software monorepo; the levenshtein match to 'hapi' is coincidental and not an impersonation attempt. ai
phantom-deps phantom-dep:@stryke/fs AI (phantom-deps): Same-org sibling package in the @stryke monorepo; indirect usage or re-export is expected across the ecosystem. ai
phantom-deps phantom-dep:@stryke/json AI (phantom-deps): Same-org sibling package in the @stryke monorepo; indirect usage or re-export is expected across the ecosystem. ai
phantom-deps phantom-dep:@stryke/type-checks AI (phantom-deps): Same-org sibling package in the @stryke monorepo; indirect usage or re-export is expected across the ecosystem. ai

Versions (showing 51 of 90)

View all versions
Version Deps Published
0.13.38 5 / 2
0.13.37 5 / 2
0.13.36 5 / 2
0.13.35 5 / 2
0.13.34 5 / 2
0.13.33 5 / 2
0.13.32 5 / 2
0.13.31 5 / 2
0.13.30 5 / 2
0.13.29 5 / 2
0.13.28 5 / 2
0.13.27 5 / 2
0.13.26 5 / 2
0.13.25 5 / 2
0.13.24 5 / 2
0.13.23 5 / 2
0.13.22 5 / 2
0.13.21 5 / 2
0.13.20 5 / 2
0.13.19 5 / 2
0.13.18 5 / 2
0.13.17 5 / 2
0.13.16 5 / 2
0.13.15 5 / 2
0.13.14 5 / 2
0.13.13 5 / 2
0.13.12 5 / 2
0.13.11 5 / 2
0.13.10 5 / 2
0.13.9 5 / 2
0.13.8 5 / 2
0.13.7 5 / 2
0.13.6 5 / 2
0.13.3 5 / 2
0.13.2 5 / 2
0.13.1 5 / 2
0.13.0 5 / 2
0.12.52 2 / 1
0.12.51 2 / 1
0.12.50 2 / 1
0.12.49 2 / 1
0.12.48 2 / 1
0.12.46 2 / 1
0.12.45 2 / 1
0.12.44 2 / 1
0.12.43 2 / 1
0.12.42 2 / 1
0.12.41 2 / 1
0.12.40 2 / 1
0.12.39 2 / 1
0.12.38 2 / 1

v0.13.38

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.13.37

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.13.36

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.13.35

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.13.34

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.13.33

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.13.32

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.13.31

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.13.30

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: GitHub Actions → stormie-bot (on 2026-05-25, known maintainer) provenance

This version was published by a different npm account (stormie-bot) than the most recent previously approved version (GitHub Actions) on 2026-05-25, but stormie-bot is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.13.29

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.13.28

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.13.27

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.13.26

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.13.25

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.13.24

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.13.22

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.13.21

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.13.20

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.13.19

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.13.18

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.13.12

2 findings
HIGH Publisher changed: stormie-bot → GitHub Actions (on 2026-03-14) provenance

This version was published by a different npm account than previous versions on 2026-03-14. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.40

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.