@stryke/http
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Publisher changed from stormie-bot to GitHub Actions as part of a legitimate CI/CD migration; SLSA provenance attestation confirms builds originate from the official storm-software/stryke repo. | ai | |
| phantom-deps | phantom-dep:@stryke/url | AI (phantom-deps): Sibling package in the same @stryke org scope; phantom detection is a false positive for monorepo packages that may be used in specific sub-exports. | ai | |
| phantom-deps | phantom-dep:@stryke/type-checks | AI (phantom-deps): Sibling package in the same @stryke org scope; phantom detection is a false positive for monorepo packages used in specific sub-exports. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Minor metadata quality signals (off-topic README content, no keywords) for a legitimate HTTP utility library with SLSA provenance and 85 published versions. | ai |
Versions (showing 51 of 84)
| Version | Deps | Published |
|---|---|---|
| 0.12.74 | 4 / 3 | |
| 0.12.73 | 4 / 3 | |
| 0.12.72 | 4 / 3 | |
| 0.12.71 | 4 / 3 | |
| 0.12.70 | 4 / 3 | |
| 0.12.69 | 4 / 3 | |
| 0.12.68 | 4 / 3 | |
| 0.12.67 | 4 / 3 | |
| 0.12.66 | 4 / 3 | |
| 0.12.65 | 4 / 3 | |
| 0.12.64 | 4 / 3 | |
| 0.12.63 | 4 / 3 | |
| 0.12.62 | 4 / 3 | |
| 0.12.61 | 4 / 3 | |
| 0.12.60 | 4 / 3 | |
| 0.12.59 | 4 / 3 | |
| 0.12.58 | 4 / 3 | |
| 0.12.57 | 4 / 3 | |
| 0.12.56 | 4 / 3 | |
| 0.12.55 | 4 / 3 | |
| 0.12.54 | 4 / 3 | |
| 0.12.53 | 4 / 3 | |
| 0.12.52 | 4 / 3 | |
| 0.12.51 | 4 / 3 | |
| 0.12.50 | 4 / 3 | |
| 0.12.49 | 4 / 3 | |
| 0.12.48 | 4 / 3 | |
| 0.12.47 | 4 / 3 | |
| 0.12.46 | 4 / 3 | |
| 0.12.45 | 4 / 3 | |
| 0.12.42 | 4 / 3 | |
| 0.12.41 | 4 / 3 | |
| 0.12.40 | 4 / 3 | |
| 0.12.39 | 4 / 3 | |
| 0.12.38 | 4 / 3 | |
| 0.12.37 | 4 / 3 | |
| 0.12.36 | 4 / 3 | |
| 0.12.35 | 4 / 3 | |
| 0.12.33 | 4 / 3 | |
| 0.12.32 | 4 / 3 | |
| 0.12.31 | 4 / 3 | |
| 0.12.30 | 4 / 3 | |
| 0.12.29 | 4 / 3 | |
| 0.12.28 | 4 / 3 | |
| 0.12.27 | 4 / 3 | |
| 0.12.26 | 4 / 3 | |
| 0.12.25 | 4 / 3 | |
| 0.12.24 | 4 / 3 | |
| 0.12.23 | 4 / 3 | |
| 0.12.22 | 4 / 3 | |
| 0.12.21 | 4 / 3 |
v0.12.74
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.73
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.72
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.71
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.70
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.69
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.68
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.67
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (stormie-bot) than the most recent previously approved version (GitHub Actions) on 2026-05-25, but stormie-bot is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.12.66
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.65
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.64
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.63
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.62
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.61
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.60
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.59
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.57
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.56
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.55
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.54
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.48
2 findingsThis version was published by a different npm account than previous versions on 2026-03-11. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.26
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.