@stryke/http
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Publisher changed from stormie-bot to GitHub Actions as part of a legitimate CI/CD migration; SLSA provenance attestation confirms builds originate from the official storm-software/stryke repo. | ai | |
| phantom-deps | phantom-dep:@stryke/url | AI (phantom-deps): Sibling package in the same @stryke org scope; phantom detection is a false positive for monorepo packages that may be used in specific sub-exports. | ai | |
| phantom-deps | phantom-dep:@stryke/type-checks | AI (phantom-deps): Sibling package in the same @stryke org scope; phantom detection is a false positive for monorepo packages used in specific sub-exports. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Minor metadata quality signals (off-topic README content, no keywords) for a legitimate HTTP utility library with SLSA provenance and 85 published versions. | ai |
Versions (showing 51 of 120)
| Version | Deps | Published |
|---|---|---|
| 0.12.89 | 6 / 4 | |
| 0.12.88 | 6 / 4 | |
| 0.12.87 | 6 / 4 | |
| 0.12.86 | 6 / 4 | |
| 0.12.85 | 6 / 4 | |
| 0.12.84 | 6 / 4 | |
| 0.12.83 | 6 / 4 | |
| 0.12.82 | 6 / 4 | |
| 0.12.81 | 6 / 4 | |
| 0.12.80 | 6 / 4 | |
| 0.12.79 | 6 / 4 | |
| 0.12.78 | 6 / 4 | |
| 0.12.77 | 6 / 4 | |
| 0.12.76 | 4 / 3 | |
| 0.12.75 | 4 / 3 | |
| 0.12.74 | 4 / 3 | |
| 0.12.73 | 4 / 3 | |
| 0.12.72 | 4 / 3 | |
| 0.12.71 | 4 / 3 | |
| 0.12.70 | 4 / 3 | |
| 0.12.69 | 4 / 3 | |
| 0.12.68 | 4 / 3 | |
| 0.12.67 | 4 / 3 | |
| 0.12.66 | 4 / 3 | |
| 0.12.65 | 4 / 3 | |
| 0.12.64 | 4 / 3 | |
| 0.12.63 | 4 / 3 | |
| 0.12.62 | 4 / 3 | |
| 0.12.61 | 4 / 3 | |
| 0.12.60 | 4 / 3 | |
| 0.12.59 | 4 / 3 | |
| 0.12.58 | 4 / 3 | |
| 0.12.57 | 4 / 3 | |
| 0.12.56 | 4 / 3 | |
| 0.12.55 | 4 / 3 | |
| 0.12.54 | 4 / 3 | |
| 0.12.53 | 4 / 3 | |
| 0.12.52 | 4 / 3 | |
| 0.12.51 | 4 / 3 | |
| 0.12.50 | 4 / 3 | |
| 0.12.49 | 4 / 3 | |
| 0.12.48 | 4 / 3 | |
| 0.12.47 | 4 / 3 | |
| 0.12.46 | 4 / 3 | |
| 0.12.45 | 4 / 3 | |
| 0.12.42 | 4 / 3 | |
| 0.12.41 | 4 / 3 | |
| 0.12.40 | 4 / 3 | |
| 0.12.39 | 4 / 3 | |
| 0.12.38 | 4 / 3 | |
| 0.12.37 | 4 / 3 |
v0.12.89
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.88
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.87
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.86
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.85
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.84
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.83
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.