@stryke/http
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Publisher changed from stormie-bot to GitHub Actions as part of a legitimate CI/CD migration; SLSA provenance attestation confirms builds originate from the official storm-software/stryke repo. | ai | |
| phantom-deps | phantom-dep:@stryke/url | AI (phantom-deps): Sibling package in the same @stryke org scope; phantom detection is a false positive for monorepo packages that may be used in specific sub-exports. | ai | |
| phantom-deps | phantom-dep:@stryke/type-checks | AI (phantom-deps): Sibling package in the same @stryke org scope; phantom detection is a false positive for monorepo packages used in specific sub-exports. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Minor metadata quality signals (off-topic README content, no keywords) for a legitimate HTTP utility library with SLSA provenance and 85 published versions. | ai |
Versions (showing 84 of 84)
| Version | Deps | Published |
|---|---|---|
| 0.12.74 | 4 / 3 | |
| 0.12.73 | 4 / 3 | |
| 0.12.72 | 4 / 3 | |
| 0.12.71 | 4 / 3 | |
| 0.12.70 | 4 / 3 | |
| 0.12.69 | 4 / 3 | |
| 0.12.68 | 4 / 3 | |
| 0.12.67 | 4 / 3 | |
| 0.12.66 | 4 / 3 | |
| 0.12.65 | 4 / 3 | |
| 0.12.64 | 4 / 3 | |
| 0.12.63 | 4 / 3 | |
| 0.12.62 | 4 / 3 | |
| 0.12.61 | 4 / 3 | |
| 0.12.60 | 4 / 3 | |
| 0.12.59 | 4 / 3 | |
| 0.12.58 | 4 / 3 | |
| 0.12.57 | 4 / 3 | |
| 0.12.56 | 4 / 3 | |
| 0.12.55 | 4 / 3 | |
| 0.12.54 | 4 / 3 | |
| 0.12.53 | 4 / 3 | |
| 0.12.52 | 4 / 3 | |
| 0.12.51 | 4 / 3 | |
| 0.12.50 | 4 / 3 | |
| 0.12.49 | 4 / 3 | |
| 0.12.48 | 4 / 3 | |
| 0.12.47 | 4 / 3 | |
| 0.12.46 | 4 / 3 | |
| 0.12.45 | 4 / 3 | |
| 0.12.42 | 4 / 3 | |
| 0.12.41 | 4 / 3 | |
| 0.12.40 | 4 / 3 | |
| 0.12.39 | 4 / 3 | |
| 0.12.38 | 4 / 3 | |
| 0.12.37 | 4 / 3 | |
| 0.12.36 | 4 / 3 | |
| 0.12.35 | 4 / 3 | |
| 0.12.33 | 4 / 3 | |
| 0.12.32 | 4 / 3 | |
| 0.12.31 | 4 / 3 | |
| 0.12.30 | 4 / 3 | |
| 0.12.29 | 4 / 3 | |
| 0.12.28 | 4 / 3 | |
| 0.12.27 | 4 / 3 | |
| 0.12.26 | 4 / 3 | |
| 0.12.25 | 4 / 3 | |
| 0.12.24 | 4 / 3 | |
| 0.12.23 | 4 / 3 | |
| 0.12.22 | 4 / 3 | |
| 0.12.21 | 4 / 3 | |
| 0.12.20 | 4 / 3 | |
| 0.12.19 | 4 / 3 | |
| 0.12.18 | 4 / 3 | |
| 0.12.17 | 4 / 3 | |
| 0.12.16 | 4 / 3 | |
| 0.12.15 | 4 / 3 | |
| 0.12.14 | 4 / 3 | |
| 0.12.13 | 4 / 3 | |
| 0.12.12 | 4 / 3 | |
| 0.12.11 | 4 / 3 | |
| 0.12.10 | 4 / 3 | |
| 0.12.3 | 4 / 2 | |
| 0.12.2 | 4 / 2 | |
| 0.12.1 | 4 / 2 | |
| 0.12.0 | 5 / 1 | |
| 0.11.10 | 2 / 1 | |
| 0.11.9 | 2 / 1 | |
| 0.11.8 | 2 / 1 | |
| 0.11.7 | 2 / 1 | |
| 0.11.6 | 2 / 1 | |
| 0.11.5 | 2 / 1 | |
| 0.11.4 | 2 / 1 | |
| 0.11.3 | 2 / 1 | |
| 0.11.2 | 2 / 1 | |
| 0.11.1 | 2 / 1 | |
| 0.11.0 | 2 / 1 | |
| 0.10.0 | 1 / 1 | |
| 0.9.0 | 1 / 1 | |
| 0.8.5 | 1 / 1 | |
| 0.8.4 | 1 / 1 | |
| 0.8.3 | 1 / 1 | |
| 0.8.2 | 1 / 1 | |
| 0.8.1 | 1 / 1 |
v0.12.74
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.73
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.72
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.71
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.70
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.69
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.68
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.67
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (stormie-bot) than the most recent previously approved version (GitHub Actions) on 2026-05-25, but stormie-bot is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.12.66
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.65
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.64
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.63
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.62
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.61
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.60
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.59
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.57
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.56
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.55
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.54
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.48
2 findingsThis version was published by a different npm account than previous versions on 2026-03-11. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.26
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.10.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.9.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.