← Home

@stryke/path

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

sullivanpjstormie-bot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Publisher changed to GitHub Actions with SLSA provenance attestation — this is the storm-software CI/CD pipeline, a legitimate and expected transition for this org. ai
source-diff obfuscated-file:dist/file-path-fns-B9hKjfA-.cjs AI (source-diff): Minified bundler output (tsdown/Rollup) with hash-suffixed filenames. Code content is consistent with path utility functions; no malicious patterns present. ai
source-diff large-new-source-files AI (source-diff): 88 files reflects bundler output for 18+ named sub-path exports with CJS/ESM variants and shared chunks — consistent with package structure. ai

Versions (showing 51 of 118)

View all versions
Version Deps Published
0.29.11 4 / 1
0.29.10 4 / 1
0.29.9 4 / 1
0.29.8 4 / 1
0.29.7 4 / 1
0.29.6 4 / 1
0.29.5 4 / 1
0.29.4 4 / 1
0.29.3 4 / 1
0.29.2 4 / 1
0.29.1 4 / 1
0.29.0 4 / 1
0.28.3 4 / 1
0.28.2 0 / 5
0.28.1 0 / 5
0.28.0 0 / 5
0.27.5 0 / 5
0.27.4 0 / 5
0.27.3 0 / 5
0.27.2 0 / 5
0.27.1 0 / 5
0.27.0 0 / 5
0.26.19 0 / 5
0.26.18 0 / 5
0.26.17 0 / 5
0.26.16 0 / 5
0.26.15 0 / 5
0.26.12 0 / 5
0.26.11 0 / 5
0.26.10 0 / 5
0.26.9 0 / 5
0.26.8 0 / 5
0.26.7 0 / 5
0.26.6 0 / 5
0.26.4 0 / 5
0.26.3 0 / 5
0.26.2 0 / 5
0.26.1 0 / 5
0.26.0 0 / 5
0.25.3 0 / 5
0.25.2 0 / 5
0.25.1 0 / 5
0.25.0 0 / 5
0.24.4 0 / 5
0.24.3 0 / 5
0.24.2 0 / 5
0.24.1 0 / 5
0.24.0 0 / 5
0.23.2 0 / 5
0.23.1 0 / 5
0.23.0 0 / 5

v0.29.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.29.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.29.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.29.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.29.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.29.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.29.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.29.4

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: GitHub Actions → stormie-bot (on 2026-05-25, known maintainer) provenance

This version was published by a different npm account (stormie-bot) than the most recent previously approved version (GitHub Actions) on 2026-05-25, but stormie-bot is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.29.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.29.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.29.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.29.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.28.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.28.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.28.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.27.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.27.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.26.2

2 findings
HIGH Publisher changed: stormie-bot → GitHub Actions (on 2026-01-27) provenance

This version was published by a different npm account than previous versions on 2026-01-27. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.