← Home

@stryke/string-format

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

sullivanpjstormie-bot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Publisher changed from stormie-bot to GitHub Actions with SLSA provenance attestation — this is a legitimate CI/CD modernization for the storm-software/stryke monorepo, not a compromise. ai
phantom-deps phantom-dep:@stryke/path AI (phantom-deps): Same-org dependency used in specific sub-entry-points (pretty-path export); phantom at index level is expected for multi-entry-point bundled packages. ai
source-diff obfuscated-file:dist/acronyms-DiyHB1FK.cjs AI (source-diff): File contains minified acronym dictionary data — long lines are due to data density, not obfuscation. No malicious patterns present. Standard build output for this string-formatting utility. ai
source-diff large-new-source-files AI (source-diff): New files correspond to expanded sub-path exports visible in package.json exports map, plus inlining of removed runtime deps. Legitimate package expansion. ai

Versions (showing 51 of 94)

View all versions
Version Deps Published
0.17.26 2 / 1
0.17.25 2 / 1
0.17.24 2 / 1
0.17.23 2 / 1
0.17.22 2 / 1
0.17.21 2 / 1
0.17.20 2 / 1
0.17.19 2 / 1
0.17.18 2 / 1
0.17.17 2 / 1
0.17.16 2 / 1
0.17.15 1 / 1
0.17.14 1 / 1
0.17.13 1 / 1
0.17.12 1 / 1
0.17.11 1 / 1
0.17.10 1 / 1
0.17.9 1 / 1
0.17.8 1 / 1
0.17.7 1 / 1
0.17.6 1 / 1
0.17.5 1 / 1
0.17.4 1 / 1
0.17.3 1 / 1
0.17.2 1 / 1
0.17.1 1 / 1
0.17.0 1 / 1
0.16.0 1 / 1
0.14.8 0 / 1
0.14.7 0 / 1
0.14.6 0 / 1
0.14.5 0 / 1
0.14.4 0 / 1
0.14.3 0 / 1
0.14.2 0 / 1
0.14.1 0 / 1
0.13.7 0 / 1
0.13.6 0 / 1
0.13.5 0 / 1
0.13.4 0 / 1
0.13.3 0 / 1
0.13.2 0 / 1
0.13.1 0 / 1
0.13.0 0 / 1
0.12.31 0 / 1
0.12.30 0 / 1
0.12.29 0 / 1
0.12.28 0 / 1
0.12.27 0 / 1
0.12.26 0 / 1
0.12.25 0 / 1

v0.17.26

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.17.25

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.17.24

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.17.23

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.17.22

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.17.21

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.17.20

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.17.19

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: GitHub Actions → stormie-bot (on 2026-05-25, known maintainer) provenance

This version was published by a different npm account (stormie-bot) than the most recent previously approved version (GitHub Actions) on 2026-05-25, but stormie-bot is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.17.18

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.17.17

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.17.16

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.17.15

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.17.14

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.17.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.17.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.17.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.17.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.17.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.14.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.13.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.28

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.