← Home

@stryke/string-format

100
Versions
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures gitHead linked

Maintainers

sullivanpjstormie-bot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Publisher changed from stormie-bot to GitHub Actions with SLSA provenance attestation — this is a legitimate CI/CD modernization for the storm-software/stryke monorepo, not a compromise. ai
phantom-deps phantom-dep:@stryke/path AI (phantom-deps): Same-org dependency used in specific sub-entry-points (pretty-path export); phantom at index level is expected for multi-entry-point bundled packages. ai
source-diff obfuscated-file:dist/acronyms-DiyHB1FK.cjs AI (source-diff): File contains minified acronym dictionary data — long lines are due to data density, not obfuscation. No malicious patterns present. Standard build output for this string-formatting utility. ai
source-diff large-new-source-files AI (source-diff): New files correspond to expanded sub-path exports visible in package.json exports map, plus inlining of removed runtime deps. Legitimate package expansion. ai

Versions (showing 100 of 122)

Version Deps Published
0.17.40 2 / 1
0.17.39 2 / 1
0.17.38 2 / 1
0.17.37 2 / 1
0.17.36 2 / 1
0.17.35 2 / 1
0.17.34 2 / 1
0.17.33 2 / 1
0.17.32 2 / 1
0.17.31 2 / 1
0.17.30 2 / 1
0.17.29 2 / 1
0.17.28 2 / 1
0.17.27 2 / 1
0.17.26 2 / 1
0.17.25 2 / 1
0.17.24 2 / 1
0.17.23 2 / 1
0.17.22 2 / 1
0.17.21 2 / 1
0.17.20 2 / 1
0.17.19 2 / 1
0.17.18 2 / 1
0.17.17 2 / 1
0.17.16 2 / 1
0.17.15 1 / 1
0.17.14 1 / 1
0.17.13 1 / 1
0.17.12 1 / 1
0.17.11 1 / 1
0.17.10 1 / 1
0.17.9 1 / 1
0.17.8 1 / 1
0.17.7 1 / 1
0.17.6 1 / 1
0.17.5 1 / 1
0.17.4 1 / 1
0.17.3 1 / 1
0.17.2 1 / 1
0.17.1 1 / 1
0.17.0 1 / 1
0.16.0 1 / 1
0.14.8 0 / 1
0.14.7 0 / 1
0.14.6 0 / 1
0.14.5 0 / 1
0.14.4 0 / 1
0.14.3 0 / 1
0.14.2 0 / 1
0.14.1 0 / 1
0.13.7 0 / 1
0.13.6 0 / 1
0.13.5 0 / 1
0.13.4 0 / 1
0.13.3 0 / 1
0.13.2 0 / 1
0.13.1 0 / 1
0.13.0 0 / 1
0.12.31 0 / 1
0.12.30 0 / 1
0.12.29 0 / 1
0.12.28 0 / 1
0.12.27 0 / 1
0.12.26 0 / 1
0.12.25 0 / 1
0.12.24 0 / 1
0.12.23 0 / 1
0.12.22 0 / 1
0.12.21 0 / 1
0.12.20 0 / 1
0.12.13 2 / 0
0.12.12 2 / 0
0.12.11 2 / 0
0.12.10 2 / 0
0.12.9 2 / 0
0.12.8 2 / 0
0.12.7 2 / 0
0.12.6 2 / 0
0.12.5 2 / 0
0.12.4 2 / 0
0.12.3 2 / 0
0.12.2 2 / 0
0.12.1 2 / 0
0.12.0 2 / 0
0.11.0 2 / 0
0.10.0 2 / 0
0.9.2 2 / 0
0.9.1 2 / 0
0.9.0 2 / 0
0.8.0 2 / 0
0.7.3 2 / 0
0.7.2 2 / 0
0.7.1 2 / 0
0.7.0 2 / 0
0.6.2 2 / 0
0.6.1 2 / 0
0.6.0 2 / 0
0.5.3 2 / 0
0.5.2 2 / 0
0.5.1 2 / 0
Showing 100 of 122 Next page →

v0.17.40

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.17.39

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.17.38

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.17.37

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.17.36

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.