← Home

@stryke/url

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

sullivanpjstormie-bot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Publisher changed from stormie-bot to GitHub Actions as part of a legitimate CI/CD migration for the storm-software/stryke monorepo, corroborated by SLSA provenance attestation. ai
bogus-package bogus-package AI (bogus-package): Low-score cosmetic signals (off-topic README content, no keywords) with no security relevance for this established URL utility package. ai
source-diff obfuscated-file:dist/storm-url-t7pdfQNU.cjs AI (source-diff): Minified bundle output from tsdown build tool; code is readable JS logic using known deps (ufo, superjson, jsonc-parser). Not obfuscation — standard minification for this package. ai
source-diff obfuscated-file:dist/storm-url-DQn2usO1.mjs AI (source-diff): Minified ESM bundle output from tsdown build tool; same readable logic as CJS counterpart. Standard minification, not obfuscation. ai

Versions (showing 51 of 97)

View all versions
Version Deps Published
0.4.49 3 / 2
0.4.48 3 / 2
0.4.47 3 / 2
0.4.46 3 / 2
0.4.45 3 / 2
0.4.44 3 / 2
0.4.43 3 / 2
0.4.42 3 / 2
0.4.41 3 / 2
0.4.40 3 / 2
0.4.39 3 / 2
0.4.38 3 / 2
0.4.37 4 / 2
0.4.36 4 / 2
0.4.35 4 / 2
0.4.34 4 / 2
0.4.33 4 / 2
0.4.32 4 / 2
0.4.31 4 / 2
0.4.30 4 / 2
0.4.29 4 / 2
0.4.28 4 / 2
0.4.27 4 / 2
0.4.26 4 / 2
0.4.25 4 / 2
0.4.24 4 / 2
0.4.23 4 / 2
0.4.22 4 / 2
0.4.21 1 / 2
0.4.20 1 / 2
0.4.19 1 / 2
0.4.18 1 / 2
0.4.17 1 / 2
0.4.16 1 / 2
0.4.15 1 / 2
0.4.14 1 / 2
0.4.13 1 / 2
0.4.12 1 / 2
0.4.11 1 / 2
0.4.10 1 / 2
0.4.9 1 / 2
0.4.8 1 / 2
0.4.7 1 / 2
0.4.6 1 / 2
0.4.3 1 / 2
0.4.2 1 / 2
0.4.1 1 / 2
0.4.0 1 / 2
0.3.39 1 / 2
0.3.38 1 / 2
0.3.37 1 / 2

v0.4.49

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.48

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.47

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.46

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.45

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.44

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.43

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.