← Home

@storm-software/cloudflare-tools

A Nx plugin package that contains various executors, generators, and utilities that assist in managing Cloudflare services.

8
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

stormie-botsullivanpj

Keywords

monorepoopen-systemstormstorm-opsstorm-stackstormstacksullivanpj

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:env-bulk-read AI (semgrep): Used only for debug trace logging of config; not exfiltrating data. ai
semgrep semgrep:env-spread AI (semgrep): Code explicitly names only two env vars (CLOUDFLARE_ACCOUNT_ID, CLOUDFLARE_API_TOKEN); no actual full spread of process.env. ai
provenance publisher-changed AI (provenance): Transition from stormie-bot to GitHub Actions reflects CI/CD automation; SLSA provenance attestation confirms integrity. ai

Versions (showing 8 of 422)

Version Deps Published
0.55.73 2 / 8
0.55.72 2 / 8
0.55.71 2 / 8
0.55.70 2 / 8
0.55.69 2 / 8
0.55.68 2 / 8
0.55.67 2 / 8
0.55.66 2 / 8

v0.55.73

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.55.72

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.55.71

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.55.70

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.55.69

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.55.68

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.55.67

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.55.66

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.