← Home

@storm-software/pulumi-tools

Tools for managing Pulumi infrastructure within a Nx workspace.

2
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

stormie-botsullivanpj

Keywords

iacinfrastructuremonorepopulumistormstorm-opsstorm-stacksullivanpj

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:env-spread AI (semgrep): Pulumi executor intentionally passes full env to child process; standard pattern for infrastructure tooling. ai
provenance publisher-changed AI (provenance): Transition to GitHub Actions publisher is consistent with CI/CD automation; backed by SLSA provenance attestation. ai
phantom-deps phantom-dep:@pulumi/awsx AI (phantom-deps): Package is declared as a runtime dep and referenced in config; not directly imported is expected for optional Pulumi provider usage. ai

Versions (showing 2 of 406)

Version Deps Published
0.7.62 2 / 5
0.7.61 2 / 5

v0.7.62

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.61

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.