← Home

@storm-software/workspace-tools

15
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

stormie-bot

Keywords

monoreponxstorm-softwarestorm-opsstormsullivanpj

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@actions/core AI (phantom-deps): Declared but not directly imported; used in CI/CD config context consistent with a workspace-tools package. ai
source-diff large-new-source-files AI (source-diff): High-velocity monorepo package; large file additions are routine across its 1367 versions. ai
dependencies unvetted-dep:@samchon/openapi AI (dependencies): Known OpenAPI library; phantom-dep finding confirms it's config-only usage. ai
dependencies unvetted-dep:@size-limit/file AI (dependencies): Part of size-limit ecosystem; no risk indicators. ai
dependencies unvetted-dep:@nx/js AI (dependencies): Well-known Nx ecosystem package; stable dependency for this workspace-tools package. ai
dependencies unvetted-dep:@size-limit/esbuild-why AI (dependencies): Part of size-limit ecosystem; no risk indicators. ai
dependencies unvetted-dep:@size-limit/esbuild AI (dependencies): Part of size-limit ecosystem; no risk indicators. ai
dependencies unvetted-dep:size-limit AI (dependencies): Established size-limit tooling; no malware indicators. ai
phantom-deps phantom-dep:@storm-software/tsdown AI (phantom-deps): Same-org dep used in config files; stable pattern for this package. ai
phantom-deps phantom-dep:@microsoft/api-extractor AI (phantom-deps): Referenced in config files only; stable false positive for this package. ai
phantom-deps phantom-dep:@storm-software/esbuild AI (phantom-deps): Same-org dep used in config files; stable pattern for this package. ai
phantom-deps phantom-dep:@storm-software/unbuild AI (phantom-deps): Same-org dep used in config files; stable pattern for this package. ai
phantom-deps phantom-dep:@storm-software/prettier AI (phantom-deps): Same-org dep used in config files; stable pattern for this package. ai
phantom-deps phantom-dep:@storm-software/npm-tools AI (phantom-deps): Same-org dep used in config files; stable pattern for this package. ai
phantom-deps phantom-dep:@storm-software/pnpm-tools AI (phantom-deps): Same-org dep used in config files; stable pattern for this package. ai
phantom-deps phantom-dep:@samchon/openapi AI (phantom-deps): Referenced in config files only; stable false positive for this package. ai
phantom-deps phantom-dep:markdownlint-cli2 AI (phantom-deps): Declared as peer dep and used in config; stable false positive for this package. ai

Versions (showing 15 of 328)

Version Deps Published
1.267.14 21 / 8
1.267.13 21 / 8
1.267.12 21 / 8
1.267.11 21 / 8
1.267.10 21 / 8
1.267.9 21 / 8
1.267.8 21 / 8
1.267.7 21 / 8
1.267.6 21 / 8
1.267.5 21 / 8
1.267.4 21 / 8
1.267.3 21 / 8
1.267.2 21 / 8
1.267.1 21 / 8
1.267.0 21 / 8

v1.267.14

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.267.13

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.267.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.267.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.267.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.267.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.267.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.267.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.267.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.267.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.267.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.267.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.267.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.267.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.267.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.