@applitools/core
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@types/ws | AI (phantom-deps): Framework-scoped type definitions loaded by convention; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:webdriver | AI (phantom-deps): Referenced in config; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@applitools/socket | AI (phantom-deps): Same-org scope dep; phantom-dep heuristic is a stable false positive for this monorepo package. | ai | |
| typosquat | typosquat.levenshtein:cors | AI (typosquat): Scoped @applitools/core is a legitimate SDK package; Levenshtein match to 'cors' is a false positive. | ai |
Versions (showing 60 of 60)
| Version | Deps | Published |
|---|---|---|
| 4.64.0 | 18 / 23 | |
| 4.63.1 | 18 / 23 | |
| 4.62.0 | 18 / 18 | |
| 4.61.0 | 18 / 16 | |
| 4.60.0 | 18 / 16 | |
| 4.59.3 | 18 / 16 | |
| 4.59.2 | 18 / 16 | |
| 4.59.1 | 18 / 16 | |
| 4.59.0 | 18 / 16 | |
| 4.58.2 | 18 / 16 | |
| 4.58.1 | 18 / 16 | |
| 4.58.0 | 18 / 16 | |
| 4.57.2 | 18 / 16 | |
| 4.57.1 | 18 / 16 | |
| 4.57.0 | 18 / 16 | |
| 4.56.3 | 18 / 16 | |
| 4.56.2 | 23 / 17 | |
| 4.56.1 | 23 / 18 | |
| 4.56.0 | 23 / 18 | |
| 4.55.0 | 23 / 18 | |
| 4.54.4 | 23 / 18 | |
| 4.54.3 | 23 / 18 | |
| 4.54.2 | 23 / 18 | |
| 4.54.1 | 23 / 18 | |
| 4.54.0 | 23 / 18 | |
| 4.53.2 | 23 / 18 | |
| 4.53.1 | 23 / 18 | |
| 4.53.0 | 23 / 18 | |
| 4.52.0 | 23 / 18 | |
| 4.51.0 | 23 / 18 | |
| 4.50.4 | 23 / 18 | |
| 4.50.3 | 23 / 18 | |
| 4.50.2 | 23 / 18 | |
| 4.50.1 | 23 / 18 | |
| 4.50.0 | 23 / 18 | |
| 4.49.0 | 23 / 18 | |
| 4.48.0 | 23 / 18 | |
| 4.47.1 | 23 / 18 | |
| 4.47.0 | 23 / 18 | |
| 4.46.0 | 23 / 18 | |
| 4.45.0 | 23 / 18 | |
| 4.44.5 | 23 / 18 | |
| 4.44.4 | 23 / 18 | |
| 4.44.3 | 23 / 18 | |
| 4.44.2 | 23 / 18 | |
| 4.44.1 | 23 / 18 | |
| 4.44.0 | 23 / 18 | |
| 4.43.0 | 23 / 18 | |
| 4.42.1 | 23 / 18 | |
| 4.42.0 | 23 / 18 | |
| 4.41.0 | 23 / 18 | |
| 4.40.0 | 23 / 18 | |
| 4.39.3 | 23 / 18 | |
| 4.39.2 | 23 / 18 | |
| 4.39.1 | 23 / 18 | |
| 4.39.0 | 23 / 18 | |
| 4.38.2 | 23 / 17 | |
| 4.38.1 | 23 / 17 | |
| 4.38.0 | 23 / 17 | |
| 4.37.1 | 23 / 17 |
v4.64.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.63.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.62.0
2 findingsThis version was published by a different npm account than previous versions on 2026-05-05. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.61.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.59.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.59.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.59.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.59.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.58.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.58.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.58.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.57.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.57.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.57.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.56.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.56.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.56.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.56.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.55.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.54.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.54.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.54.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.54.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.54.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.53.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.53.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.53.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.52.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.51.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.50.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.50.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.50.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.50.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.50.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.49.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.48.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.47.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.47.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.46.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.45.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.44.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.44.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.44.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.44.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.44.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.44.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.43.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.42.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.42.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.41.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.40.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.39.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.39.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.39.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.39.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.38.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.38.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.38.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.37.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.