@applitools/dom-snapshot
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-added | AI (maintainer-change): Internal Applitools team rotation, publisher matched as known maintainer. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Consistent with team rotation, not a takeover pattern. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): css-tree replaces @applitools/css-tree fork, benign rename. | ai | |
| phantom-deps | phantom-dep:pako | AI (phantom-deps): Bundled via rollup build; declared as runtime dep, not directly imported in source. | ai | |
| phantom-deps | phantom-dep:@applitools/dom-shared | AI (phantom-deps): Same-org dependency; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:throat | AI (phantom-deps): Bundled via rollup build; declared as runtime dep, not directly imported in source. | ai | |
| phantom-deps | phantom-dep:css-tree | AI (phantom-deps): Bundled via rollup build; declared as runtime dep, not directly imported in source. | ai |
Versions (showing 51 of 54)
| Version | Deps | Published |
|---|---|---|
| 4.17.6 | 5 / 41 | |
| 4.17.5 | 5 / 41 | |
| 4.17.4 | 5 / 41 | |
| 4.17.3 | 5 / 40 | |
| 4.17.2 | 5 / 40 | |
| 4.17.1 | 5 / 40 | |
| 4.17.0 | 5 / 37 | |
| 4.16.4 | 5 / 37 | |
| 4.16.3 | 5 / 37 | |
| 4.16.2 | 5 / 37 | |
| 4.16.1 | 5 / 37 | |
| 4.16.0 | 5 / 37 | |
| 4.15.11 | 5 / 37 | |
| 4.15.10 | 5 / 37 | |
| 4.15.9 | 5 / 37 | |
| 4.15.8 | 5 / 37 | |
| 4.15.7 | 5 / 37 | |
| 4.15.6 | 4 / 37 | |
| 4.15.5 | 4 / 37 | |
| 4.15.4 | 4 / 37 | |
| 4.15.3 | 4 / 37 | |
| 4.15.2 | 4 / 37 | |
| 4.15.1 | 4 / 36 | |
| 4.13.7 | 4 / 31 | |
| 4.13.6 | 4 / 31 | |
| 4.13.5 | 4 / 31 | |
| 4.13.4 | 4 / 31 | |
| 4.13.3 | 4 / 31 | |
| 4.13.2 | 4 / 31 | |
| 4.13.1 | 4 / 31 | |
| 4.13.0 | 4 / 31 | |
| 4.12.1 | 4 / 31 | |
| 4.12.0 | 4 / 31 | |
| 4.11.22 | 4 / 31 | |
| 4.11.21 | 4 / 31 | |
| 4.11.20 | 4 / 31 | |
| 4.11.19 | 4 / 31 | |
| 4.11.18 | 4 / 31 | |
| 4.11.17 | 4 / 31 | |
| 4.11.16 | 4 / 31 | |
| 4.11.15 | 4 / 31 | |
| 4.11.14 | 4 / 31 | |
| 4.11.13 | 4 / 31 | |
| 4.11.12 | 4 / 31 | |
| 4.11.11 | 4 / 31 | |
| 4.11.10 | 4 / 31 | |
| 4.11.9 | 4 / 31 | |
| 4.11.8 | 4 / 31 | |
| 4.11.7 | 4 / 31 | |
| 4.11.6 | 4 / 32 | |
| 4.11.5 | 4 / 32 |
v4.17.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.17.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.16.3
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (danielputerman) than the most recent previously approved version (applitools-admin) on 2026-04-13, but danielputerman is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.16.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (danielputerman) than the most recent previously approved version (applitools-admin) on 2026-03-29, but danielputerman is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.16.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (danielputerman) than the most recent previously approved version (applitools-admin) on 2026-03-16, but danielputerman is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.16.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (danielputerman) than the most recent previously approved version (applitools-admin) on 2026-03-12, but danielputerman is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.15.11
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (danielputerman) than the most recent previously approved version (applitools-admin) on 2026-03-08, but danielputerman is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.15.10
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (danielputerman) than the most recent previously approved version (applitools-admin) on 2026-03-03, but danielputerman is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.15.9
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (danielputerman) than the most recent previously approved version (applitools-admin) on 2026-03-02, but danielputerman is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.15.8
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (danielputerman) than the most recent previously approved version (applitools-admin) on 2026-02-16, but danielputerman is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.15.7
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (danielputerman) than the most recent previously approved version (applitools-admin) on 2026-01-22, but danielputerman is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.15.6
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (danielputerman) than the most recent previously approved version (applitools-admin) on 2026-01-20, but danielputerman is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.15.5
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (danielputerman) than the most recent previously approved version (applitools-admin) on 2026-01-11, but danielputerman is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.15.4
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (danielputerman) than the most recent previously approved version (applitools-admin) on 2025-12-28, but danielputerman is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.15.3
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (danielputerman) than the most recent previously approved version (applitools-admin) on 2025-12-07, but danielputerman is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.15.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (danielputerman) than the most recent previously approved version (applitools-admin) on 2025-12-01, but danielputerman is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.15.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (danielputerman) than the most recent previously approved version (applitools-admin) on 2025-11-20, but danielputerman is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.11.21
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.11.20
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.11.19
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.11.18
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.11.17
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.11.16
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.11.15
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.11.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.11.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.11.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.11.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.11.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.11.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.11.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.11.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.11.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.11.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.