← Home

@applitools/eyes-browser

51
Versions
SEE LICENSE IN LICENSE
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

danielputermangearmamit.rokachroy.selaapplitools-adminapplitools-readonlyiasisappnoam.mendelarik-applitoolsyotammademdenis.styrtkyrylo.onufriievormedaclementbarryidosapplitoolsgofilordalex.burdeynyyronikar_applitoolsbenny.halberstadtgrayscale64fatihsolhan-applitoolsitaiz134dockermasteranandbagmaritaytamir-atsergovapplitoolsfluxomni.iommilappnoam.gaashroeefranastasia.koifmanaretm_borodavkayonittzairilevyasundaram-applitoolsamir.groismanemasuarynaama.shohamadamcarmimulygottliebyoavnaveh-applitoolschaimaharonsonmovshonetta.bondyshirbinranhadardmytro-hrostyslav.pidburachynskyi.applitoolstaltool

Keywords

applitoolsbrowserchrome extensioneyeseyes-sdkstandalonetest automationvisual regressionautomationtestingtests

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
vendored-integrity tampered-vendored-dep:. AI (vendored-integrity): Diff is metadata + bundled dist output, not an injected payload; content-verified tree covers 76/79 files. ai
phantom-deps phantom-dep:@applitools/snippets AI (phantom-deps): Same-org official Applitools package used at build/runtime. ai
phantom-deps phantom-dep:@applitools/dom-snapshot AI (phantom-deps): Same-org official Applitools package used at build/runtime. ai
source-diff encoded-string-file:dist/index.js AI (source-diff): Long hex strings are DH prime constants from bundled diffie-hellman module; not obfuscated payloads. ai
phantom-deps phantom-dep:@applitools/eyes AI (phantom-deps): Same-org runtime dep bundled for browser distribution; not directly imported but legitimately declared. ai

Versions (showing 51 of 89)

View all versions
Version Deps Published
1.6.26 3 / 17
1.6.25 1 / 17
1.6.24 1 / 17
1.6.23 1 / 17
1.6.22 1 / 17
1.6.21 1 / 17
1.6.20 1 / 17
1.6.19 1 / 17
1.6.18 1 / 17
1.6.17 1 / 17
1.6.16 1 / 17
1.6.15 1 / 17
1.6.14 1 / 17
1.6.13 1 / 17
1.6.12 1 / 17
1.6.11 1 / 17
1.6.10 1 / 17
1.6.9 1 / 17
1.6.8 1 / 17
1.6.7 1 / 17
1.6.6 1 / 17
1.6.5 1 / 17
1.6.4 1 / 17
1.6.3 1 / 17
1.6.2 1 / 17
1.6.1 1 / 17
1.6.0 1 / 17
1.5.24 1 / 14
1.5.23 1 / 14
1.5.22 1 / 14
1.5.21 1 / 14
1.5.20 1 / 14
1.5.19 1 / 14
1.5.18 1 / 14
1.5.17 1 / 14
1.5.16 1 / 14
1.5.15 1 / 14
1.5.14 1 / 14
1.5.13 1 / 14
1.5.12 1 / 14
1.5.11 1 / 14
1.5.10 1 / 14
1.5.9 1 / 14
1.5.8 1 / 14
1.5.7 1 / 14
1.5.6 1 / 14
1.5.5 1 / 14
1.5.4 1 / 14
1.5.3 1 / 14
1.5.2 1 / 14
1.5.1 1 / 14

v1.6.26

2 findings
HIGH Modified vendored dependency: . (3 file(s)) vendored-integrity

The directory `.` byte-matched 76 of 79 file(s) against @applitools/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 3 file(s) inside it differ from that package's bytes at the same path: CHANGELOG.md, dist/index.js, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @applitools/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.25

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.24

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.17

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: danielputerman → movsho (on 2026-05-19, known maintainer) provenance

This version was published by a different npm account (movsho) than the most recent previously approved version (danielputerman) on 2026-05-19, but movsho is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.6.16

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.15

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: danielputerman → movsho (on 2026-05-04, known maintainer) provenance

This version was published by a different npm account (movsho) than the most recent previously approved version (danielputerman) on 2026-05-04, but movsho is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.6.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.5.24

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.5.23

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.5.22

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.5.21

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.5.20

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.5.19

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.5.18

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.5.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.5.16

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.5.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.