@applitools/eyes-playwright
Applitools Eyes SDK for Playwright
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | no-provenance | AI (provenance): Established package; provenance is aspirational, not a blocker for mature packages. | ai | |
| license | uncommon-license:SEE LICENSE IN LICENSE | AI (license): Custom license file reference; stable pattern for this package. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Applitools SDK with 185 published versions; dormancy likely reflects release cadence, not account takeover. | ai | |
| dependencies | unvetted-dep:@applitools/req | AI (dependencies): First-party @applitools scoped dep; consistent with Applitools SDK ecosystem. | ai | |
| dependencies | unvetted-dep:@applitools/spec-driver-playwright | AI (dependencies): First-party @applitools scoped dep; Playwright driver for the SDK. | ai | |
| dependencies | unvetted-dep:@applitools/eyes | AI (dependencies): First-party @applitools scoped dep; core SDK dependency. | ai | |
| dependencies | unvetted-dep:@applitools/utils | AI (dependencies): First-party @applitools scoped dep; stable utility package. | ai |
Versions (showing 47 of 47)
| Version | Deps | Published |
|---|---|---|
| 1.47.4 | 8 / 16 | |
| 1.47.0 | 7 / 14 | |
| 1.46.8 | 7 / 14 | |
| 1.46.7 | 7 / 14 | |
| 1.46.6 | 7 / 14 | |
| 1.46.5 | 7 / 14 | |
| 1.46.4 | 7 / 14 | |
| 1.46.3 | 7 / 14 | |
| 1.46.2 | 7 / 14 | |
| 1.46.1 | 7 / 14 | |
| 1.46.0 | 7 / 14 | |
| 1.45.2 | 7 / 14 | |
| 1.45.1 | 7 / 14 | |
| 1.45.0 | 7 / 14 | |
| 1.44.5 | 7 / 14 | |
| 1.44.4 | 7 / 14 | |
| 1.44.3 | 7 / 14 | |
| 1.44.2 | 7 / 14 | |
| 1.44.1 | 7 / 14 | |
| 1.44.0 | 7 / 14 | |
| 1.43.0 | 7 / 14 | |
| 1.42.5 | 7 / 14 | |
| 1.42.4 | 7 / 14 | |
| 1.42.3 | 7 / 14 | |
| 1.42.2 | 7 / 14 | |
| 1.42.1 | 7 / 14 | |
| 1.41.2 | 7 / 14 | |
| 1.41.1 | 7 / 14 | |
| 1.40.7 | 7 / 13 | |
| 1.40.6 | 7 / 13 | |
| 1.40.5 | 7 / 13 | |
| 1.40.4 | 7 / 13 | |
| 1.40.3 | 7 / 13 | |
| 1.40.2 | 7 / 13 | |
| 1.40.1 | 7 / 13 | |
| 1.40.0 | 7 / 13 | |
| 1.39.6 | 8 / 13 | |
| 1.39.5 | 8 / 13 | |
| 1.39.4 | 8 / 13 | |
| 1.39.3 | 8 / 13 | |
| 1.39.2 | 8 / 13 | |
| 1.39.1 | 8 / 13 | |
| 1.39.0 | 6 / 12 | |
| 1.38.2 | 6 / 12 | |
| 1.38.1 | 6 / 12 | |
| 1.38.0 | 6 / 12 | |
| 1.37.3 | 6 / 12 |
v1.47.4
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (movsho) than the most recent previously approved version (danielputerman) on 2026-05-26, but movsho is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.47.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.46.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.46.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.46.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.46.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.46.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.46.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.46.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.46.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.45.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.45.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.45.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.44.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.44.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.44.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.44.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.44.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.44.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.43.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.42.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.42.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.42.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.42.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.41.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.41.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.40.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.40.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.40.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.40.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.40.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.40.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.40.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.40.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.39.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.39.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.39.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.39.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.39.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.39.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.39.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.38.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.38.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.38.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.37.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.