@applitools/eyes-puppeteer
Applitools Eyes SDK for Puppeteer
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): danielputerman is a long-standing Applitools contributor with 404 approved packages; publisher rotation within org is expected. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Applitools SDK with long history; dormancy likely reflects SDK consolidation, not account takeover. | ai | |
| dependencies | unvetted-dep:@applitools/eyes | AI (dependencies): First-party Applitools scoped dependency; consistent with SDK architecture across all versions. | ai | |
| dependencies | unvetted-dep:@applitools/spec-driver-puppeteer | AI (dependencies): First-party Applitools scoped dependency; consistent with SDK architecture across all versions. | ai |
Versions (showing 49 of 49)
| Version | Deps | Published |
|---|---|---|
| 1.31.23 | 2 / 7 | |
| 1.31.22 | 2 / 7 | |
| 1.31.21 | 2 / 7 | |
| 1.31.20 | 2 / 7 | |
| 1.31.19 | 2 / 6 | |
| 1.31.18 | 2 / 6 | |
| 1.31.17 | 2 / 6 | |
| 1.31.16 | 2 / 6 | |
| 1.31.15 | 2 / 6 | |
| 1.31.14 | 2 / 6 | |
| 1.31.13 | 2 / 6 | |
| 1.31.12 | 2 / 6 | |
| 1.31.11 | 2 / 6 | |
| 1.31.10 | 2 / 6 | |
| 1.31.9 | 2 / 6 | |
| 1.31.8 | 2 / 6 | |
| 1.31.7 | 2 / 6 | |
| 1.31.6 | 2 / 6 | |
| 1.31.5 | 2 / 6 | |
| 1.31.4 | 2 / 6 | |
| 1.31.3 | 2 / 6 | |
| 1.31.2 | 2 / 6 | |
| 1.31.1 | 2 / 6 | |
| 1.31.0 | 2 / 6 | |
| 1.30.21 | 2 / 6 | |
| 1.30.20 | 2 / 6 | |
| 1.30.19 | 2 / 6 | |
| 1.30.18 | 2 / 6 | |
| 1.30.17 | 2 / 6 | |
| 1.30.16 | 2 / 6 | |
| 1.30.15 | 2 / 6 | |
| 1.30.14 | 2 / 6 | |
| 1.30.13 | 2 / 6 | |
| 1.30.12 | 2 / 6 | |
| 1.30.11 | 2 / 6 | |
| 1.30.10 | 2 / 6 | |
| 1.30.9 | 2 / 6 | |
| 1.30.8 | 2 / 6 | |
| 1.30.7 | 2 / 6 | |
| 1.30.6 | 2 / 6 | |
| 1.30.5 | 2 / 6 | |
| 1.30.4 | 2 / 6 | |
| 1.30.3 | 2 / 6 | |
| 1.30.2 | 2 / 6 | |
| 1.30.1 | 2 / 6 | |
| 1.30.0 | 2 / 6 | |
| 1.29.6 | 2 / 6 | |
| 1.29.5 | 2 / 6 | |
| 1.29.4 | 2 / 6 |
v1.31.23
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.31.22
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.31.21
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (movsho) than the most recent previously approved version (danielputerman) on 2026-05-26, but movsho is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.31.20
2 findingsThis version was published by a different npm account than previous versions on 2026-05-19. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.31.19
2 findingsThis version was published by a different npm account than previous versions on 2026-05-05. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.31.18
2 findingsThis version was published by a different npm account than previous versions on 2026-05-04. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.31.17
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.31.15
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.31.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.31.13
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.31.12
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.31.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.31.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.31.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.31.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.31.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.31.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.31.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.31.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.31.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.31.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.31.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.31.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.30.21
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.30.20
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.30.19
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.30.18
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.30.17
2 findingsThis version was published by a different npm account than previous versions on 2025-12-07. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.30.16
2 findingsThis version was published by a different npm account than previous versions on 2025-11-20. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.30.15
2 findingsThis version was published by a different npm account than previous versions on 2025-11-10. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.30.14
2 findingsThis version was published by a different npm account than previous versions on 2025-11-03. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.30.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.30.12
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.30.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.30.10
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.30.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.30.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.30.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.30.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.30.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.30.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.30.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.30.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.30.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.30.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.29.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.29.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.29.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.