@applitools/eyes
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| license | uncommon-license:SEE LICENSE IN LICENSE | AI (license): Custom license reference; legitimate for established org packages. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Established Applitools package with matching official repo; no suspicious changes in this release. | ai | |
| dependencies | unvetted-dep:@applitools/utils | AI (dependencies): Internal Applitools monorepo dependency; expected for this SDK family. | ai | |
| dependencies | unvetted-dep:@applitools/logger | AI (dependencies): Internal Applitools monorepo dependency; expected for this SDK family. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Applitools SDK package; missing description is cosmetic, not a malware indicator for this established package. | ai |
Versions (showing 53 of 53)
| Version | Deps | Published |
|---|---|---|
| 1.43.0 | 5 / 3 | |
| 1.42.1 | 5 / 3 | |
| 1.40.1 | 5 / 2 | |
| 1.40.0 | 5 / 2 | |
| 1.39.0 | 5 / 2 | |
| 1.38.15 | 5 / 2 | |
| 1.38.14 | 5 / 2 | |
| 1.38.13 | 5 / 2 | |
| 1.38.12 | 5 / 2 | |
| 1.38.11 | 5 / 2 | |
| 1.38.10 | 5 / 2 | |
| 1.38.9 | 5 / 2 | |
| 1.38.8 | 5 / 2 | |
| 1.38.7 | 5 / 2 | |
| 1.38.6 | 5 / 2 | |
| 1.38.5 | 5 / 2 | |
| 1.38.4 | 5 / 2 | |
| 1.38.3 | 5 / 2 | |
| 1.38.2 | 5 / 2 | |
| 1.38.1 | 5 / 2 | |
| 1.38.0 | 5 / 2 | |
| 1.37.0 | 5 / 2 | |
| 1.36.20 | 5 / 2 | |
| 1.36.19 | 5 / 2 | |
| 1.36.18 | 5 / 2 | |
| 1.36.17 | 5 / 2 | |
| 1.36.16 | 5 / 2 | |
| 1.36.15 | 5 / 2 | |
| 1.36.14 | 5 / 2 | |
| 1.36.13 | 5 / 2 | |
| 1.36.12 | 5 / 2 | |
| 1.36.11 | 5 / 2 | |
| 1.36.10 | 5 / 2 | |
| 1.36.9 | 5 / 2 | |
| 1.36.8 | 5 / 2 | |
| 1.36.7 | 5 / 2 | |
| 1.36.6 | 5 / 2 | |
| 1.36.5 | 5 / 2 | |
| 1.36.4 | 5 / 2 | |
| 1.36.3 | 5 / 2 | |
| 1.36.2 | 5 / 2 | |
| 1.36.1 | 5 / 2 | |
| 1.36.0 | 5 / 2 | |
| 1.35.3 | 5 / 2 | |
| 1.35.2 | 5 / 2 | |
| 1.35.1 | 5 / 2 | |
| 1.35.0 | 5 / 2 | |
| 1.34.6 | 5 / 2 | |
| 1.34.5 | 5 / 2 | |
| 1.34.4 | 5 / 2 | |
| 1.34.3 | 5 / 2 | |
| 1.34.2 | 5 / 2 | |
| 1.34.1 | 5 / 2 |
v1.43.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.42.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.40.1
2 findingsThis version was published by a different npm account than previous versions on 2026-05-04. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.40.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.38.15
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.38.14
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.38.13
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.38.12
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.38.11
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.38.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.38.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.38.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.38.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.38.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.38.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.38.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.38.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.38.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.38.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.38.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.37.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.36.20
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.36.19
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.36.18
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.36.17
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.36.16
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.36.15
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.36.14
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.36.13
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.36.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.36.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.36.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.36.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.36.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.36.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.36.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.36.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.36.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.36.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.36.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.36.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.36.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.35.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.35.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.35.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.35.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.34.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.34.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.34.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.34.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.34.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.34.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.