← Home

@brightspace-ui/testing

Utilities for testing front-end components and applications

25
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

d2l-travis-deploy

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition from d2l-travis-deploy to GitHub Actions is a documented CI migration; SLSA provenance attestation confirms legitimate CI/CD build. ai
dependencies unvetted-dep:@web/dev-server AI (dependencies): Well-known @web toolchain package; stable for this testing utility. ai
dependencies unvetted-dep:@open-wc/testing AI (dependencies): Standard open-wc testing library; stable for this package. ai
dependencies unvetted-dep:@web/test-runner AI (dependencies): Well-known @web toolchain package; stable for this testing utility. ai
dependencies unvetted-dep:d2l-test-reporting AI (dependencies): D2L-owned reporting package; same org as this package. ai
dependencies unvetted-dep:@web/rollup-plugin-html AI (dependencies): Well-known @web toolchain package; stable for this testing utility. ai
dependencies unvetted-dep:@web/test-runner-commands AI (dependencies): Well-known @web toolchain package; stable for this testing utility. ai
dependencies unvetted-dep:@web/test-runner-playwright AI (dependencies): Well-known @web toolchain package; stable for this testing utility. ai
dependencies unvetted-dep:@brightspace-ui/intl AI (dependencies): Same Brightspace org; stable for this package. ai
phantom-deps phantom-dep:rollup AI (phantom-deps): rollup is a declared runtime dependency used in config files; stable false positive for this package. ai

Versions (showing 25 of 25)

Version Deps Published
1.46.0 17 / 8
1.45.0 17 / 8
1.44.2 17 / 8
1.44.1 17 / 8
1.44.0 17 / 8
1.43.0 17 / 8
1.42.0 17 / 8
1.39.2 17 / 8
1.39.1 17 / 8
1.38.2 17 / 8
1.38.1 17 / 8
1.38.0 17 / 8
1.36.1 17 / 7
1.34.0 17 / 7
1.33.0 17 / 7
1.32.1 17 / 7
1.32.0 17 / 7
1.31.7 18 / 7
1.31.6 18 / 7
1.31.5 18 / 7
1.31.4 18 / 7
1.31.3 18 / 7
1.31.2 18 / 7
1.31.1 18 / 7
1.31.0 18 / 7

v1.46.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.45.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.44.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.44.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.44.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.43.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.42.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.39.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.39.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.38.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.38.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.38.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.36.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.34.0

2 findings
HIGH Publisher changed: d2l-travis-deploy → GitHub Actions (on 2025-10-21) provenance

This version was published by a different npm account than previous versions on 2025-10-21. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.33.0

2 findings
HIGH Publisher changed: d2l-travis-deploy → GitHub Actions (on 2025-10-17) provenance

This version was published by a different npm account than previous versions on 2025-10-17. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.32.1

2 findings
HIGH Publisher changed: d2l-travis-deploy → GitHub Actions (on 2025-10-17) provenance

This version was published by a different npm account than previous versions on 2025-10-17. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.32.0

2 findings
HIGH Publisher changed: d2l-travis-deploy → GitHub Actions (on 2025-10-16) provenance

This version was published by a different npm account than previous versions on 2025-10-16. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.31.7

2 findings
HIGH Publisher changed: d2l-travis-deploy → GitHub Actions (on 2025-10-17) provenance

This version was published by a different npm account than previous versions on 2025-10-17. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.31.6

2 findings
HIGH Publisher changed: d2l-travis-deploy → GitHub Actions (on 2025-10-17) provenance

This version was published by a different npm account than previous versions on 2025-10-17. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.31.5

2 findings
HIGH Publisher changed: d2l-travis-deploy → GitHub Actions (on 2025-10-16) provenance

This version was published by a different npm account than previous versions on 2025-10-16. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.31.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.31.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.31.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.31.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.31.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.