← Home

@davidsneighbour/cypress-config

Cypress configuration for use in @davidsneighbour projects.

7
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

davidsneighbour

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:dynamic-require AI (semgrep): Config-loader pattern resolving user-supplied filenames; stable and intentional for this package. ai
phantom-deps phantom-dep:cypress AI (phantom-deps): Config package re-exports deps for consumers; not directly imported by design. ai
phantom-deps phantom-dep:cypress-axe AI (phantom-deps): Config package re-exports deps for consumers; not directly imported by design. ai
phantom-deps phantom-dep:cypress-html-validate AI (phantom-deps): Config package re-exports deps for consumers; not directly imported by design. ai
phantom-deps phantom-dep:eslint-plugin-cypress AI (phantom-deps): Config package re-exports deps for consumers; not directly imported by design. ai
phantom-deps phantom-dep:@davidsneighbour/htmlvalidate-config AI (phantom-deps): Same-org config package; declared for consumers, not directly imported by design. ai

Versions (showing 7 of 7)

Version Deps Published
2026.0.6 5 / 0
2026.0.5 5 / 0
2026.0.4 5 / 0
2026.0.3 5 / 0
2026.0.2 5 / 0
2026.0.1 5 / 0
2025.3.8 5 / 0

v2026.0.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2026.0.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2026.0.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2026.0.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2026.0.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2026.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2025.3.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.