@handy-common-utils/dev-dependencies-mocha
This package contains dependencies that are common, including mocha
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:eslint-plugin-chai-friendly | AI (phantom-deps): Dev-dependencies aggregator; phantom-deps are expected and stable for this package's purpose. | ai | |
| provenance | missing-githead | AI (provenance): Cosmetic provenance gap; no other risk signals present for this well-established dev-dependencies package. | ai | |
| phantom-deps | phantom-dep:nyc | AI (phantom-deps): Config-referenced test coverage tool; stable for this dev-dependencies package. | ai | |
| phantom-deps | phantom-dep:@istanbuljs/nyc-config-typescript | AI (phantom-deps): Config-referenced Istanbul preset; stable for this dev-dependencies package. | ai | |
| provenance | no-provenance | AI (provenance): Dev-tooling bundle; no provenance is common and not a meaningful risk here. | ai | |
| dependencies | unvetted-dep:@types/chai | AI (dependencies): @types/chai is a standard TypeScript type definition package; no security risk. | ai | |
| phantom-deps | phantom-dep:@types/mocha | AI (phantom-deps): Dev-dependency bundle; type packages declared for consumers. | ai | |
| phantom-deps | phantom-dep:@types/sinon | AI (phantom-deps): Dev-dependency bundle; type packages declared for consumers. | ai | |
| phantom-deps | phantom-dep:chai-as-promised | AI (phantom-deps): Dev-dependency bundle; deps declared for consumers. | ai | |
| phantom-deps | phantom-dep:c8 | AI (phantom-deps): Dev-dependency bundle; deps declared for consumers, not imported directly by this package. | ai | |
| phantom-deps | phantom-dep:@types/chai-as-promised | AI (phantom-deps): Dev-dependency bundle; type packages declared for consumers. | ai | |
| phantom-deps | phantom-dep:eslint-plugin-chai-expect | AI (phantom-deps): Dev-dependency bundle; deps declared for consumers. | ai | |
| phantom-deps | phantom-dep:@handy-common-utils/dev-dependencies-common | AI (phantom-deps): Same-org sibling package; declared for consumers. | ai | |
| phantom-deps | phantom-dep:@types/sinon-chai | AI (phantom-deps): Dev-dependency bundle; type packages declared for consumers. | ai | |
| phantom-deps | phantom-dep:chai | AI (phantom-deps): Dev-dependency bundle; deps declared for consumers, not imported directly by this package. | ai | |
| phantom-deps | phantom-dep:mocha | AI (phantom-deps): Dev-dependency bundle; deps declared for consumers, not imported directly by this package. | ai | |
| phantom-deps | phantom-dep:sinon | AI (phantom-deps): Dev-dependency bundle; deps declared for consumers, not imported directly by this package. | ai | |
| phantom-deps | phantom-dep:sinon-chai | AI (phantom-deps): Dev-dependency bundle; deps declared for consumers, not imported directly by this package. | ai | |
| phantom-deps | phantom-dep:@types/chai | AI (phantom-deps): Dev-dependency bundle; type packages declared for consumers. | ai |
Versions (showing 16 of 16)
| Version | Deps | Published |
|---|---|---|
| 1.11.13 | 14 / 2 | |
| 1.11.12 | 14 / 2 | |
| 1.11.11 | 14 / 2 | |
| 1.11.10 | 14 / 2 | |
| 1.11.8 | 14 / 2 | |
| 1.11.7 | 14 / 2 | |
| 1.11.6 | 14 / 2 | |
| 1.10.3 | 15 / 2 | |
| 1.10.2 | 15 / 2 | |
| 1.10.1 | 15 / 2 | |
| 1.9.5 | 15 / 2 | |
| 1.9.4 | 13 / 2 | |
| 1.9.3 | 13 / 2 | |
| 1.9.2 | 13 / 2 | |
| 1.8.0 | 13 / 2 | |
| 1.7.0 | 13 / 2 |
v1.11.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.11.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.11.11
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: james-hu.
v1.11.10
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: james-hu.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.10.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.10.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.8.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.