← Home

@lowdefy/server-e2e

Lowdefy e2e testing server with cookie-based user injection

9
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

samtolmaygervwykmachielvdw

Keywords

lowdefyservere2etesting

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:base64-decode AI (semgrep): Decodes session cookie JWT-style payload; standard auth pattern for this e2e server. ai
semgrep semgrep:env-bulk-read AI (semgrep): Reads only LOWDEFY_E2E_SECRET_* prefixed env vars; intentional e2e secret injection pattern. ai
semgrep semgrep:dynamic-require AI (semgrep): Loads plugin type maps by package name; documented plugin loader pattern for Lowdefy. ai
phantom-deps phantom-dep:pino AI (phantom-deps): Listed in dependencies; phantom-dep heuristic false positive for config-referenced deps. ai
phantom-deps phantom-dep:dayjs AI (phantom-deps): Listed in dependencies; used via config/plugin references in monorepo. ai
phantom-deps phantom-dep:react-dom AI (phantom-deps): Next.js app dependency; used implicitly by framework. ai
phantom-deps phantom-dep:react-icons AI (phantom-deps): UI icon library; referenced in config/templates, not direct imports. ai
phantom-deps phantom-dep:@lowdefy/layout AI (phantom-deps): Same-org monorepo package; resolved via plugin/config system. ai
phantom-deps phantom-dep:@lowdefy/blocks-antd AI (phantom-deps): Same-org monorepo package; resolved via plugin/config system. ai
phantom-deps phantom-dep:@lowdefy/actions-core AI (phantom-deps): Same-org monorepo package; resolved via plugin/config system. ai
phantom-deps phantom-dep:@lowdefy/blocks-basic AI (phantom-deps): Same-org monorepo package; resolved via plugin/config system. ai
phantom-deps phantom-dep:@lowdefy/operators-js AI (phantom-deps): Same-org monorepo package; resolved via plugin/config system. ai
phantom-deps phantom-dep:@lowdefy/blocks-loaders AI (phantom-deps): Same-org monorepo package; resolved via plugin/config system. ai
phantom-deps phantom-dep:@lowdefy/operators-uuid AI (phantom-deps): Same-org monorepo package; resolved via plugin/config system. ai
phantom-deps phantom-dep:@lowdefy/blocks-markdown AI (phantom-deps): Same-org monorepo package; resolved via plugin/config system. ai
phantom-deps phantom-dep:@lowdefy/connection-mongodb AI (phantom-deps): Same-org monorepo package; resolved via plugin/config system. ai
phantom-deps phantom-dep:@lowdefy/operators-nunjucks AI (phantom-deps): Same-org monorepo package; resolved via plugin/config system. ai
phantom-deps phantom-dep:@lowdefy/connection-axios-http AI (phantom-deps): Same-org monorepo package; resolved via plugin/config system. ai

Versions (showing 9 of 9)

Version Deps Published
5.3.0 29 / 7
5.2.0 29 / 7
5.1.0 28 / 7
5.0.0 28 / 7
4.7.3 25 / 8
4.7.2 25 / 8
4.7.1 25 / 8
4.7.0 25 / 8
4.6.0 25 / 8

v5.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.7.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.7.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.7.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.7.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.