@matter/testing
Test harness for running JavaScript and Matter certification tests
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:child-process-import | AI (semgrep): Used in mocharc.cjs to invoke the build tool via spawnSync; legitimate build-time pattern for this test harness. | ai | |
| phantom-deps | phantom-dep:yaml | AI (phantom-deps): yaml is a declared runtime dep used in config handling; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@types/express | AI (phantom-deps): Type-only package for express which is a direct dep; phantom-dep false positive. | ai |
Versions (showing 4 of 4)
| Version | Deps | Published |
|---|---|---|
| 0.17.1 | 15 / 11 | |
| 0.17.0 | 15 / 11 | |
| 0.16.11 | 14 / 11 | |
| 0.16.0 | 14 / 11 |
v0.17.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.17.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.16.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.16.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.