← Home

@matterbridge/jest-utils

Matterbridge jest utility library

10
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

luligu

Keywords

matterbridgehomebridgebridgepluginfrontendmatter.jsmatter-node.jsmattermatterprotocoliotsmarthomeconnectedthingshaphomekitsirigoogle-homealexahomeassistantsmartthingsewelink

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
typosquat typosquat.pattern:jest AI (typosquat): @matterbridge/jest-utils is a scoped Jest utility library for the Matterbridge ecosystem, not a typosquat of 'jest'. The name similarity is intentional and descriptive. ai
bogus-package bogus-package AI (bogus-package): Monorepo utility package; thin export barrel and shared README are expected patterns, not spam indicators. Package has 18.7k weekly downloads and SLSA provenance. ai

Versions (showing 10 of 10)

Version Deps Published
3.8.0 2 / 0
3.7.10 1 / 0
3.7.9 1 / 0
3.7.8 1 / 0
3.7.7 1 / 0
3.7.6 1 / 0
3.7.5 1 / 0
3.7.2 1 / 0
3.5.4 1 / 0
0.0.1 1 / 0

v3.8.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.7.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.7.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.7.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.7.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.7.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.7.5

2 findings
HIGH typosquat.pattern: Suspicious name similarity to 'jest' typosquat

Package name '@matterbridge/jest-utils' matches a known typosquatting pattern (hyphen swap, prefix/suffix) of 'jest'.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.7.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.5.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.