← Home

@nationalbankbelgium/stark-testing

Stark - Testing

3
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

superitmannbb_ci

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
bogus-package bogus-package AI (bogus-package): Testing utility package; sparse README and no keywords are expected for this type of library. ai
dependencies unvetted-dep:protractor AI (dependencies): Protractor is a well-known Angular e2e testing framework; stable dependency for this testing config package. ai
dependencies unvetted-dep:@types/karma AI (dependencies): TypeScript types for Karma; standard testing tooling, no risk. ai
phantom-deps phantom-dep:@types/karma AI (phantom-deps): Framework-scoped type package; expected pattern for this testing config package. ai
phantom-deps phantom-dep:jasmine-core AI (phantom-deps): Testing config package; jasmine-core referenced in config files, not directly imported. ai
phantom-deps phantom-dep:karma-jasmine AI (phantom-deps): Testing config package; karma plugin referenced in config files, not directly imported. ai
phantom-deps phantom-dep:@types/jasmine AI (phantom-deps): Framework-scoped type package; expected pattern for this testing config package. ai
phantom-deps phantom-dep:karma-coverage AI (phantom-deps): Testing config package; karma plugin referenced in config files, not directly imported. ai
phantom-deps phantom-dep:karma-edge-launcher AI (phantom-deps): Testing config package; karma plugin referenced in config files, not directly imported. ai
phantom-deps phantom-dep:karma AI (phantom-deps): Testing config package; karma plugins are declared deps for consumers, not directly imported. ai
phantom-deps phantom-dep:karma-chrome-launcher AI (phantom-deps): Testing config package; karma plugin referenced in config files, not directly imported. ai
phantom-deps phantom-dep:karma-firefox-launcher AI (phantom-deps): Testing config package; karma plugin referenced in config files, not directly imported. ai
phantom-deps phantom-dep:karma-sourcemap-loader AI (phantom-deps): Testing config package; karma plugin referenced in config files, not directly imported. ai
phantom-deps phantom-dep:karma-jasmine-html-reporter AI (phantom-deps): Testing config package; karma plugin referenced in config files, not directly imported. ai
semgrep semgrep:dynamic-require AI (semgrep): Loads Angular CLI config file by path — standard config-loading pattern, not arbitrary code execution. ai
phantom-deps phantom-dep:karma-mocha-reporter AI (phantom-deps): Testing config package; karma plugin referenced in config files, not directly imported. ai
phantom-deps phantom-dep:protractor AI (phantom-deps): Testing config package; protractor is a declared dep for consumers, not directly imported. ai
phantom-deps phantom-dep:@types/node AI (phantom-deps): Framework-scoped type package; expected pattern for this testing config package. ai

Versions (showing 3 of 3)

Version Deps Published
12.0.3 17 / 0
12.0.2 17 / 0
12.0.1 17 / 0

v12.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v12.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v12.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.