@nx/vitest
The Nx Plugin for Vitest to enable fast unit testing with Vitest.
45
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
nrwlownernrwl-jasonjack-nrwlmaxk-nrwljameshenry
Keywords
MonorepoVitestTestingUnit Testing
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:src/plugins/plugin.js | AI (source-diff): Standard CJS-compiled Nx plugin code with dynamic import('esbuild') workaround; not malicious. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Version jump causes file diff; established package with normal plugin structure. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): maxkless renamed to maxk-nrwl; same person. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): maxk-nrwl is a rename of maxkless within the Nrwl org. | ai | |
| source-diff | net-exec-file:dist/src/plugins/plugin.js | AI (source-diff): Standard Nx plugin boilerplate doing config scanning and caching; no actual malicious network/exec behavior. | ai | |
| typosquat | typosquat.levenshtein:vite | AI (typosquat): @nx/vitest is the official Nx plugin for vitest/vite; the name similarity is intentional, not a typosquat. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): Known esbuild dynamic-import workaround pattern in Nx plugin; not arbitrary code execution from user input. | ai |
Versions (showing 45 of 45)
| Version | Deps | Published |
|---|---|---|
| 23.1.0 | 5 / 1 | |
| 23.0.2 | 5 / 1 | |
| 23.0.1 | 5 / 1 | |
| 23.0.0 | 5 / 1 | |
| 22.7.7 | 5 / 1 | |
| 22.7.6 | 5 / 1 | |
| 22.7.5 | 5 / 1 | |
| 22.7.4 | 5 / 1 | |
| 22.7.3 | 5 / 1 | |
| 22.7.2 | 5 / 1 | |
| 22.7.1 | 5 / 1 | |
| 22.7.0 | 5 / 1 | |
| 22.6.5 | 5 / 1 | |
| 22.6.4 | 5 / 1 | |
| 22.6.3 | 5 / 1 | |
| 22.6.2 | 5 / 1 | |
| 22.6.1 | 5 / 1 | |
| 22.6.0 | 5 / 1 | |
| 22.5.4 | 5 / 1 | |
| 22.5.3 | 5 / 1 | |
| 22.5.2 | 5 / 1 | |
| 22.5.1 | 5 / 1 | |
| 22.5.0 | 5 / 1 | |
| 22.4.5 | 5 / 1 | |
| 22.4.4 | 5 / 1 | |
| 22.4.3 | 5 / 1 | |
| 22.4.2 | 5 / 1 | |
| 22.4.1 | 5 / 1 | |
| 22.4.0 | 5 / 1 | |
| 22.3.3 | 5 / 1 | |
| 22.3.2 | 5 / 1 | |
| 22.3.1 | 5 / 1 | |
| 22.3.0 | 5 / 1 | |
| 22.2.7 | 5 / 1 | |
| 22.2.6 | 5 / 1 | |
| 22.2.5 | 5 / 1 | |
| 22.2.4 | 5 / 1 | |
| 22.2.3 | 5 / 1 | |
| 22.2.2 | 5 / 1 | |
| 22.2.1 | 5 / 1 | |
| 22.2.0 | 5 / 1 | |
| 22.1.3 | 5 / 1 | |
| 22.1.2 | 5 / 1 | |
| 22.1.1 | 5 / 1 | |
| 22.1.0 | 5 / 1 |
v23.1.0
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v23.0.2
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v22.7.7
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.