@open-xchange/appsuite-codeceptjs
OX App Suite CodeceptJS Configuration and Helpers
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | new-deps-added | AI (publish-pattern): New dep is same-org scoped package (@open-xchange/appsuite-codeceptjs-pageobjects); low risk. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): mbiggeleben added within same org; consistent with internal team management. | ai | |
| dependencies | unvetted-dep:chalk-table | AI (dependencies): chalk-table is a simple table-formatting utility; stable dependency in this package's context. | ai | |
| phantom-deps | phantom-dep:playwright-core | AI (phantom-deps): Playwright peer dep referenced in config, not directly imported — expected pattern. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): CLI runner intentionally forwards parent env to child process; standard pattern for test tooling. | ai | |
| dependencies | unvetted-dep:@types/chai | AI (dependencies): @types/chai is a TypeScript type declaration package with no runtime execution risk. | ai | |
| phantom-deps | phantom-dep:@types/mocha | AI (phantom-deps): Type-only package loaded by framework convention, not directly imported. | ai | |
| phantom-deps | phantom-dep:@types/chai | AI (phantom-deps): Type-only package loaded by framework convention, not directly imported. | ai | |
| phantom-deps | phantom-dep:mocha | AI (phantom-deps): Referenced in config files only; normal for a test framework wrapper package. | ai | |
| phantom-deps | phantom-dep:@open-xchange/codecept-horizontal-scaler | AI (phantom-deps): Same org scope; declared dep used indirectly via config, not a phantom risk. | ai | |
| phantom-deps | phantom-dep:@open-xchange/codeceptjs-hindsight | AI (phantom-deps): Same org scope; declared dep used indirectly via config, not a phantom risk. | ai | |
| phantom-deps | phantom-dep:mocha-junit-reporter | AI (phantom-deps): Referenced in config files only; normal for a test framework wrapper package. | ai | |
| phantom-deps | phantom-dep:allure-codeceptjs | AI (phantom-deps): Referenced in config files only; normal for a test framework wrapper package. | ai | |
| phantom-deps | phantom-dep:mocha-multi | AI (phantom-deps): Referenced in config files only; normal for a test framework wrapper package. | ai |
Versions (showing 40 of 40)
| Version | Deps | Published |
|---|---|---|
| 0.14.4 | 20 / 4 | |
| 0.14.3 | 20 / 4 | |
| 0.14.2 | 20 / 4 | |
| 0.14.1 | 20 / 4 | |
| 0.14.0 | 20 / 4 | |
| 0.13.3 | 20 / 4 | |
| 0.13.2 | 20 / 4 | |
| 0.13.1 | 20 / 4 | |
| 0.13.0 | 20 / 4 | |
| 0.12.0 | 20 / 4 | |
| 0.11.0 | 18 / 4 | |
| 0.10.0 | 18 / 4 | |
| 0.9.8 | 20 / 5 | |
| 0.9.6 | 20 / 4 | |
| 0.9.4 | 20 / 4 | |
| 0.9.2 | 20 / 4 | |
| 0.9.1 | 20 / 4 | |
| 0.9.0 | 18 / 4 | |
| 0.8.1 | 18 / 4 | |
| 0.8.0 | 18 / 4 | |
| 0.7.2 | 21 / 4 | |
| 0.7.1 | 21 / 4 | |
| 0.7.0 | 21 / 4 | |
| 0.6.20 | 21 / 4 | |
| 0.6.19 | 21 / 4 | |
| 0.6.18 | 21 / 4 | |
| 0.6.17 | 21 / 4 | |
| 0.6.16 | 21 / 4 | |
| 0.6.15 | 21 / 4 | |
| 0.6.14 | 21 / 4 | |
| 0.6.13 | 21 / 4 | |
| 0.6.12 | 21 / 4 | |
| 0.6.11 | 20 / 4 | |
| 0.6.10 | 20 / 4 | |
| 0.6.9 | 20 / 4 | |
| 0.6.8 | 20 / 4 | |
| 0.6.7 | 20 / 4 | |
| 0.6.6 | 20 / 4 | |
| 0.6.4 | 20 / 4 | |
| 0.6.3 | 20 / 4 |
v0.14.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.