← Home

@playwright/experimental-ct-vue

Playwright Component Testing for Vue

51
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

pavelfeldmanyurysdgozman-msplaywright-bot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Playwright migrated publishing to GitHub Actions with SLSA attestation; this is the expected CI/CD pattern for microsoft/playwright. ai
maintainer-change maintainer-removed AI (maintainer-change): Maintainer consolidation under GitHub Actions CI is consistent with Microsoft's supply chain hardening; not a takeover signal. ai
publish-pattern dormant-publish AI (publish-pattern): Dormancy reflects the package's experimental/niche status; 2416 registry versions confirm active Playwright ecosystem publishing. ai
semgrep semgrep:new-function-constructor AI (semgrep): new Function() is used to execute Vue compiler output for runtime template compilation — a standard, documented Vue pattern. Not a security risk in this context. ai
bogus-package bogus-package AI (bogus-package): Monorepo sub-package from Microsoft's Playwright project; sparse README and missing keywords are expected for sub-packages, not spam indicators. ai
dependencies unvetted-dep:@vitejs/plugin-vue AI (dependencies): @vitejs/plugin-vue is the official Vue core team Vite plugin, a natural and expected dependency for a Vue component testing package. ai

Versions (showing 51 of 96)

View all versions
Version Deps Published
1.62.0 2 / 0
1.61.1 2 / 0
1.61.0 2 / 0
1.60.0 2 / 0
1.59.1 2 / 0
1.59.0 2 / 0
1.58.2 2 / 0
1.58.1 2 / 0
1.58.0 2 / 0
1.57.0 2 / 0
1.56.1 2 / 0
1.56.0 2 / 0
1.55.1 2 / 0
1.55.0 2 / 0
1.54.2 2 / 0
1.54.1 2 / 0
1.54.0 2 / 0
1.53.2 2 / 0
1.53.1 2 / 0
1.53.0 2 / 0
1.52.0 2 / 0
1.51.1 2 / 0
1.51.0 2 / 0
1.50.1 2 / 0
1.50.0 2 / 0
1.49.1 2 / 0
1.49.0 2 / 0
1.48.2 2 / 0
1.48.1 2 / 0
1.48.0 2 / 0
1.47.2 2 / 0
1.47.1 2 / 0
1.47.0 2 / 0
1.46.1 2 / 0
1.46.0 2 / 0
1.45.3 2 / 0
1.45.2 2 / 0
1.45.1 2 / 0
1.45.0 2 / 0
1.44.1 2 / 0
1.44.0 2 / 0
1.43.1 2 / 0
1.43.0 2 / 0
1.42.1 2 / 0
1.42.0 2 / 0
1.41.2 2 / 0
1.41.1 2 / 0
1.41.0 2 / 0
1.40.1 2 / 0
1.40.0 2 / 0
1.39.0 2 / 0

v1.62.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.52.0

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: dgozman-ms → playwright-bot (on 2025-04-17) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2025-04-17. This could indicate a legitimate maintainer transition or an account compromise.

v1.51.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.51.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.50.1

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: yurys → dgozman-ms (on 2025-01-31, known maintainer) provenance

This version was published by a different npm account (dgozman-ms) than the most recent previously approved version (yurys) on 2025-01-31, but dgozman-ms is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.50.0

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: yurys → dgozman-ms (on 2025-01-23, known maintainer) provenance

This version was published by a different npm account (dgozman-ms) than the most recent previously approved version (yurys) on 2025-01-23, but dgozman-ms is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.49.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.49.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.48.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.48.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.48.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.47.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.47.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.47.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.46.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.46.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.45.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.45.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.45.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.45.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.44.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.44.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.43.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.43.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.42.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.42.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.41.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.41.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.41.0

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: dgozman-ms → yurys (on 2024-01-16, now via trusted publisher with provenance) provenance

This version was published by a different npm account (yurys) than the most recent previously approved version (dgozman-ms) on 2024-01-16, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.40.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.40.0

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: aslushnikov → dgozman-ms (on 2023-11-16, now via trusted publisher with provenance) provenance

This version was published by a different npm account (dgozman-ms) than the most recent previously approved version (aslushnikov) on 2023-11-16, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.39.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.