@stencil/vitest
First-class testing utilities for Stencil design systems with Vitest
58
Versions
MIT
License
No
Install Scripts
Attested
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation (unverified)
npm registry signatures
No source commit
Maintainers
ionicjsgm-osvmfognbmjohnny.jenkinsstencil-bot
Keywords
stencilstenciljstestingvitestcustom elementsweb componentscomponent testing
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): Package has SLSA provenance attestation via Sigstore, which provides stronger supply chain integrity than gitHead. The missing gitHead is a minor metadata gap, not a security concern for this package. | ai | |
| typosquat | typosquat.levenshtein:vite | AI (typosquat): @stencil/vitest is a legitimate StencilJS org package integrating Vitest for testing; the name 'vitest' is intentional and descriptive, not an impersonation of 'vite'. | ai | |
| dependencies | unvetted-dep:jiti | AI (dependencies): jiti is a widely-used ESM/TS runtime loader (used by Vite, Nuxt, etc.); its use in a Vitest integration package for config loading is expected and benign. | ai | |
| phantom-deps | phantom-dep:vitest-environment-stencil | AI (phantom-deps): vitest-environment-stencil is a companion package bundled for user vitest config reference, not directly imported in source. Coordinated release pattern (same version pin) is legitimate. | ai |
Versions (showing 58 of 58)
| Version | Deps | Published |
|---|---|---|
| 1.14.0 | 3 / 17 | |
| 1.13.3 | 3 / 17 | |
| 1.13.2 | 3 / 17 | |
| 1.13.1 | 3 / 17 | |
| 1.13.0 | 3 / 17 | |
| 1.12.1 | 3 / 17 | |
| 1.12.0 | 3 / 17 | |
| 1.11.6 | 3 / 17 | |
| 1.11.5 | 3 / 17 | |
| 1.11.4 | 3 / 17 | |
| 1.11.3 | 3 / 17 | |
| 1.11.2 | 3 / 17 | |
| 1.11.1 | 3 / 17 | |
| 1.11.0 | 3 / 17 | |
| 1.10.0 | 3 / 17 | |
| 1.9.3 | 3 / 17 | |
| 1.9.2 | 3 / 17 | |
| 1.9.1 | 3 / 17 | |
| 1.9.0 | 3 / 17 | |
| 1.8.3 | 3 / 17 | |
| 1.8.2 | 3 / 17 | |
| 1.8.1 | 3 / 17 | |
| 1.8.0 | 3 / 17 | |
| 1.7.2 | 3 / 17 | |
| 1.7.1 | 3 / 17 | |
| 1.7.0 | 3 / 17 | |
| 1.6.2 | 3 / 17 | |
| 1.6.1 | 3 / 17 | |
| 1.6.0 | 3 / 17 | |
| 1.5.0 | 3 / 17 | |
| 1.4.0 | 3 / 17 | |
| 1.3.0 | 3 / 17 | |
| 1.2.0 | 3 / 17 | |
| 1.1.21 | 3 / 17 | |
| 1.1.20 | 3 / 17 | |
| 1.1.19 | 3 / 17 | |
| 1.1.18 | 3 / 17 | |
| 1.1.17 | 3 / 17 | |
| 1.1.16 | 3 / 17 | |
| 1.1.15 | 3 / 17 | |
| 1.1.14 | 3 / 17 | |
| 1.1.13 | 3 / 17 | |
| 1.1.12 | 3 / 17 | |
| 1.1.11 | 3 / 17 | |
| 1.1.10 | 3 / 17 | |
| 1.1.9 | 3 / 17 | |
| 1.1.8 | 3 / 17 | |
| 1.1.7 | 3 / 17 | |
| 1.1.6 | 3 / 17 | |
| 1.1.5 | 3 / 17 | |
| 1.1.4 | 3 / 17 | |
| 1.1.3 | 3 / 17 | |
| 1.1.2 | 3 / 17 | |
| 1.1.1 | 3 / 17 | |
| 1.1.0 | 3 / 17 | |
| 0.0.4 | 3 / 17 | |
| 0.0.3 | 3 / 17 | |
| 0.0.1 | 3 / 16 |
v1.14.0
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.