@teamkeel/testing-runtime
Internal package used by the generated @teamkeel/testing package
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Standard Proxy/Reflect.get handler pattern; not obfuscation. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Decoding a base64-encoded private key from env var; legitimate credential handling. | ai | |
| phantom-deps | phantom-dep:vite | AI (phantom-deps): vite is listed as a runtime dep and used via vitest config; phantom-dep is a false positive here. | ai |
Versions (showing 51 of 93)
| Version | Deps | Published |
|---|---|---|
| 0.455.2 | 6 / 1 | |
| 0.455.1 | 6 / 1 | |
| 0.455.0 | 6 / 1 | |
| 0.454.3 | 6 / 1 | |
| 0.454.2 | 6 / 1 | |
| 0.453.0 | 6 / 1 | |
| 0.452.1 | 6 / 1 | |
| 0.452.0 | 6 / 1 | |
| 0.451.2 | 6 / 1 | |
| 0.451.1 | 6 / 1 | |
| 0.451.0 | 6 / 1 | |
| 0.450.0 | 6 / 1 | |
| 0.449.3 | 6 / 1 | |
| 0.449.2 | 6 / 1 | |
| 0.449.1 | 6 / 1 | |
| 0.449.0 | 6 / 1 | |
| 0.448.1 | 6 / 1 | |
| 0.447.0 | 6 / 1 | |
| 0.446.1 | 6 / 1 | |
| 0.446.0 | 6 / 1 | |
| 0.445.0 | 6 / 1 | |
| 0.444.0 | 6 / 1 | |
| 0.443.0 | 6 / 1 | |
| 0.442.0 | 6 / 1 | |
| 0.441.0 | 6 / 1 | |
| 0.440.1 | 6 / 1 | |
| 0.439.0 | 6 / 1 | |
| 0.438.1 | 6 / 1 | |
| 0.438.0 | 6 / 1 | |
| 0.437.0 | 6 / 1 | |
| 0.436.1 | 6 / 1 | |
| 0.436.0 | 6 / 1 | |
| 0.435.0 | 6 / 1 | |
| 0.434.1 | 6 / 1 | |
| 0.434.0 | 6 / 1 | |
| 0.433.0 | 6 / 1 | |
| 0.432.0 | 6 / 1 | |
| 0.431.0 | 6 / 1 | |
| 0.430.0 | 6 / 1 | |
| 0.429.2 | 6 / 1 | |
| 0.429.1 | 6 / 1 | |
| 0.429.0 | 6 / 1 | |
| 0.428.2 | 6 / 1 | |
| 0.428.0 | 6 / 1 | |
| 0.427.1 | 6 / 1 | |
| 0.427.0 | 6 / 1 | |
| 0.426.0 | 6 / 1 | |
| 0.425.1 | 6 / 1 | |
| 0.425.0 | 6 / 1 | |
| 0.424.0 | 6 / 1 | |
| 0.423.3 | 6 / 1 |
v0.455.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.455.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.455.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.454.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.454.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.453.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.452.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.452.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.451.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.451.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.451.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.450.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.449.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.449.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.449.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.449.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.448.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.447.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.446.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.446.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.445.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.444.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.443.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.442.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.441.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.440.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.439.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.438.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.438.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.437.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.436.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.436.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.435.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.434.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.434.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.433.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.432.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.431.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.430.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.429.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.429.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.429.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.428.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.428.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.427.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.427.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.426.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.425.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.425.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.424.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.423.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.