@trackunit/iris-app-e2e
A comprehensive E2E testing utilities library for Trackunit's Iris platform. This package provides reusable Cypress commands, setup utilities, and configuration helpers to streamline E2E testing for both internal and external developers.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@nx/cypress | AI (phantom-deps): Nx tooling commonly referenced in config; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@trackunit/react-test-setup | AI (phantom-deps): Same-org test utility; expected in monorepo structure. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Established package with 322 versions and clean diff; dormancy gap alone is insufficient signal for this org-scoped package. | ai | |
| dependencies | unvetted-dep:@neuralegion/cypress-har-generator | AI (dependencies): Known Cypress HAR generator plugin; legitimate e2e tooling dependency. | ai | |
| dependencies | unvetted-dep:@nx/vite | AI (dependencies): Well-known Nx build tooling; stable false positive for this e2e test package. | ai | |
| dependencies | unvetted-dep:node-xlsx | AI (dependencies): Established xlsx parsing library; no known malicious history. | ai | |
| dependencies | unvetted-dep:@nx/cypress | AI (dependencies): Official Nx Cypress integration; expected dependency for this e2e package. | ai | |
| dependencies | unvetted-dep:cypress-terminal-report | AI (dependencies): Popular Cypress plugin; legitimate e2e tooling dependency. | ai |
Versions (showing 17 of 17)
| Version | Deps | Published |
|---|---|---|
| 1.11.6 | 8 / 0 | |
| 1.11.4 | 8 / 0 | |
| 1.11.3 | 8 / 0 | |
| 1.11.2 | 8 / 0 | |
| 1.11.1 | 8 / 0 | |
| 1.10.6 | 8 / 0 | |
| 1.10.4 | 8 / 0 | |
| 1.10.2 | 8 / 0 | |
| 1.9.31 | 8 / 0 | |
| 1.9.30 | 8 / 0 | |
| 1.9.29 | 8 / 0 | |
| 1.9.28 | 8 / 0 | |
| 1.8.87 | 7 / 0 | |
| 1.8.17 | 6 / 0 | |
| 1.4.85 | 6 / 0 | |
| 1.4.45 | 7 / 0 | |
| 1.1.7 | 7 / 0 |
v1.11.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.11.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.11.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.11.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.11.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.31
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.30
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.29
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.8.87
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.8.17
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.85
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.45
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.