← Home

@web/test-runner

45
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

d4kmorpasslejorenbroekemabennyplarsdenbakkerwestbrookmodern-web

Keywords

webtestrunnertestrunnerdefaultimplementationcli

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@web/test-runner-helpers AI (phantom-deps): Same-org sibling, re-exported not directly imported. ai
dependencies unvetted-dep:@web/test-runner-helpers AI (dependencies): First-party monorepo sibling package. ai
phantom-deps phantom-dep:command-line-args AI (phantom-deps): Used in config, not a real risk. ai
phantom-deps phantom-dep:@web/dev-server-legacy AI (phantom-deps): Same-org sibling, re-exported not directly imported. ai
phantom-deps phantom-dep:@web/test-runner-mocha AI (phantom-deps): Same-org sibling, re-exported not directly imported. ai
dependencies unvetted-dep:@web/test-runner-cli AI (dependencies): First-party monorepo sibling package. ai
dependencies unvetted-dep:@web/dev-server-legacy AI (dependencies): First-party monorepo sibling package. ai
dependencies unvetted-dep:@web/test-runner-server AI (dependencies): First-party monorepo sibling package. ai
phantom-deps phantom-dep:source-map AI (phantom-deps): source-map is a declared runtime dep used transitively in source-map processing; stable false positive for this package. ai
phantom-deps phantom-dep:convert-source-map AI (phantom-deps): convert-source-map is a declared runtime dep; phantom-dep heuristic fires but it is legitimately used. ai
phantom-deps phantom-dep:@web/browser-logs AI (phantom-deps): First-party @web/* dep from same org; used indirectly via @web/test-runner-core. ai
semgrep semgrep:dynamic-require AI (semgrep): Used in loadLauncher.ts to resolve optional browser launcher packages by name — documented plugin-loading pattern for this test runner. ai

Versions (showing 45 of 45)

Version Deps Published
1.0.0 16 / 5
0.20.2 16 / 5
0.20.1 16 / 5
0.20.0 16 / 5
0.19.0 16 / 5
0.18.3 16 / 5
0.18.2 16 / 5
0.10.2 10 / 3
0.10.1 11 / 3
0.10.0 11 / 3
0.9.13 11 / 3
0.7.32 11 / 2
0.7.31 9 / 2
0.7.30 9 / 2
0.7.29 9 / 2
0.7.28 9 / 2
0.7.27 9 / 2
0.7.26 9 / 2
0.7.25 9 / 2
0.7.24 9 / 2
0.7.23 9 / 2
0.7.22 9 / 2
0.7.21 9 / 2
0.7.20 9 / 2
0.7.19 9 / 2
0.7.17 9 / 2
0.7.16 9 / 2
0.7.15 9 / 2
0.7.14 9 / 2
0.7.13 9 / 2
0.7.12 9 / 2
0.7.11 9 / 2
0.7.10 9 / 2
0.7.9 9 / 2
0.7.8 9 / 2
0.7.7 9 / 2
0.7.6 9 / 2
0.7.5 9 / 2
0.7.4 9 / 2
0.7.3 9 / 2
0.7.2 9 / 3
0.7.1 9 / 3
0.7.0 9 / 3
0.6.54 9 / 2
0.6.29 11 / 0

v1.0.0

2 findings
HIGH Publisher changed: modern-web → GitHub Actions (on 2026-07-07) provenance

This version was published by a different npm account than previous versions on 2026-07-07. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.10.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.32

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.31

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.30

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.29

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.28

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.27

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.26

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.25

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.24

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.23

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.22

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.21

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.20

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.19

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.16

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.6

2 findings
MEDIUM Publisher changed: larsdenbakker → modern-web (on 2020-08-22, unremoved on npm for 2157d) provenance

This version was published by a different npm account (modern-web) than the most recent previously approved version (larsdenbakker) on 2020-08-22. It has since remained available on npm for 2157 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.7.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.6.54

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.6.29

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.