← Home

pa11y

4
Versions
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures gitHead linked

Maintainers

rowanmanninghollskglynnphillipsjoseluisbolosdotcodejoey.ciechanowiczdanyalaytekinaarongoldenthaljpwpa11y-botandrewmee

Keywords

a11yaccessibilityanalysisariaauditautomationaxeaxe-corecheckerclicomplianceheadlesshtmlcsopen-sourcepa11ypuppeteerreportstandardstestingvalidatorWCAG

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:dynamic-require AI (semgrep): Variable is validated against a hardcoded allowlist of reporter names before require(); no arbitrary module loading possible. ai
dependencies unvetted-dep:@pa11y/html_codesniffer AI (dependencies): First-party pa11y org package; stable dependency across many pa11y versions. ai

Versions (showing 4 of 4)

Version Deps Published
9.1.1 10 / 7
9.1.0 10 / 7
9.0.1 10 / 8
9.0.0 10 / 8

v9.0.1

2 findings
HIGH Publisher changed: pa11y-bot → GitHub Actions (on 2025-09-25) provenance

This version was published by a different npm account than previous versions on 2025-09-25. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.