pretty-format
Stringify any JavaScript value.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:build-es5/index.js | AI (source-diff): build-es5/index.js is the documented browser entry point — a UMD bundle with core-js polyfills. The 'network+exec' pattern is the standard global-detection idiom (Function('return this')()) in polyfill code, not malware. | ai | |
| provenance | missing-githead | AI (provenance): pretty-format is a long-established Jest package; missing gitHead reflects a publish environment change, not a security concern. Stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@jest/types | AI (phantom-deps): Framework-scoped Jest package loaded by convention; phantom status is expected and benign. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Legitimate growth from v22 to v24; consistent with feature additions and build artifacts. | ai | |
| dependencies | unvetted-dep:@jest/types | AI (dependencies): @jest/types is a core Jest package; unvetted status is expected for internal monorepo dependencies. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Expected growth for a two-version bump with feature additions; no evidence of injected code. | ai | |
| maintainer-change | maintainer-takeover | AI (maintainer-change): The maintainer transition reflects the well-documented handoff of the Jest project to the Facebook/Meta team. The new maintainers (simenb, aaronabramov, fb, etc.) are the official Jest maintainers at Facebook. This is not a hijack. | ai | |
| provenance | no-provenance | AI (provenance): Provenance absence is expected for packages predating Sigstore adoption; not a security risk. | ai | |
| provenance | publisher-changed | AI (provenance): Publisher change reflects documented Jest maintainer transition in 2020; stable for this package. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Maintainer additions are part of documented Jest project transition; stable for this package. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Maintainer removal is part of documented Jest project transition; stable for this package. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New dependencies are all established packages appropriate for a formatting utility. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): new Function() is in a performance test with explicit eslint-disable; legitimate test case, not code execution risk. | ai | |
| dependencies | unvetted-dep:@jest/schemas | AI (dependencies): @jest/schemas is a first-party Jest monorepo package versioned in lockstep with pretty-format; not a suspicious third-party dependency. | ai |
Versions (showing 51 of 131)
| Version | Deps | Published |
|---|---|---|
| 30.3.0 | 3 / 8 | |
| 30.2.0 | 3 / 8 | |
| 30.0.5 | 3 / 8 | |
| 30.0.2 | 3 / 8 | |
| 30.0.1 | 3 / 8 | |
| 30.0.0 | 3 / 8 | |
| 29.7.0 | 3 / 8 | |
| 29.6.3 | 3 / 8 | |
| 29.6.2 | 3 / 8 | |
| 29.6.1 | 3 / 8 | |
| 29.6.0 | 3 / 8 | |
| 29.5.0 | 3 / 8 | |
| 29.4.3 | 3 / 8 | |
| 29.4.2 | 3 / 8 | |
| 29.4.1 | 3 / 8 | |
| 29.4.0 | 3 / 8 | |
| 29.3.1 | 3 / 8 | |
| 29.2.1 | 3 / 8 | |
| 29.2.0 | 3 / 8 | |
| 29.1.2 | 3 / 8 | |
| 29.1.0 | 3 / 8 | |
| 29.0.3 | 3 / 9 | |
| 29.0.2 | 3 / 9 | |
| 29.0.1 | 3 / 9 | |
| 29.0.0 | 3 / 9 | |
| 28.1.3 | 4 / 9 | |
| 28.1.1 | 4 / 9 | |
| 28.1.0 | 4 / 9 | |
| 28.0.2 | 4 / 9 | |
| 28.0.1 | 4 / 9 | |
| 28.0.0 | 4 / 9 | |
| 27.5.1 | 3 / 8 | |
| 27.5.0 | 3 / 8 | |
| 27.4.6 | 3 / 8 | |
| 27.4.2 | 4 / 8 | |
| 27.4.1 | 4 / 8 | |
| 27.4.0 | 4 / 8 | |
| 27.3.1 | 4 / 8 | |
| 27.3.0 | 4 / 8 | |
| 27.2.5 | 4 / 8 | |
| 27.2.4 | 4 / 8 | |
| 27.2.3 | 4 / 8 | |
| 27.2.2 | 4 / 8 | |
| 27.2.0 | 4 / 8 | |
| 27.1.1 | 4 / 8 | |
| 27.1.0 | 4 / 8 | |
| 27.0.6 | 4 / 8 | |
| 27.0.2 | 4 / 8 | |
| 27.0.1 | 4 / 8 | |
| 27.0.0 | 4 / 8 | |
| 26.6.2 | 4 / 8 |
v30.3.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v30.2.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v30.0.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v30.0.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v30.0.1
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2025-06-18. This could indicate a legitimate maintainer transition or an account compromise.
v30.0.0
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2025-06-10. This could indicate a legitimate maintainer transition or an account compromise.
v29.7.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v29.6.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v29.6.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v29.6.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v29.6.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v29.5.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v29.4.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v29.4.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v29.4.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v29.4.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v29.3.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v29.2.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v29.2.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v29.1.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v29.1.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v29.0.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v29.0.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v29.0.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v29.0.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v28.1.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v28.1.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v28.1.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v28.0.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v28.0.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v28.0.0
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2022-04-25. This could indicate a legitimate maintainer transition or an account compromise.
v27.5.1
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2022-02-08. This could indicate a legitimate maintainer transition or an account compromise.
v27.5.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v27.4.6
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2022-01-04. This could indicate a legitimate maintainer transition or an account compromise.
v27.4.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v27.4.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v27.4.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v27.3.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v27.3.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v27.2.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v27.2.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v27.2.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v27.2.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v27.2.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v27.1.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v27.1.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v27.0.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v27.0.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v27.0.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v27.0.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v26.6.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.