← Home

vest

Declarative Form Validations Framework

13
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

ealush

Keywords

Form validationUnit testingFramework-agnosticValidationDeclarativeAsynchronous validationsAsync validationsTestingData validationForm validationReact ValidationAngular ValidationVue ValidationSvelte Validationnodejs Validationenforce

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
typosquat typosquat.levenshtein:jest AI (typosquat): vest is a legitimate, well-established form validation library (4139 days, 424 versions, 55k weekly downloads), not a typosquat of jest. The name similarity is purely coincidental. ai
typosquat typosquat.levenshtein:next AI (typosquat): vest is a legitimate package unrelated to next.js. Levenshtein match is coincidental. ai
typosquat typosquat.levenshtein:vitest AI (typosquat): vest predates vitest and is an unrelated form validation library. Levenshtein match is coincidental. ai
dependencies unvetted-dep:n4s AI (dependencies): n4s is part of the vest monorepo ecosystem, a first-party dependency published alongside vest. ai
dependencies unvetted-dep:context AI (dependencies): context is part of the vest monorepo ecosystem, a first-party dependency published alongside vest. ai
dependencies unvetted-dep:vestjs-runtime AI (dependencies): vestjs-runtime is part of the vest monorepo ecosystem, a first-party dependency published alongside vest. ai

Versions (showing 13 of 13)

Version Deps Published
6.3.2 4 / 1
6.3.0 4 / 1
6.2.8 5 / 1
6.2.7 5 / 1
6.2.5 5 / 1
6.2.4 5 / 1
6.2.2 5 / 1
6.2.0 5 / 1
6.1.0 5 / 1
6.0.3 5 / 1
6.0.2 5 / 1
6.0.1 5 / 1
6.0.0 5 / 1

v6.3.2

2 findings
HIGH typosquat.levenshtein: Possible typosquat of 'jest' typosquat

Package name 'vest' is 1 edit(s) away from popular package 'jest'.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.2.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.2.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.2.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.2.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.2.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.0.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.0.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.