← Home

jest-config

51
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

aaronabramovsimenbrickhanloniiopenjs-operationscpojer

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-peer-dep:ts-node AI (dependencies): ts-node is an optional peer dependency; unvetted status is acceptable for optional tooling. ai
source-diff large-new-source-files AI (source-diff): 26 new files consistent with Jest monorepo development; no obfuscation or malware indicators. ai
maintainer-change maintainer-removed AI (maintainer-change): cpojer removal is normal Jest team evolution; package remains under official Facebook/Jest org with active maintainer. ai
maintainer-change maintainer-added AI (maintainer-change): Jest monorepo maintainer transition; rubennorte and scotthovestadt are documented Jest maintainers. ai
phantom-deps phantom-dep:babel-core AI (phantom-deps): babel-core is referenced as a default transformer string in config, not directly imported — this is the expected usage pattern for jest-config. ai
provenance no-provenance AI (provenance): Provenance is a best-practice gap; not a blocker for packages with strong ecosystem trust. ai
dependencies unvetted-dep:babel-core AI (dependencies): babel-core is a well-known Babel v6 package legitimately added in Jest 23 as a required peer for the default babel-jest transformer. Not a supply chain risk. ai
provenance publisher-changed AI (provenance): Publisher change (mjesun → scotthovestadt) occurred in 2019 as documented Jest maintainer transition. ai
publish-pattern new-deps-added AI (publish-pattern): New deps are Jest-scoped or established packages (micromatch, @babel/core, realpath-native); appropriate for config module. ai
source-diff obfuscated-file:build/normalize.js AI (source-diff): build/normalize.js is a standard Babel-compiled build artifact from the facebook/jest monorepo, not malicious obfuscation. Pattern is consistent across all Jest package builds. ai
phantom-deps phantom-dep:jest-mock AI (phantom-deps): jest-mock is referenced as a default config value resolved at runtime. Phantom-dep pattern is expected and stable for jest-config. ai
phantom-deps phantom-dep:json-stable-stringify AI (phantom-deps): json-stable-stringify is a runtime-resolved dependency used via configuration, not direct import. Expected pattern for jest-config. ai
phantom-deps phantom-dep:jest-environment-jsdom AI (phantom-deps): Referenced in config files; expected phantom dep for Jest config module. ai
dependencies unvetted-dep:jest-jasmine2 AI (dependencies): jest-jasmine2 is a sibling package in the same Jest monorepo; internal dependency is safe. ai
phantom-deps phantom-dep:istanbul AI (phantom-deps): jest-config passes istanbul as a default coverage provider via configuration strings resolved at runtime, not via direct import. This phantom-dep pattern is stable for this package. ai
dependencies unvetted-dep:@jest/test-sequencer AI (dependencies): @jest/test-sequencer is a first-party Jest monorepo sibling, co-released at the same version. Not a third-party risk. ai
dependencies unvetted-dep:jest-circus AI (dependencies): jest-circus is a first-party Jest monorepo sibling, co-released at the same version. Not a third-party risk. ai
npm-metadata suspicious-initial-version AI (npm-metadata): jest-config 0.0.0 is a namespace reservation by the core Jest maintainer (cpojer). The 0.0.0 version is intentional and not indicative of malicious intent for this package. ai
npm-metadata no-description AI (npm-metadata): jest-config is a monorepo package; missing description is common in Jest's published structure. ai
phantom-deps phantom-dep:@jest/test-sequencer AI (phantom-deps): Jest-scoped package loaded by convention; expected in config module. ai
phantom-deps phantom-dep:jest-environment-node AI (phantom-deps): Referenced in config files; expected phantom dep for Jest config module. ai
bogus-package bogus-package AI (bogus-package): jest-config is a Jest monorepo package following unified versioning (30.x). Inflated semver, no description, and no keywords are expected for this monorepo package — not spam indicators. ai
phantom-deps phantom-dep:@babel/core AI (phantom-deps): Framework-scoped package loaded by convention in Jest's build pipeline. ai
phantom-deps phantom-dep:jest-runner AI (phantom-deps): jest-config references jest-runner as the default test runner via config; loaded by convention, not direct import. ai

Versions (showing 51 of 187)

View all versions
Version Deps Published
30.4.2 23 / 8
30.4.1 23 / 8
30.4.0 23 / 8
30.3.0 23 / 8
30.2.0 24 / 9
30.1.3 24 / 8
30.1.2 24 / 8
30.1.1 24 / 8
30.1.0 24 / 8
30.0.5 24 / 8
30.0.4 24 / 8
30.0.3 24 / 8
30.0.2 24 / 8
30.0.1 24 / 8
30.0.0 24 / 8
29.7.0 22 / 7
29.6.4 22 / 7
29.6.3 22 / 7
29.6.2 22 / 7
29.6.1 22 / 7
29.6.0 22 / 7
29.5.0 22 / 7
29.4.3 22 / 7
29.4.2 22 / 7
29.4.1 22 / 7
29.4.0 22 / 7
29.3.1 22 / 6
29.3.0 22 / 6
29.2.2 22 / 6
29.2.1 22 / 6
29.2.0 22 / 6
29.1.2 22 / 6
29.1.1 22 / 6
29.1.0 22 / 6
29.0.3 22 / 6
29.0.2 22 / 6
29.0.1 22 / 6
29.0.0 22 / 6
28.1.3 22 / 6
28.1.2 22 / 6
28.1.1 22 / 6
28.1.0 22 / 6
28.0.3 22 / 6
28.0.2 22 / 6
28.0.1 22 / 6
28.0.0 22 / 6
27.5.1 24 / 6
27.5.0 22 / 8
27.4.7 22 / 8
27.4.6 21 / 8
27.4.5 22 / 9

v30.4.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v30.4.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v30.4.0

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: cpojer → simenb (on 2026-05-07) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2026-05-07. This could indicate a legitimate maintainer transition or an account compromise.

v30.3.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v30.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v30.1.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v30.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v30.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v30.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v30.0.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v30.0.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v30.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v30.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v30.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v30.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v29.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.6.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.6.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.6.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.6.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.4.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.4.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.4.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.3.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.2.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.2.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v29.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v29.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v28.1.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v28.1.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v28.1.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v28.1.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v28.0.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v28.0.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v28.0.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v28.0.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v27.5.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v27.5.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v27.4.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v27.4.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v27.4.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.