jest-file-exists
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| bogus-package | bogus-package | AI (bogus-package): jest-file-exists is a legitimate tiny utility in the official Jest monorepo (facebook/jest). Tiny payload, no deps, and no description are expected for monorepo sub-packages. Spam publisher flags are false positives for Meta/Facebook OSS contributors. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Absence of description is consistent with this being an internal Jest monorepo sub-package; not indicative of malicious intent. | ai |
Versions (showing 5 of 5)
| Version | Deps | Published |
|---|---|---|
| 19.0.0 | 0 / 0 | |
| 17.0.0 | 0 / 0 | |
| 15.0.0 | 0 / 0 | |
| 14.0.0 | 0 / 0 | |
| 0.0.0 | 0 / 0 |
v19.0.0
2 findingsMatched 5 signal(s), weighted score 7: • [S_KNOWN_SPAM_PUBLISHER] Maintainer(s) previously flagged as spam: fb, dmitriiabramov, gaearon, cpojer. • [S_DESC_MATCHES_NAME] Description is empty or just restates the package name. • [S_NO_KEYWORDS] No keywords declared. • [S_NO_DEPS] No runtime, dev, peer, or optional dependencies declared. • [S_TINY_PAYLOAD] Tiny payload: 1 code file(s), 696 bytes total.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.