← Home

jest-runtime

51
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

aaronabramovsimenbrickhanloniiopenjs-operationscpojer

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:fast-json-stable-stringify AI (dependencies): fast-json-stable-stringify is an established utility; unvetted status is a false positive for this well-known package. ai
phantom-deps phantom-dep:exit AI (phantom-deps): exit is a known phantom dependency pattern in Jest; stable for this package. ai
provenance publisher-changed AI (provenance): Publisher change is documented as legitimate maintainer transition within the official Jest project. ai
provenance no-provenance AI (provenance): This is a 2017 release predating Sigstore provenance; no provenance is expected and not a risk signal for this package. ai
maintainer-change maintainer-removed AI (maintainer-change): Documented maintainer transition within Jest project; stable for this package. ai
maintainer-change maintainer-added AI (maintainer-change): Legitimate Jest project maintainer expansion; stable for this package. ai
dependencies unvetted-dep:babel-core AI (dependencies): babel-core is essential for jest-runtime's transpilation function; stable dependency. ai
publish-pattern new-deps-added AI (publish-pattern): New dependencies are all established packages (slash, realpath-native, write-file-atomic); no suspicious additions. ai
phantom-deps phantom-dep:babel-jest AI (phantom-deps): babel-jest is a legitimate Jest plugin referenced in config; phantom-dep status is expected. ai
phantom-deps phantom-dep:jest-snapshot AI (phantom-deps): jest-snapshot is a core Jest module referenced in config; phantom-dep status is expected. ai
dependencies unvetted-dep:@jest/fake-timers AI (dependencies): Sibling monorepo package published simultaneously; unvetted status is transient, not a security concern for jest-runtime. ai
dependencies unvetted-dep:@jest/globals AI (dependencies): Sibling monorepo package published simultaneously; unvetted status is transient, not a security concern for jest-runtime. ai
dependencies unvetted-dep:jest-snapshot AI (dependencies): Sibling monorepo package published simultaneously; unvetted status is transient, not a security concern for jest-runtime. ai
dependencies unvetted-dep:@jest/source-map AI (dependencies): Sibling monorepo package published simultaneously; unvetted status is transient, not a security concern for jest-runtime. ai
dependencies unvetted-dep:collect-v8-coverage AI (dependencies): collect-v8-coverage is a well-known utility used by Jest for V8 coverage collection; stable dependency with no security concerns. ai
npm-metadata suspicious-initial-version AI (npm-metadata): jest-runtime is a core Jest package by trusted maintainer cpojer; 0.0.0 is a namespace reservation placeholder, not a malicious throwaway package. ai
npm-metadata no-description AI (npm-metadata): Missing description is common in Jest monorepo packages; not a malware indicator here. ai
bogus-package bogus-package AI (bogus-package): jest-runtime is a monorepo workspace package with 327 prior versions; inflated-semver and missing-description signals are false positives for established internal packages. ai
phantom-deps phantom-dep:chalk AI (phantom-deps): chalk is a declared runtime dependency; phantom-dep false positive for this package. ai
phantom-deps phantom-dep:@jest/fake-timers AI (phantom-deps): @jest/fake-timers is a declared runtime dependency; phantom-dep false positive for this package. ai
phantom-deps phantom-dep:@types/node AI (phantom-deps): @types/node is a framework-scoped type dependency; phantom-dep false positive for this package. ai
phantom-deps phantom-dep:jest-mock AI (phantom-deps): jest-mock is a declared runtime dependency used by the Jest runtime; phantom-dep false positive. ai

Versions (showing 51 of 186)

View all versions
Version Deps Published
30.4.2 22 / 3
30.4.1 22 / 3
30.4.0 22 / 3
30.3.0 22 / 3
30.2.0 22 / 3
30.1.3 22 / 3
30.1.2 22 / 3
30.1.1 22 / 3
30.1.0 22 / 3
30.0.5 22 / 3
30.0.4 22 / 3
30.0.3 22 / 3
30.0.2 22 / 3
30.0.1 22 / 3
30.0.0 22 / 3
29.7.0 22 / 4
29.6.4 22 / 4
29.6.3 22 / 4
29.6.2 22 / 4
29.6.1 22 / 4
29.6.0 22 / 4
29.5.0 22 / 4
29.4.3 22 / 4
29.4.2 23 / 5
29.4.1 23 / 5
29.4.0 23 / 5
29.3.1 22 / 4
29.3.0 22 / 4
29.2.2 22 / 4
29.2.1 22 / 4
29.2.0 22 / 4
29.1.2 22 / 4
29.1.1 22 / 4
29.1.0 22 / 4
29.0.3 22 / 4
29.0.2 22 / 4
29.0.1 22 / 4
29.0.0 22 / 4
28.1.3 22 / 5
28.1.2 22 / 5
28.1.1 22 / 5
28.1.0 22 / 5
28.0.3 22 / 5
28.0.2 22 / 5
28.0.1 22 / 5
28.0.0 22 / 5
27.5.1 22 / 5
27.5.0 22 / 6
27.4.6 22 / 6
27.4.5 26 / 8
27.4.4 26 / 8

v30.4.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v30.4.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v30.4.0

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: cpojer → simenb (on 2026-05-07) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2026-05-07. This could indicate a legitimate maintainer transition or an account compromise.

v30.3.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v30.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v30.1.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v30.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v30.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v30.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v30.0.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v30.0.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v30.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v30.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v30.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v30.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v29.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.6.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.6.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.6.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.6.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.4.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.4.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.4.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.3.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.2.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.2.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v28.1.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v28.1.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v28.1.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v28.1.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v28.0.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v28.0.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v28.0.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v28.0.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v27.5.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v27.5.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v27.4.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v27.4.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v27.4.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.