← Home

jest-snapshot

51
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

aaronabramovsimenbrickhanloniiopenjs-operationscpojer

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
npm-metadata suspicious-initial-version AI (npm-metadata): jest-snapshot 0.0.0 is a namespace reservation by the official Jest maintainer (cpojer); the 0.0.0 version is a known placeholder pattern for this established package. ai
npm-metadata no-description AI (npm-metadata): Placeholder/stub release by trusted publisher; missing description is expected for a namespace reservation, not a malicious signal. ai
provenance publisher-changed AI (provenance): simenb (Simen Bekkhus) is a well-known Jest core maintainer; the cpojer→simenb transition is a documented, legitimate handoff within the Jest team, not a compromise. ai
publish-pattern new-deps-added AI (publish-pattern): Diff is against v19.0.2; 18 new deps reflect 10 major versions of legitimate Jest development. All added packages are standard, well-known ecosystem packages. ai
phantom-deps phantom-dep:@types/babel__traverse AI (phantom-deps): @types/babel__traverse is a TypeScript type package; phantom-dep finding is a stable false positive for this package. ai
phantom-deps phantom-dep:@types/prettier AI (phantom-deps): @types/prettier is a TypeScript type package used for type inference; not directly imported at runtime by convention. Stable false positive for this package. ai
maintainer-change maintainer-removed AI (maintainer-change): Removed maintainers are former Facebook employees; removal is consistent with the well-documented Jest governance transfer from Meta to the OpenJS Foundation. ai
maintainer-change maintainer-added AI (maintainer-change): New maintainers reflect the documented Jest transition to the OpenJS Foundation; aaronabramov, simenb, rickhanlonii are known Jest contributors and openjs-operations is the OpenJS Foundation npm account. ai
source-diff source-size-tripled AI (source-diff): Size increase from v19 to v30 reflects a major version with significant new Babel integration and snapshot utility features; not indicative of injected payload. ai
bogus-package bogus-package AI (bogus-package): jest-snapshot is an official Jest monorepo package; inflated semver, no description, and no keywords are expected characteristics of this package, not spam indicators. ai
phantom-deps phantom-dep:@babel/types AI (phantom-deps): @babel/types is a legitimate declared dependency used for Babel AST type definitions; phantom detection is a false positive for this Babel-integrated package. ai

Versions (showing 51 of 159)

View all versions
Version Deps Published
30.4.1 21 / 11
30.4.0 21 / 11
30.3.0 21 / 11
30.2.0 21 / 11
30.1.2 21 / 11
30.1.1 21 / 11
30.1.0 21 / 11
30.0.5 21 / 11
30.0.4 21 / 11
30.0.3 21 / 11
30.0.2 21 / 11
30.0.1 21 / 11
30.0.0 21 / 11
29.7.0 20 / 13
29.6.4 20 / 13
29.6.3 20 / 13
29.6.2 20 / 13
29.6.1 21 / 12
29.6.0 21 / 12
29.5.0 23 / 12
29.4.3 24 / 12
29.4.2 24 / 12
29.4.1 24 / 12
29.4.0 24 / 12
29.3.1 24 / 11
29.3.0 24 / 11
29.2.2 24 / 11
29.2.1 24 / 11
29.2.0 24 / 11
29.1.2 24 / 11
29.1.0 24 / 11
29.0.3 24 / 11
29.0.2 24 / 11
29.0.1 24 / 11
29.0.0 24 / 11
28.1.3 23 / 11
28.1.2 23 / 11
28.1.1 23 / 11
28.1.0 23 / 11
28.0.3 23 / 9
28.0.2 23 / 9
28.0.1 23 / 9
28.0.0 23 / 9
27.5.1 22 / 9
27.5.0 22 / 9
27.4.6 22 / 9
27.4.5 24 / 9
27.4.4 24 / 9
27.4.2 24 / 9
27.4.1 24 / 9
27.4.0 24 / 9

v30.4.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v30.4.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: cpojer → simenb (on 2026-05-07) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2026-05-07. This could indicate a legitimate maintainer transition or an account compromise.

v30.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v30.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v30.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v30.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v30.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v30.0.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v30.0.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v30.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v30.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v30.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v30.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.7.0

2 findings
HIGH Publisher changed: cpojer → simenb (on 2023-09-12) provenance

This version was published by a different npm account than previous versions on 2023-09-12. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.6.4

2 findings
HIGH Publisher changed: cpojer → simenb (on 2023-08-24) provenance

This version was published by a different npm account than previous versions on 2023-08-24. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.6.3

2 findings
HIGH Publisher changed: cpojer → simenb (on 2023-08-21) provenance

This version was published by a different npm account than previous versions on 2023-08-21. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.6.2

2 findings
HIGH Publisher changed: cpojer → simenb (on 2023-07-27) provenance

This version was published by a different npm account than previous versions on 2023-07-27. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.6.1

2 findings
HIGH Publisher changed: cpojer → simenb (on 2023-07-06) provenance

This version was published by a different npm account than previous versions on 2023-07-06. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.6.0

2 findings
HIGH Publisher changed: cpojer → simenb (on 2023-07-04) provenance

This version was published by a different npm account than previous versions on 2023-07-04. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.5.0

2 findings
HIGH Publisher changed: cpojer → simenb (on 2023-03-06) provenance

This version was published by a different npm account than previous versions on 2023-03-06. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.4.3

2 findings
HIGH Publisher changed: cpojer → simenb (on 2023-02-15) provenance

This version was published by a different npm account than previous versions on 2023-02-15. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.4.2

2 findings
HIGH Publisher changed: cpojer → simenb (on 2023-02-07) provenance

This version was published by a different npm account than previous versions on 2023-02-07. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.4.1

2 findings
HIGH Publisher changed: cpojer → simenb (on 2023-01-26) provenance

This version was published by a different npm account than previous versions on 2023-01-26. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.4.0

2 findings
HIGH Publisher changed: cpojer → simenb (on 2023-01-24) provenance

This version was published by a different npm account than previous versions on 2023-01-24. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.3.1

2 findings
HIGH Publisher changed: cpojer → simenb (on 2022-11-08) provenance

This version was published by a different npm account than previous versions on 2022-11-08. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.3.0

2 findings
HIGH Publisher changed: cpojer → simenb (on 2022-11-07) provenance

This version was published by a different npm account than previous versions on 2022-11-07. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.2.2

2 findings
HIGH Publisher changed: cpojer → simenb (on 2022-10-24) provenance

This version was published by a different npm account than previous versions on 2022-10-24. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.2.1

2 findings
HIGH Publisher changed: cpojer → simenb (on 2022-10-18) provenance

This version was published by a different npm account than previous versions on 2022-10-18. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.2.0

2 findings
HIGH Publisher changed: cpojer → simenb (on 2022-10-14) provenance

This version was published by a different npm account than previous versions on 2022-10-14. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.1.2

2 findings
HIGH Publisher changed: cpojer → simenb (on 2022-09-30) provenance

This version was published by a different npm account than previous versions on 2022-09-30. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.1.0

2 findings
HIGH Publisher changed: cpojer → simenb (on 2022-09-28) provenance

This version was published by a different npm account than previous versions on 2022-09-28. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.0.3

2 findings
HIGH Publisher changed: cpojer → simenb (on 2022-09-10) provenance

This version was published by a different npm account than previous versions on 2022-09-10. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.0.2

2 findings
HIGH Publisher changed: cpojer → simenb (on 2022-09-03) provenance

This version was published by a different npm account than previous versions on 2022-09-03. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.0.1

2 findings
HIGH Publisher changed: cpojer → simenb (on 2022-08-26) provenance

This version was published by a different npm account than previous versions on 2022-08-26. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.0.0

2 findings
HIGH Publisher changed: cpojer → simenb (on 2022-08-25) provenance

This version was published by a different npm account than previous versions on 2022-08-25. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v28.1.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v28.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v28.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v28.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v28.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v28.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v28.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v28.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v27.5.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v27.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v27.4.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v27.4.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v27.4.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v27.4.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v27.4.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v27.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.