sinon-chai
Extends Chai with assertions for the Sinon.JS mocking framework.
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): simondel is a long-standing maintainer (1857 days, 36 approved versions). Legitimate maintainer transition for sinon-chai. | ai | |
| license | uncommon-license:WTFPL | AI (license): Dual-licensed (BSD-2-Clause OR WTFPL); BSD-2-Clause is standard permissive. Stable for this package. | ai |
Versions (showing 36 of 36)
| Version | Deps | Published |
|---|---|---|
| 4.0.1 | 0 / 7 | |
| 4.0.0 | 0 / 7 | |
| 3.7.0 | 0 / 6 | |
| 3.6.0 | 0 / 6 | |
| 3.5.0 | 0 / 6 | |
| 3.4.0 | 0 / 6 | |
| 3.3.0 | 0 / 6 | |
| 3.2.0 | 0 / 6 | |
| 3.1.0 | 0 / 6 | |
| 3.0.0 | 0 / 6 | |
| 2.14.0 | 0 / 6 | |
| 2.13.0 | 0 / 7 | |
| 2.12.0 | 0 / 6 | |
| 2.11.0 | 0 / 6 | |
| 2.10.0 | 0 / 7 | |
| 2.9.0 | 0 / 7 | |
| 2.8.0 | 0 / 7 | |
| 2.7.0 | 0 / 7 | |
| 2.6.0 | 0 / 7 | |
| 2.5.0 | 0 / 7 | |
| 2.4.0 | 0 / 7 | |
| 2.3.1 | 1 / 6 | |
| 2.3.0 | 1 / 6 | |
| 2.2.0 | 1 / 6 | |
| 2.1.2 | 1 / 5 | |
| 2.1.1 | 1 / 5 | |
| 2.1.0 | 1 / 5 | |
| 2.0.1 | 1 / 5 | |
| 2.0.0 | 1 / 5 | |
| 1.3.1 | 1 / 5 | |
| 1.3.0 | 1 / 5 | |
| 1.2.2 | 1 / 4 | |
| 1.2.1 | 1 / 4 | |
| 1.2.0 | 1 / 4 | |
| 1.1.0 | 2 / 3 | |
| 1.0.0 | 2 / 3 |
v3.7.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.6.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.4.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.3.0
2 findingsThis version was published by a different npm account than previous versions on 2018-11-26. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.