Applies source maps to stack traces, so a failing test points at the code you wrote rather than at the code Jest ran.
84%
Total Score
100
100
90
88
50
No build attestation or trusted publisher identity is recorded for the release, leaving publication provenance less transparent than it could be.
The repository name differs from the package and its README does not mention @jest/source-map, so the linkage is less explicit; this may be normal for a monorepo subpackage but still warrants caution.
The project uses established build tools, but no security-scanning tool was detected in the collected repository tooling.
All 11 workflows were analyzed, all 48 action references are pinned, and no untrusted checkout or script injection was found. However, three workflows grant top-level write permissions and the audit flags trusted publishing, creating a moderate workflow-hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
callsites Version ^3.1.0 | — | — |
graceful-fs Version ^4.2.11 | — | — |
convert-source-map Version ^2.0.0 | — | — |
@jridgewell/trace-mapping Version ^0.3.31 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.