← Home

@mdn/browser-compat-data

Browser compatibility data provided by MDN Web Docs

51
Versions
CC0-1.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

leomcacaugnermdn-bot

Keywords

bcdbrowser-compat-databrowsercompatibilitydatamdnmozilla

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:dynamic-require AI (semgrep): Dynamic require() loads the package's own bundled JSON compat data files via filesystem traversal — not user-controlled input. This is the package's core data-loading mechanism. ai
semgrep semgrep:child-process-import AI (semgrep): child_process is used only in dev/scripts tooling (fix-format.js), not in runtime code or install hooks. No risk to package consumers. ai
provenance no-provenance AI (provenance): Official MDN/Mozilla package with 2000+ day history and clean publisher record. Lack of Sigstore provenance is acceptable given strong ecosystem trust signals. ai
provenance publisher-changed AI (provenance): MDN BCD transitioned to GitHub Actions CI/CD publishing with SLSA attestation — this is a legitimate, security-improving automation change for this package. ai
maintainer-change maintainer-removed AI (maintainer-change): Removal of individual maintainers is consistent with MDN BCD's transition to fully automated GitHub Actions publishing; no suspicious new maintainers added. ai

Versions (showing 51 of 396)

View all versions
Version Deps Published
8.0.1 0 / 0
8.0.0 0 / 0
7.3.17 0 / 0
7.3.16 0 / 0
7.3.15 0 / 0
7.3.14 0 / 0
7.3.13 0 / 0
7.3.12 0 / 0
7.3.11 0 / 0
7.3.10 0 / 0
7.3.9 0 / 0
7.3.8 0 / 0
7.3.7 0 / 0
7.3.6 0 / 0
7.3.5 0 / 0
7.3.4 0 / 0
7.3.3 0 / 0
7.3.2 0 / 0
7.3.1 0 / 0
7.3.0 0 / 0
7.2.6 0 / 0
7.2.5 0 / 0
7.2.4 0 / 0
7.2.3 0 / 0
7.2.2 0 / 0
7.2.1 0 / 0
7.2.0 0 / 0
7.1.24 0 / 0
7.1.23 0 / 0
7.1.22 0 / 0
7.1.21 0 / 0
7.1.20 0 / 0
7.1.19 0 / 0
7.1.18 0 / 0
7.1.17 0 / 0
7.1.16 0 / 0
7.1.15 0 / 0
7.1.14 0 / 0
7.1.13 0 / 0
7.1.12 0 / 0
7.1.11 0 / 0
7.1.10 0 / 0
7.1.9 0 / 0
7.1.8 0 / 0
7.1.7 0 / 0
7.1.6 0 / 0
7.1.5 0 / 0
7.1.4 0 / 0
7.1.3 0 / 0
7.1.2 0 / 0
7.1.1 0 / 0

v8.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.3.17

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.3.16

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.3.15

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.3.14

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.3.13

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.