@mdn/browser-compat-data
Browser compatibility data provided by MDN Web Docs
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require() loads the package's own bundled JSON compat data files via filesystem traversal — not user-controlled input. This is the package's core data-loading mechanism. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): child_process is used only in dev/scripts tooling (fix-format.js), not in runtime code or install hooks. No risk to package consumers. | ai | |
| provenance | no-provenance | AI (provenance): Official MDN/Mozilla package with 2000+ day history and clean publisher record. Lack of Sigstore provenance is acceptable given strong ecosystem trust signals. | ai | |
| provenance | publisher-changed | AI (provenance): MDN BCD transitioned to GitHub Actions CI/CD publishing with SLSA attestation — this is a legitimate, security-improving automation change for this package. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Removal of individual maintainers is consistent with MDN BCD's transition to fully automated GitHub Actions publishing; no suspicious new maintainers added. | ai |
Versions (showing 100 of 396)
| Version | Deps | Published |
|---|---|---|
| 8.0.1 | 0 / 0 | |
| 8.0.0 | 0 / 0 | |
| 7.3.17 | 0 / 0 | |
| 7.3.16 | 0 / 0 | |
| 7.3.15 | 0 / 0 | |
| 7.3.14 | 0 / 0 | |
| 7.3.13 | 0 / 0 | |
| 7.3.12 | 0 / 0 | |
| 7.3.11 | 0 / 0 | |
| 7.3.10 | 0 / 0 | |
| 7.3.9 | 0 / 0 | |
| 7.3.8 | 0 / 0 | |
| 7.3.7 | 0 / 0 | |
| 7.3.6 | 0 / 0 | |
| 7.3.5 | 0 / 0 | |
| 7.3.4 | 0 / 0 | |
| 7.3.3 | 0 / 0 | |
| 7.3.2 | 0 / 0 | |
| 7.3.1 | 0 / 0 | |
| 7.3.0 | 0 / 0 | |
| 7.2.6 | 0 / 0 | |
| 7.2.5 | 0 / 0 | |
| 7.2.4 | 0 / 0 | |
| 7.2.3 | 0 / 0 | |
| 7.2.2 | 0 / 0 | |
| 7.2.1 | 0 / 0 | |
| 7.2.0 | 0 / 0 | |
| 7.1.24 | 0 / 0 | |
| 7.1.23 | 0 / 0 | |
| 7.1.22 | 0 / 0 | |
| 7.1.21 | 0 / 0 | |
| 7.1.20 | 0 / 0 | |
| 7.1.19 | 0 / 0 | |
| 7.1.18 | 0 / 0 | |
| 7.1.17 | 0 / 0 | |
| 7.1.16 | 0 / 0 | |
| 7.1.15 | 0 / 0 | |
| 7.1.14 | 0 / 0 | |
| 7.1.13 | 0 / 0 | |
| 7.1.12 | 0 / 0 | |
| 7.1.11 | 0 / 0 | |
| 7.1.10 | 0 / 0 | |
| 7.1.9 | 0 / 0 | |
| 7.1.8 | 0 / 0 | |
| 7.1.7 | 0 / 0 | |
| 7.1.6 | 0 / 0 | |
| 7.1.5 | 0 / 0 | |
| 7.1.4 | 0 / 0 | |
| 7.1.3 | 0 / 0 | |
| 7.1.2 | 0 / 0 | |
| 7.1.1 | 0 / 0 | |
| 7.1.0 | 0 / 0 | |
| 7.0.0 | 0 / 0 | |
| 6.1.5 | 0 / 0 | |
| 6.1.4 | 0 / 0 | |
| 6.1.3 | 0 / 0 | |
| 6.1.2 | 0 / 0 | |
| 6.1.1 | 0 / 0 | |
| 6.1.0 | 0 / 0 | |
| 6.0.37 | 0 / 0 | |
| 6.0.36 | 0 / 0 | |
| 6.0.35 | 0 / 0 | |
| 6.0.34 | 0 / 0 | |
| 6.0.33 | 0 / 0 | |
| 6.0.32 | 0 / 0 | |
| 6.0.31 | 0 / 0 | |
| 6.0.30 | 0 / 0 | |
| 6.0.29 | 0 / 0 | |
| 6.0.28 | 0 / 0 | |
| 6.0.27 | 0 / 0 | |
| 6.0.26 | 0 / 0 | |
| 6.0.25 | 0 / 0 | |
| 6.0.24 | 0 / 0 | |
| 6.0.23 | 0 / 0 | |
| 6.0.22 | 0 / 0 | |
| 6.0.21 | 0 / 0 | |
| 6.0.20 | 0 / 0 | |
| 6.0.19 | 0 / 0 | |
| 6.0.18 | 0 / 0 | |
| 6.0.17 | 0 / 0 | |
| 6.0.16 | 0 / 0 | |
| 6.0.15 | 0 / 0 | |
| 6.0.14 | 0 / 0 | |
| 6.0.13 | 0 / 0 | |
| 6.0.12 | 0 / 0 | |
| 6.0.11 | 0 / 0 | |
| 6.0.10 | 0 / 0 | |
| 6.0.9 | 0 / 0 | |
| 6.0.8 | 0 / 0 | |
| 6.0.7 | 0 / 0 | |
| 6.0.6 | 0 / 0 | |
| 6.0.5 | 0 / 0 | |
| 6.0.4 | 0 / 0 | |
| 6.0.3 | 0 / 0 | |
| 6.0.2 | 0 / 0 | |
| 6.0.1 | 0 / 0 | |
| 6.0.0 | 0 / 0 | |
| 5.7.6 | 0 / 0 | |
| 5.7.5 | 0 / 0 | |
| 5.7.4 | 0 / 0 |
v8.0.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.3.17
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.3.16
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.3.15
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.3.14
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.3.13
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.