← Home

baseline-browser-mapping

A library for obtaining browser versions with their maximum supported Baseline feature set and Widely Available status.

34
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

tonypconway

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:web-features AI (dependencies): web-features is an MDN/web-platform-dx package directly relevant to this library's purpose of tracking Baseline browser feature support. Not a risk for this package. ai
provenance publisher-changed AI (provenance): Publisher changed from personal account to GitHub Actions CI/CD, backed by SLSA v1 Sigstore attestation from the web-platform-dx org. This is a legitimate and verifiable supply chain improvement, not a compromise. ai

Versions (showing 34 of 134)

Hide prereleases
Version Deps Published
2.4.3 2 / 3
2.4.2 2 / 3
2.4.1 2 / 3
2.4.0 0 / 5
2.3.0 2 / 3
2.2.2 2 / 3
2.2.1 2 / 3
2.2.0 2 / 3
2.1.1 2 / 3
2.1.0 2 / 3
2.0.0 2 / 2
1.0.0 2 / 2
0.3.1 1 / 2
0.3.0 1 / 2
0.2.9 1 / 0
0.2.8 1 / 0
0.2.7 1 / 0
0.2.6 1 / 0
0.2.5 1 / 0
0.2.4 1 / 0
0.2.3 1 / 0
0.2.2 1 / 0
0.2.1 1 / 0
0.1.1 1 / 0
0.1.0 1 / 0
2.8.4-beta5 0 / 13
2.8.4-beta4 0 / 13
2.8.4-beta3 0 / 13
2.8.4-beta2 0 / 13
2.8.4-beta 0 / 13
2.8.0-beta 0 / 13
2.7.4-beta 0 / 13
2.7.0-beta 0 / 13
2.5.0-beta 0 / 13

v2.8.4-beta5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.8.4-beta4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.8.4-beta3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.8.4-beta2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.8.4-beta

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.8.0-beta

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.7.4-beta

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.7.0-beta

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.5.0-beta

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.