← Home

binary-version

Get the version of a binary in semver format

1
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

sindresorhus

Keywords

binaryexecutableversionsemversemanticcli

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:execa AI (dependencies): execa is a well-known sindresorhus package for process execution; its use here is appropriate and expected for this binary-version utility. ai
dependencies unvetted-dep:find-versions AI (dependencies): find-versions is a well-known sindresorhus package for extracting semver strings; its use here is the core mechanism of binary-version. ai
provenance no-provenance AI (provenance): Sindresorhus packages historically lack Sigstore provenance; absence is consistent with the publisher's track record and not a risk signal here. ai

Versions (showing 1 of 1)

Version Deps Published
7.1.0 2 / 3