electron-chromedriver
Electron ChromeDriver
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| install-scripts | install-script:install | AI (install-scripts): Documented binary download via download-chromedriver.js; stable pattern for this official Electron package. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): child_process used to spawn the chromedriver binary as a CLI wrapper; expected and benign for this package. | ai | |
| semgrep | semgrep:child-process-spawn | AI (semgrep): Spawns the downloaded chromedriver binary; core functionality of this CLI wrapper package. | ai |
Versions (showing 8 of 8)
| Version | Deps | Published |
|---|---|---|
| 42.2.0 | 2 / 2 | |
| 42.0.0 | 2 / 2 | |
| 41.3.0 | 2 / 2 | |
| 40.10.1 | 2 / 2 | |
| 40.9.1 | 2 / 2 | |
| 39.8.7 | 2 / 2 | |
| 39.2.2 | 2 / 3 | |
| 39.2.1 | 2 / 3 |
v42.2.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v42.0.0
2 findingsScript: node ./download-chromedriver.js
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v41.3.0
2 findingsScript: node ./download-chromedriver.js
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v40.10.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v40.9.1
2 findingsScript: node ./download-chromedriver.js
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v39.8.7
2 findingsScript: node ./download-chromedriver.js
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v39.2.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v39.2.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.