← Home

puppeteer-core

A high-level API to control headless Chrome over the DevTools Protocol

37
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

mathiasgoogle-wombot

Keywords

puppeteerchromeheadlessautomation

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Publisher changed from google-wombot to GitHub Actions CI/CD with SLSA provenance attestation — this reflects a legitimate migration to automated, attested releases for the official puppeteer project. ai
semgrep semgrep:child-process-import AI (semgrep): puppeteer-core legitimately uses child_process to spawn ffmpeg for screen recording; this is a documented, expected feature of the package. ai
provenance no-provenance AI (provenance): Established Google-maintained package; lack of Sigstore provenance is not a meaningful risk signal here. ai
semgrep semgrep:base64-decode AI (semgrep): Decodes base64 binary data from Chrome DevTools Protocol event streams — standard, expected behavior for a browser automation library. Not a malicious payload risk. ai
semgrep semgrep:new-function-constructor AI (semgrep): Core Puppeteer feature for serializing user-supplied JS functions to execute in browser contexts (page.evaluate etc.). Intentional and documented API behavior, not a security risk. ai

Versions (showing 37 of 337)

Version Deps Published
5.4.0 12 / 40
5.3.1 11 / 36
5.3.0 12 / 36
5.2.1 12 / 34
5.2.0 12 / 34
5.1.0 13 / 33
5.0.0 12 / 33
4.0.1 11 / 30
4.0.0 11 / 30
3.3.0 10 / 28
3.2.0 11 / 28
3.1.0 10 / 28
3.0.4 10 / 23
3.0.3 12 / 23
3.0.2 12 / 22
3.0.1 12 / 22
3.0.0 12 / 22
2.1.1 10 / 17
2.1.0 10 / 17
2.0.0 8 / 17
1.20.0 8 / 17
1.19.0 8 / 17
1.18.1 8 / 17
1.18.0 8 / 17
1.17.0 8 / 17
1.16.0 8 / 17
1.15.0 8 / 17
1.14.0 8 / 17
1.13.0 8 / 17
1.12.2 8 / 17
1.12.1 8 / 17
1.12.0 8 / 17
1.11.0 8 / 17
1.10.0 8 / 17
1.9.0 8 / 17
1.8.0 8 / 16
1.7.0 8 / 16