← Home

@ironsoftware/ironpdf

IronPDF for Node

4
Versions
SEE LICENSE IN LICENSE
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

ikkyuironpyaephyobline

Keywords

IronPDFpdfhtmldocumentchromeinvoiceheadless-chromehtml to pdf nodejsnodejs html to pdfnode html to pdfhtml to pdf nodehtml to pdf in nodejsnode js html to pdfnodejs generate pdf from htmlnodejs convert html to pdfnodejs create pdf from htmlhow to convert html to pdf in node jsconvert html to pdf nodejsgenerate pdf from html nodejsnode js generate pdf from htmlnode js convert html to pdfhtml to pdf in node jsconvert html to pdf nodehtml-pdf-nodenode js pdf generatorhtml to pdf nodejs without puppeteerconvert html to pdf in node jsnodejs pdf generator from htmlnode generate pdf from htmlnodejs pdf generatorhtml to pdf node.jshtml to pdf node jshtml pdf nodenode pdf librarynodejs pdf libraryhtml-pdf nodejshtml-pdf nodenode.js html to pdfsign pdf nodejsnode create pdf from htmlnode pdf apinode convert html to pdfnode js pdf generator from htmlnodejs pdf viewerhtml to pdf converter nodejsnode pdf generatorgenerate pdf nodejscreate pdf from html nodejsnodejs pdf from htmlnode js create pdf from html templatenode js download pdf from urlnodejs generate pdf from templateconvert html to pdf in nodejsnodejs create pdf filegenerate pdf in nodejsnode js generate pdf from templatepdf generator node jsnodejs convert pdf to imagegenerate pdf node jspdf conversion in node.jscreate pdf in node jsnode pdf sdk

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:child-process-import AI (semgrep): Expected for a native PDF engine wrapper that spawns platform-specific binaries. ai
semgrep semgrep:dynamic-require AI (semgrep): Resolves platform-specific engine package by OS/arch name; not user-controlled input. ai
phantom-deps phantom-dep:@jimp/types AI (phantom-deps): Transitive type dependency of jimp; stable false positive for this package. ai
phantom-deps phantom-dep:@types/unzipper AI (phantom-deps): Type-only package for unzipper; framework-scoped, stable false positive. ai

Versions (showing 4 of 4)

Version Deps Published
2026.6.1 7 / 12
2026.5.1 7 / 12
2025.12.2 8 / 11
2025.11.2 8 / 10

v2026.6.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2026.5.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2025.12.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2025.11.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.