← Home

@tangle-network/browser-agent-driver

LLM-driven browser agent for UI automation, testing, and evaluation

18
Versions
(MIT OR Apache-2.0)
License
Yes
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

vutuanlinh2k2drewstonetjemmmictin-tangle-tools

Keywords

agentautomationplaywrightllmtestingbrowserbrowser-agentbadai-browseraccessibilitya11y

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): Consistent with manual publish by known maintainer, not a source-tampering signal. ai
source-diff obfuscated-file:dist/drivers/som-overlay.d.ts AI (source-diff): Long line is a minified inline JS string for a documented SoM overlay feature, not obfuscation. ai
maintainer-change maintainer-removed AI (maintainer-change): Publisher shifted to CI/CD (GitHub Actions) with SLSA provenance, not a takeover pattern. ai
phantom-deps phantom-dep:ffmpeg-static AI (phantom-deps): ffmpeg-static is a declared runtime dep; likely consumed indirectly or in dist bundle, not a phantom dep. ai
publish-pattern new-deps-added AI (publish-pattern): axe-core is a well-established accessibility library; addition is consistent with package purpose. ai
source-diff large-new-source-files AI (source-diff): Large file additions reflect benchmark/research tooling growth, consistent with the project's stated purpose and CI-attested provenance. ai
source-diff obfuscated-file:dist/drivers/cursor-overlay.d.ts AI (source-diff): Long line is a legitimate inline DOM/CSS script string in a .d.ts declaration file, not obfuscated malware. ai
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI publishing with SLSA attestation; legitimate automation pattern for this package. ai
install-scripts install-script:postinstall AI (install-scripts): Runs a local bundled .mjs script for provider patching; no remote code fetch; SLSA provenance attested. ai
phantom-deps phantom-dep:axe-core AI (phantom-deps): axe-core is a declared runtime dep used via config injection; false positive for this package. ai
phantom-deps phantom-dep:openai AI (phantom-deps): openai is a declared runtime dep; phantom-dep heuristic is a false positive here. ai

Versions (showing 18 of 18)

Version Deps Published
0.35.4 6 / 14
0.35.3 6 / 14
0.35.2 9 / 14
0.34.0 9 / 14
0.33.2 9 / 14
0.33.1 9 / 14
0.32.0 9 / 13
0.30.0 9 / 12
0.29.0 9 / 12
0.21.0 8 / 12
0.18.0 8 / 12
0.17.0 8 / 12
0.16.0 8 / 12
0.14.1 8 / 12
0.13.0 8 / 10
0.12.1 7 / 10
0.12.0 7 / 10
0.6.0 6 / 6

v0.35.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.35.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.35.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.34.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.29.0

2 findings
HIGH New obfuscated file: dist/drivers/som-overlay.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.17.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.13.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.