edgedriver
Microsofts' EdgeDriver for Node.js
16
Versions
MIT
License
Yes
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
barrettswdio-user
Keywords
edgedriveredgedriverserverwebdriver
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:yargs | AI (phantom-deps): yargs is explicitly declared as a runtime dependency in package.json; the phantom-dep finding is a false positive for this package. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): node-fetch is a well-established HTTP library appropriate for a WebDriver binary downloader; not a suspicious dependency for this package. | ai | |
| install-scripts | install-script:install | AI (install-scripts): Install script downloads the EdgeDriver binary, which is the core purpose of this package. The guard pattern (test -f) is defensive and appropriate. Stable across all versions. | ai | |
| provenance | publisher-changed | AI (provenance): Publisher changed from wdio-user to GitHub Actions CI/CD, corroborated by a valid SLSA provenance attestation. This is a legitimate migration to automated publishing, not a compromise. | ai |