← Home

playwright-chromium

A high-level API to automate Chromium

15
Versions
Apache-2.0
License
Yes
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

pavelfeldmanyurysdgozman-msplaywright-bot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:child-process-spawn AI (semgrep): Core browser-launching functionality. ai
semgrep semgrep:api-obfuscation-reflect AI (semgrep): Reflect used for API hook installation, not evasion. ai
semgrep semgrep:http-module-request AI (semgrep): Browser binary download via browserFetcher, documented install flow. ai
semgrep semgrep:child-process-import AI (semgrep): Needed to launch/manage browser processes. ai
semgrep semgrep:base64-decode AI (semgrep): Decoding CDP screenshot data, not payload hiding. ai
semgrep semgrep:new-function-constructor AI (semgrep): Injected selector-engine parsing, core Playwright feature. ai
publish-pattern dormant-publish AI (publish-pattern): playwright-chromium is an official Microsoft package with SLSA provenance attestation; dormancy between releases is a known pattern for this sub-package and does not indicate account takeover. ai
bogus-package bogus-package AI (bogus-package): False positive — playwright-chromium is a major Microsoft package (167k downloads/week). Docs live on playwright.dev; no-keywords/short-README signals are irrelevant. ai
install-scripts install-script:install AI (install-scripts): Playwright's install script downloads prebuilt Chromium binaries; this is the documented and expected install flow for all playwright-* browser packages. ai

Versions (showing 15 of 15)

Version Deps Published
1.62.0 1 / 0
1.60.0 1 / 0
1.59.1 1 / 0
1.59.0 1 / 0
1.58.2 1 / 0
1.58.1 1 / 0
1.58.0 1 / 0
1.57.0 1 / 0
1.55.0 1 / 0
1.54.2 1 / 0
1.53.2 1 / 0
1.53.1 1 / 0
1.53.0 1 / 0
1.17.1 1 / 0
1.1.0 10 / 0

v1.62.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.17.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.