← Home

playwright-webkit

A high-level API to automate WebKit

18
Versions
Apache-2.0
License
Yes
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures gitHead linked

Maintainers

pavelfeldmanyurysdgozman-msplaywright-bot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:dynamic-require AI (semgrep): Loads optional playwright-test package by resolved path; stable pattern. ai
npm-metadata bundled-binaries AI (npm-metadata): Playwright ships prebuilt browser-driver binaries; expected for automation tooling. ai
semgrep semgrep:new-function-constructor AI (semgrep): Injected page-context selector engine, standard Playwright pattern. ai
semgrep semgrep:api-obfuscation-reflect AI (semgrep): Reflect used for internal API hook installation, not evasion. ai
semgrep semgrep:child-process-import AI (semgrep): Needed to launch browser processes, core function. ai
semgrep semgrep:child-process-spawn AI (semgrep): Launches browser executable, core function. ai
semgrep semgrep:http-module-request AI (semgrep): Downloads browser binaries from official CDN, documented behavior. ai
semgrep semgrep:base64-decode AI (semgrep): Screenshot buffer decode, core browser-automation functionality. ai
install-scripts install-script:install AI (install-scripts): Install script downloads prebuilt WebKit binaries; this is Playwright's documented install flow, stable across all versions. ai
bogus-package bogus-package AI (bogus-package): playwright-webkit is a minimal browser sub-package of Playwright; short README and no keywords are expected. ai

Versions (showing 18 of 18)

Version Deps Published
1.62.0 1 / 0
1.60.0 1 / 0
1.59.1 1 / 0
1.59.0 1 / 0
1.58.1 1 / 0
1.57.0 1 / 0
1.56.1 1 / 0
1.56.0 1 / 0
1.55.1 1 / 0
1.55.0 1 / 0
1.54.2 1 / 0
1.54.1 1 / 0
1.54.0 1 / 0
1.53.1 1 / 0
1.53.0 1 / 0
1.15.0 14 / 0
1.1.1 10 / 0
1.1.0 10 / 0

v1.62.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.15.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • bin/PrintDeps.exe

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.