← Home

@homebridge/node-pty-prebuilt-multiarch

5
Versions
License
Yes
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

oznunorthernmansuperegkhaostebaauwdustin.greifnfarinabwp91

Keywords

ptyttyterminalpseudoterminalforkptyopenpty

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:node-gyp-build AI (phantom-deps): Used via install script, referenced in config, not source-imported. ai
phantom-deps phantom-dep:node-gyp AI (phantom-deps): Implicit build-time dependency for native module compilation. ai
phantom-deps phantom-dep:nan AI (phantom-deps): nan is a native-binding build dep, not directly imported by design. ai
maintainer-change maintainer-removed AI (maintainer-change): Coincides with provenance-improved CI/CD publish; not a takeover pattern. ai
semgrep semgrep:child-process-import AI (semgrep): child_process import is in test files (unixTerminal.test.js), not runtime code. Expected for a terminal emulation library's test suite. ai
semgrep semgrep:child-process-spawn AI (semgrep): child_process.spawn in test files only; used to test PTY behavior. Not a runtime risk. ai
install-scripts install-script:postinstall AI (install-scripts): Postinstall runs node scripts/post-install.js — standard native addon post-install step for node-pty-prebuilt-multiarch. Stable across versions. ai
install-scripts install-script:install AI (install-scripts): Install script uses prebuild-install pattern to fetch prebuilt binaries or compile from source — canonical native addon install flow for this package. ai
phantom-deps phantom-dep:prebuild-install AI (phantom-deps): prebuild-install is used implicitly during install script execution; false positive for native addon packages. ai
semgrep semgrep:dynamic-require AI (semgrep): Dynamic require loads the native .node addon from a computed path — standard pattern for native Node.js addons. ai
npm-metadata bundled-binaries AI (npm-metadata): Bundled .node prebuilds and ConPTY DLLs are the core purpose of this 'prebuilt-multiarch' package. Expected and legitimate. ai
phantom-deps phantom-dep:node-addon-api AI (phantom-deps): node-addon-api is used at build/compile time for native addon; phantom classification is a false positive here. ai

Versions (showing 5 of 5)

Version Deps Published
0.14.1 2 / 14
0.14.0 2 / 13
0.13.1 2 / 13
0.12.0 2 / 13
0.11.1 3 / 11

v0.14.1

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: northernman → GitHub Actions (on 2026-07-23, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (northernman) on 2026-07-23, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.12.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.11.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.