@homebridge/node-pty-prebuilt-multiarch
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:node-gyp-build | AI (phantom-deps): Used via install script, referenced in config, not source-imported. | ai | |
| phantom-deps | phantom-dep:node-gyp | AI (phantom-deps): Implicit build-time dependency for native module compilation. | ai | |
| phantom-deps | phantom-dep:nan | AI (phantom-deps): nan is a native-binding build dep, not directly imported by design. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Coincides with provenance-improved CI/CD publish; not a takeover pattern. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): child_process import is in test files (unixTerminal.test.js), not runtime code. Expected for a terminal emulation library's test suite. | ai | |
| semgrep | semgrep:child-process-spawn | AI (semgrep): child_process.spawn in test files only; used to test PTY behavior. Not a runtime risk. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Postinstall runs node scripts/post-install.js — standard native addon post-install step for node-pty-prebuilt-multiarch. Stable across versions. | ai | |
| install-scripts | install-script:install | AI (install-scripts): Install script uses prebuild-install pattern to fetch prebuilt binaries or compile from source — canonical native addon install flow for this package. | ai | |
| phantom-deps | phantom-dep:prebuild-install | AI (phantom-deps): prebuild-install is used implicitly during install script execution; false positive for native addon packages. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require loads the native .node addon from a computed path — standard pattern for native Node.js addons. | ai | |
| npm-metadata | bundled-binaries | AI (npm-metadata): Bundled .node prebuilds and ConPTY DLLs are the core purpose of this 'prebuilt-multiarch' package. Expected and legitimate. | ai | |
| phantom-deps | phantom-dep:node-addon-api | AI (phantom-deps): node-addon-api is used at build/compile time for native addon; phantom classification is a false positive here. | ai |
Versions (showing 5 of 5)
| Version | Deps | Published |
|---|---|---|
| 0.14.1 | 2 / 14 | |
| 0.14.0 | 2 / 13 | |
| 0.13.1 | 2 / 13 | |
| 0.12.0 | 2 / 13 | |
| 0.11.1 | 3 / 11 |
v0.14.1
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (northernman) on 2026-07-23, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.12.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.11.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.