@jitsi/robotjs
7
Versions
—
License
Yes
Install Scripts
Attested
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation (unverified)
npm registry signatures
gitHead linked
Maintainers
hristoterezovyanasjitsiorgsaghulmihhujallamsettyandrei.gavrilescudamenchocalinteodor
Keywords
AutomationGUImousekeyboardscreenshotimagepixeldesktoprobotjsscreenrecognitionautohotkeymachinelearningcolor
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | dormant-publish | AI (publish-pattern): No-op release after gap; provenance unchanged and diff shows no code changes. | ai | |
| install-scripts | install-script:install | AI (install-scripts): node-gyp-build is the canonical prebuilt-binary loader for native addons; stable pattern for this package. | ai | |
| npm-metadata | bundled-binaries | AI (npm-metadata): Prebuilt .node binaries are expected for this native addon; SLSA provenance attestation confirms CI/CD build integrity. | ai | |
| phantom-deps | phantom-dep:node-addon-api | AI (phantom-deps): node-addon-api is a build-time C++ header dependency referenced in binding.gyp, not a JS import — stable false positive. | ai |
Versions (showing 7 of 7)
| Version | Deps | Published |
|---|---|---|
| 0.6.24 | 2 / 5 | |
| 0.6.23 | 2 / 5 | |
| 0.6.22 | 2 / 5 | |
| 0.6.21 | 2 / 5 | |
| 0.6.20 | 2 / 5 | |
| 0.6.18 | 2 / 5 | |
| 0.6.17 | 2 / 5 |
v0.6.24
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.23
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.