← Home

@jitsi/robotjs

7
Versions
License
Yes
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures gitHead linked

Maintainers

hristoterezovyanasjitsiorgsaghulmihhujallamsettyandrei.gavrilescudamenchocalinteodor

Keywords

AutomationGUImousekeyboardscreenshotimagepixeldesktoprobotjsscreenrecognitionautohotkeymachinelearningcolor

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern dormant-publish AI (publish-pattern): No-op release after gap; provenance unchanged and diff shows no code changes. ai
install-scripts install-script:install AI (install-scripts): node-gyp-build is the canonical prebuilt-binary loader for native addons; stable pattern for this package. ai
npm-metadata bundled-binaries AI (npm-metadata): Prebuilt .node binaries are expected for this native addon; SLSA provenance attestation confirms CI/CD build integrity. ai
phantom-deps phantom-dep:node-addon-api AI (phantom-deps): node-addon-api is a build-time C++ header dependency referenced in binding.gyp, not a JS import — stable false positive. ai

Versions (showing 7 of 7)

Version Deps Published
0.6.24 2 / 5
0.6.23 2 / 5
0.6.22 2 / 5
0.6.21 2 / 5
0.6.20 2 / 5
0.6.18 2 / 5
0.6.17 2 / 5

v0.6.24

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.23

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.