@n8n/computer-use
Local AI gateway for n8n Instance AI — filesystem, shell, screenshots, mouse/keyboard, and browser automation
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | new-deps-added | AI (publish-pattern): fast-glob is a well-known, widely-used utility with no malicious history; addition is benign for this package. | ai | |
| dependencies | unvetted-dep:@napi-rs/image | AI (dependencies): Legitimate napi-rs image library replacing sharp; same functional role, well-known ecosystem package. | ai | |
| provenance | no-provenance | AI (provenance): Common across npm; n8n's publisher track record is clean. | ai | |
| dependencies | unvetted-dep:@jitsi/robotjs | AI (dependencies): Native input-automation library; expected dependency for a computer-use/mouse-keyboard automation package. | ai | |
| dependencies | unvetted-dep:node-screenshots | AI (dependencies): Screenshot capture library; expected dependency for a computer-use automation package. | ai | |
| dependencies | unvetted-dep:@n8n/mcp-browser | AI (dependencies): First-party @n8n scoped browser automation dep from the same n8n-io org; expected for this package. | ai |
Versions (showing 9 of 9)
| Version | Deps | Published |
|---|---|---|
| 0.9.0 | 14 / 3 | |
| 0.8.0 | 14 / 3 | |
| 0.7.0 | 14 / 3 | |
| 0.6.0 | 13 / 3 | |
| 0.5.0 | 13 / 3 | |
| 0.4.1 | 13 / 3 | |
| 0.4.0 | 13 / 3 | |
| 0.3.0 | 13 / 3 | |
| 0.2.0 | 13 / 3 |
v0.9.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.