← Home

@n8n/computer-use

Local AI gateway for n8n Instance AI — filesystem, shell, screenshots, mouse/keyboard, and browser automation

9
Versions
SEE LICENSE IN LICENSE.md
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

n8n-matsuuutomin8njan_n8n_iocornelius.suermann

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern new-deps-added AI (publish-pattern): fast-glob is a well-known, widely-used utility with no malicious history; addition is benign for this package. ai
dependencies unvetted-dep:@napi-rs/image AI (dependencies): Legitimate napi-rs image library replacing sharp; same functional role, well-known ecosystem package. ai
provenance no-provenance AI (provenance): Common across npm; n8n's publisher track record is clean. ai
dependencies unvetted-dep:@jitsi/robotjs AI (dependencies): Native input-automation library; expected dependency for a computer-use/mouse-keyboard automation package. ai
dependencies unvetted-dep:node-screenshots AI (dependencies): Screenshot capture library; expected dependency for a computer-use automation package. ai
dependencies unvetted-dep:@n8n/mcp-browser AI (dependencies): First-party @n8n scoped browser automation dep from the same n8n-io org; expected for this package. ai

Versions (showing 9 of 9)

Version Deps Published
0.9.0 14 / 3
0.8.0 14 / 3
0.7.0 14 / 3
0.6.0 13 / 3
0.5.0 13 / 3
0.4.1 13 / 3
0.4.0 13 / 3
0.3.0 13 / 3
0.2.0 13 / 3

v0.9.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.