← Home

node-llama-cpp

8
Versions
License
Yes
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

giladgd

Keywords

llamallama-cppllama.cppbindingsaicmakecmake-jsprebuilt-binariesllmggufmetalcudavulkangrammarembeddingrerankrerankingjson-grammarjson-schema-grammarfunctionsfunction-callingtoken-predictionspeculative-decodingtemperatureminPtopKtopPseedxtcjson-schemaraspberry-piself-hostedlocalcataimistraldeepseekqwenqwqgptgpt-osstypescriptlorabatchinggpu

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance no-provenance AI (provenance): Established package with long history; lack of provenance is common and not a risk signal for this package. ai
phantom-deps phantom-dep:cross-env AI (phantom-deps): cross-env is a declared runtime dependency used in build/cmake scripts; not a direct JS import but legitimately needed. ai
install-scripts install-script:postinstall AI (install-scripts): Postinstall runs the package's own CLI for native binary setup — standard pattern for native addon packages with prebuilt binaries. ai
phantom-deps phantom-dep:ignore AI (phantom-deps): Declared dep used via config files, not direct imports; normal for this package's build tooling. ai
phantom-deps phantom-dep:cmake-js AI (phantom-deps): cmake-js is used as a build tool via config/CLI, not direct import; expected for native addon packages. ai
phantom-deps phantom-dep:node-addon-api AI (phantom-deps): node-addon-api is consumed by native C++ build tooling, not JS imports; standard for native addons. ai

Versions (showing 8 of 8)

Version Deps Published
3.18.1 28 / 48
3.17.1 28 / 48
3.16.0 29 / 48
3.14.4 29 / 48
3.12.4 29 / 48
3.10.0 30 / 48
3.9.0 30 / 48
3.8.0 30 / 47

v3.18.1

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: node ./dist/cli/cli.js postinstall

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.17.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.16.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.14.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.12.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.10.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.9.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.8.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.