← Home

robotjs

2
Versions
License
Yes
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

octalmage

Keywords

AutomationGUImousekeyboardscreenshotimagepixeldesktoprobotjsscreenrecognitionautohotkeymachinelearningcolor

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
npm-metadata url-dep:targetpractice AI (npm-metadata): Same-author devDependency test helper repo, not runtime code. ai
publish-pattern dormant-publish AI (publish-pattern): Long-lived stable native package with sparse release cadence, no behavior change. ai
install-scripts install-script:install AI (install-scripts): Standard native addon build pattern (prebuild-install || node-gyp rebuild); stable for this package. ai
phantom-deps phantom-dep:prebuild-install AI (phantom-deps): prebuild-install is a known implicit runtime/binary dependency for native addons; not directly imported by design. ai
phantom-deps phantom-dep:node-addon-api AI (phantom-deps): node-addon-api is used at build/compile time via gyp config, not directly imported in JS; false positive for native addons. ai

Versions (showing 2 of 2)

Version Deps Published
0.7.1 2 / 4
0.7.0 2 / 5

v0.7.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.