@realtimex/node-llama-cpp-linux-x64
Prebuilt binary for node-llama-cpp for Linux x64
5
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
realtimex
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Publisher changed to GitHub Actions with SLSA provenance attestation — this is the expected pattern for CI/CD-automated publishing and is a stronger supply chain signal than manual publishing. | ai | |
| npm-metadata | bundled-binaries | AI (npm-metadata): Package is explicitly a prebuilt binary distribution for node-llama-cpp (llama.cpp native addon). The .node and .so files are expected artifacts; SLSA provenance attestation confirms CI/CD build integrity. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Platform-specific prebuilt binary sub-packages legitimately have sparse READMEs, no keywords, and no runtime deps — they are consumed as optional deps of the main package, not standalone. | ai |