@realtimex/node-llama-cpp-mac-arm64-metal
Prebuilt binary for node-llama-cpp for macOS arm64 with Metal support
9
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
realtimex
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Publisher changed from realtimex to GitHub Actions, consistent with adopting CI/CD publishing. SLSA provenance attestation confirms builds originate from the expected repository, making this a legitimate automation transition. | ai | |
| npm-metadata | bundled-binaries | AI (npm-metadata): Package is explicitly a prebuilt binary carrier for node-llama-cpp (macOS arm64 Metal). Binaries are covered by SLSA provenance attestation from CI/CD. Pattern is stable across 74 versions. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Platform-specific binary sub-packages are intentionally minimal (no deps, no keywords, sparse README). This is a structural pattern, not a spam indicator, for this package. | ai |
Versions (showing 9 of 219)
| Version | Deps | Published |
|---|---|---|
| 0.8.0 | 0 / 0 | |
| 0.7.0 | 0 / 0 | |
| 0.6.0 | 0 / 0 | |
| 0.5.0 | 0 / 0 | |
| 0.4.0 | 0 / 0 | |
| 0.3.1 | 0 / 0 | |
| 0.3.0 | 0 / 0 | |
| 0.2.4 | 0 / 0 | |
| 0.2.0 | 0 / 0 |
v0.2.4
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.