pkg.soopen package index

brew / Rang 13551

imagejs mit Homebrew installieren

Prüfe Installationswege, Executables, Metadaten und Sicherheitshinweise für imagejs in AI-Agent-Workflows.

Installation

Weitere Installationsbefehle

macOS

Homebrewverifiziert · 100%
brew install imagejs

local Homebrew formula metadata

Überblick

Paketzusammenfassung

Tool to hide JavaScript inside valid image files

Befehle und Aliase

  • imagejs

Verlauf

Projektgeschichte und Nutzung

imagejs is a small proof-of-concept command-line tool for packaging JavaScript into files that remain valid image files. The README presents it as a way to create image files that can execute JavaScript and explicitly connects the idea to extending XSS vulnerabilities.

Projektgeschichte

The project appeared on GitHub in 2014 and credits Ajin Abraham's work on GIFs serving JavaScript as the idea that inspired the C implementation. The README says imagejs added bitmap support, and the changelog shows later support for GIF injection, BMP injection, WebP injection, and additional output formats.

Adoptionsgeschichte

imagejs remained a niche security package rather than a broad media utility. GitHub repository metadata shows far more stars than package-manager breadth, and the input metadata lists Homebrew as the only package-manager mapping for this batch.

Wie es verwendet wird

Users run imagejs with an output type and a JavaScript file, producing an image-like file named after the input. The README documents BMP, GIF, WebP, PNM, and PGF outputs, a line-viewable BMP mode, and injection into existing GIF files.

Warum Paket-Nerds sich dafür interessieren

The package is interesting because it lives at the boundary between file-format polyglots and web security demonstrations. It is not a general steganography suite; it is a compact package for showing how MIME assumptions, image upload policies, and script execution contexts can collide.

Zeitleiste

  • 2014: GitHub repository is created.
  • 0.4.1: GIF, BMP, WebP, PNM, and PGF output support is documented in the changelog.
  • 0.5.0: GIF injection support is added.
  • 0.6.0: BMP injection support is added.
  • 0.7.0: WebP injection support is added.

Related projects

  • The README names Ajin Abraham's GIF/JavaScript work as the source idea. Conceptually, imagejs is related to polyglot-file demos, browser XSS testing, and image steganography tools, although its stated goal is executable JavaScript-in-image proof of concept rather than secret-message hiding.

Quellen

  • Project README, changelog, GitHub repository metadata, GitHub tags, and Homebrew formula metadata.

Sicherheitslage

Risikostufe: blue

broad file, network, media, or database tool signal.

Risikoklassifikator

blue Risiko · mittel Konfidenz · tool

Warum

  • broad file, network, media, or database tool signal

Signale

  • text:image

Installationsverhalten

  • Es wurden keine Homebrew-Bottle-Metadaten erfasst.

Empfohlene Prüfung

Prüfe vor unbeaufsichtigter Agent-Nutzung, ob das Tool Klartext-Credentials liest, Remote-Zustand schreibt, Artefakte veröffentlicht oder Plugins ausführt.

Executables

Installierte Executables

BefehlArtSichtbarkeitHinweis
imagejsExecutableindexiertes ExecutableAus dem lokalen Executable-Index erkannt.

Aktualität

Version und Aktualität

Diese Signale trennen das Alter der Seitengenerierung, Aktivität des Paketmanagers und Upstream-Release-Vergleich. Versionsrückstand wird nur gemeldet, wenn eine Evidenz-URL und vergleichbare Versionen vorhanden sind.

Seite generiert2026-08-03
Manager-Version0.7.2
Manager aktualisiert
lokale Datenunbekannt
Upstreamnicht verfügbar
neueste erkannte Versionnicht erkannt
  • OKEs wurden keine Aktualitätswarnungen generiert.

Installationsmetadaten

Paketmetadaten

Paketschlüsselbrew:imagejs
Version0.7.2
PaketmanagerHomebrew
Homepagehttps://github.com/jklmnn/imagejs
Repositoryhttps://github.com/jklmnn/imagejs
Bottlenicht erfasst
Dienstkeiner deklariert

Quellspur

Aus Repository-Daten generiert

Diese Seite wird von av-web aus dem privaten Paket-SQLite-Artefakt bereitgestellt, das scripts/generate-pkg-sqlite.py erstellt.

Verwendete Quellen

  • Geiger risk classifier
  • cross-ecosystem install command graph
  • curated package history
  • pkg.so package database
  • pkgdb category and tag curation