# 使用 Homebrew 安装 imagejs

查看 imagejs 的安装路径、可执行文件、元数据以及面向 AI 代理工作流的安全说明。

## 安装

```sh
sudo av install brew:imagejs
```

其他安装命令:

### macOS

- Homebrew (100%):

```sh
brew install imagejs
```

  证据: local Homebrew formula metadata

## 软件包事实

- **软件包键:** brew:imagejs
- **软件包管理器:** Homebrew
- **软件包管理器页面:** <https://formulae.brew.sh/formula/imagejs>
- **版本:** 0.7.2
- **来源摘要:** Tool to hide JavaScript inside valid image files
- **主页:** <https://github.com/jklmnn/imagejs>
- **仓库:** <https://github.com/jklmnn/imagejs>
- **许可证:** GPL-3.0-only
- **源码归档:** <https://github.com/jklmnn/imagejs/archive/refs/tags/0.7.2.tar.gz>
- **已生成:** 2026-08-04T22:13:35+00:00

## 可执行文件

- imagejs (cli)
- imagejs (别名)

## 安装行为

- post-install 钩子: 未定义
- Bottle: 可用 于 arm64_big_sur, arm64_linux, arm64_monterey, arm64_sequoia, arm64_sonoma, arm64_tahoe, arm64_ventura, big_sur, catalina, monterey, sonoma, ventura

## 版本和新鲜度

- 页面生成时间: 2026-08-04
- 管理器版本: 0.7.2
- 本地数据: OK
- 上游仓库: https://github.com/jklmnn/imagejs
- 检测到的最新版本: 0.7.2 (当前)
- 信息: No package-manager update timestamp was available.
## 项目历史与用法

imagejs is a small proof-of-concept command-line tool for packaging JavaScript into files that remain valid image files. The README presents it as a way to create image files that can execute JavaScript and explicitly connects the idea to extending XSS vulnerabilities.

### 项目历史

The project appeared on GitHub in 2014 and credits Ajin Abraham's work on GIFs serving JavaScript as the idea that inspired the C implementation. The README says imagejs added bitmap support, and the changelog shows later support for GIF injection, BMP injection, WebP injection, and additional output formats.

### 采用历史

imagejs remained a niche security package rather than a broad media utility. GitHub repository metadata shows far more stars than package-manager breadth, and the input metadata lists Homebrew as the only package-manager mapping for this batch.

### 使用方式

Users run imagejs with an output type and a JavaScript file, producing an image-like file named after the input. The README documents BMP, GIF, WebP, PNM, and PGF outputs, a line-viewable BMP mode, and injection into existing GIF files.

### 为什么软件包爱好者会关心

The package is interesting because it lives at the boundary between file-format polyglots and web security demonstrations. It is not a general steganography suite; it is a compact package for showing how MIME assumptions, image upload policies, and script execution contexts can collide.

### 时间线

- 2014: GitHub repository is created.
- 0.4.1: GIF, BMP, WebP, PNM, and PGF output support is documented in the changelog.
- 0.5.0: GIF injection support is added.
- 0.6.0: BMP injection support is added.
- 0.7.0: WebP injection support is added.

### Related projects

- The README names Ajin Abraham's GIF/JavaScript work as the source idea. Conceptually, imagejs is related to polyglot-file demos, browser XSS testing, and image steganography tools, although its stated goal is executable JavaScript-in-image proof of concept rather than secret-message hiding.

### 来源

- Project README, changelog, GitHub repository metadata, GitHub tags, and Homebrew formula metadata.


## 安全说明

broad file, network, media, or database tool signal.

- **Geiger 风险:** blue / 中
- broad file, network, media, or database tool signal

## 源数据库详情

- **Source Database:** Homebrew formula API
- **Tap:** homebrew/core
- **Full Name:** imagejs
- **Version Scheme:** 0
- **Revision:** 0
- **Head Version:** HEAD
- **Bottle Stable Root URL:** <https://ghcr.io/v2/homebrew/core>
- **Deprecated:** no
- **Disabled:** no
- **Keg Only:** no
- **URL Keys:** head, stable


## 相关链接

- [Source-control packages](https://pkg.so/zh-hans/source-control-tools/) - Belongs to a source-control command family.
- [Secret-risk packages](https://pkg.so/zh-hans/secret-risk-packages/) - Has protected-tool coverage, approval-gate, or non-low Geiger security signals.
- [Terminal utility packages](https://pkg.so/zh-hans/terminal-utilities/) - Matched terminal and command-line workflow metadata.
- [Language runtime packages](https://pkg.so/zh-hans/language-runtime-packages/) - Matched language runtime, compiler, or interpreter metadata.
- [retire](https://pkg.so/zh-hans/brew/retire/) - Shares pkgdb curated category or tags: cli, javascript, security.
- [mantra](https://pkg.so/zh-hans/brew/mantra/) - Shares pkgdb curated category or tags: cli, javascript, security.
- [openssl@3](https://pkg.so/zh-hans/brew/openssl-3/) - Shares pkgdb curated category or tags: cli, security.
- [gnutls](https://pkg.so/zh-hans/brew/gnutls/) - Shares pkgdb curated category or tags: cli, security.
- [p11-kit](https://pkg.so/zh-hans/brew/p11-kit/) - Shares pkgdb curated category or tags: cli, security.
- [gnupg](https://pkg.so/zh-hans/brew/gnupg/) - Shares pkgdb curated category or tags: cli, security.
- [krb5](https://pkg.so/zh-hans/brew/krb5/) - Shares pkgdb curated category or tags: cli, security.
- [nettle](https://pkg.so/zh-hans/brew/nettle/) - Shares pkgdb curated category or tags: cli, security.
- [binwalk](https://pkg.so/zh-hans/brew/binwalk/) - Both packages work with overlapping file formats or content types. Shared terms: cli, files, image, security.
- [urlfinder](https://pkg.so/zh-hans/brew/urlfinder/) - Both packages touch the same language runtime or ecosystem. Shared terms: cli, files, javascript, security.
- [exif-be-gone](https://pkg.so/zh-hans/npm/exif-be-gone/) - Both packages work with overlapping file formats or content types. Shared terms: cli, files, image, security.

## Combined YAML source

View the package source record on GitHub. [combined/imagejs.yml](https://github.com/mxcl/pkgdb/blob/main/combined/imagejs.yml)


## 来源

- pkg.so package database
- Geiger risk classifier
- package-page enrichment
- curated package history
- package version freshness
- pkgdb category and tag curation
- package relationship graph
- cross-ecosystem install command graph
