Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 3 additions & 4 deletions package-lock.json

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion package.json
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,6 @@
},
"dependencies": {
"quickjs-emscripten": "^0.31.0",
"youtubei.js": "^16.0.0"
"youtubei.js": "github:alexeichhorn/YouTube.js#feat/android-sdkless-client"
Comment on lines 19 to +20

@coderabbitai coderabbitai Bot Jan 19, 2026 •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🔴 Critical

🧩 Analysis chain

🌐 Web query:

youtubei.js repository alexeichhorn YouTube.js feat/android-sdkless-client branch

💡 Result:

I couldn't find a GitHub repository or branch matching "alexeichhorn / youtubei.js" or a branch named "feat/android-sdkless-client". I found alexeichhorn’s YouTubeKit repo (Swift) and the main YouTube.js (youtubei.js) project (LuanRT), but no fork or branch by that name. Sources: GitHub listing for alexeichhorn/YouTubeKit [1] and the YouTube.js (youtubei.js) repo (LuanRT) [2].

If you have a direct GitHub URL or more details (exact username spelling or repo owner), share it and I’ll look again.

Sources:
[1] https://github.com/alexeichhorn/YouTubeKit
[2] https://github.com/LuanRT/YouTube.js


🌐 Web query:

youtubei.js ANDROID_SDKLESS client releases tags commits

💡 Result:

Here are the places that match your query and where you can find releases/tags/commits related to the Android (sdkless) client for youtubei.js / InnerTube tooling:

  1. YouTube.js releases & tags (official repo) — release history and tags for youtubei.js. [1]
  2. The YouTube.js Constants (CLIENTS) page showing ANDROID client fields (SDK_VERSION, USER_AGENT, VERSION). [2]
  3. Example commit adding an "android_sdkless" client context in yt-dlp (shows a concrete INNERTUBE_CLIENT entry and clientVersion/userAgent used for an SDK-less Android client). [3]

Sources:
[1] GitHub — LuanRT/YouTube.js Releases & Tags.
[2] YouTube.js API / Constants — CLIENTS (ANDROID) (ytjs.dev).
[3] yt-dlp commit showing android_sdkless client context.


🌐 Web query:

site:github.com alexeichhorn YouTube.js releases tags

💡 Result:

I couldn't find any GitHub releases/tags for a repository named "YouTube.js" under the user alexeichhorn. The YouTube.js project with releases is LuanRT/YouTube.js (releases page). [1]
For reference, alexeichhorn's GitHub contains YouTubeKit and other repos (not YouTube.js). [2]

Sources:

  • LuanRT/YouTube.js — Releases. [1]
  • alexeichhorn GitHub (YouTubeKit). [2]

🏁 Script executed:

cat package.json

Repository: alexeichhorn/YouTubeKit-Server

Length of output: 581


🌐 Web query:

github.com/alexeichhorn/YouTube.js android sdkless

💡 Result:

Short answer: alexeichhorn does not have a repo named YouTube.js on GitHub. The YouTube.js (youtubei.js) project you probably mean is LuanRT/YouTube.js, and Alex Eichhorn maintains YouTubeKit (an iOS extractor), not an Android "sdkless" YouTube.js. [1][2]

Options if you want an Android, SDK-less approach:

  • Use LuanRT/YouTube.js (youtubei.js) from a Node/JS layer or bundled V8/QuickJS to call InnerTube — repo and docs. [1]
  • Use a WebView-based player library (iframe approach) for Android (no Google Play YouTube SDK required), e.g. android-youtube-player. [3]
  • For native extraction on iOS see alexeichhorn/YouTubeKit. [2]

Sources:

  1. LuanRT / YouTube.js (youtubei.js) repo/docs. [1]
  2. alexeichhorn / YouTubeKit (iOS extractor). [2]
  3. PierfrancescoSoffritti / android-youtube-player (WebView/iframe approach — SDK-less). [3]

🌐 Web query:

"alexeichhorn/YouTube.js" fork

💡 Result:

Do you mean a fork of the GitHub repo "alexeichhorn/YouTube.js"? If so, do you want me to (pick one)

  • list existing forks on GitHub, or
  • create instructions to fork it yourself, or
  • find a specific fork (most active/popular)?

Tell me which and I’ll search GitHub and return results with links.


Verify the GitHub fork and pin to a commit or tag.

The repository alexeichhorn/YouTube.js does not appear to exist publicly on GitHub. The official YouTube.js project is maintained at LuanRT/YouTube.js. Confirm whether this is a private fork, an incorrect reference, or if the dependency should point to a different source. Once verified, pin the dependency to a specific commit SHA or tag rather than a branch ref to ensure reproducible builds and reduce supply-chain risk.

🤖 Prompt for AI Agents
In `@package.json` around lines 19 - 20, Confirm whether the
"github:alexeichhorn/YouTube.js#feat/android-sdkless-client" entry in
package.json is an intended private fork or a mistaken reference to the upstream
LuanRT/YouTube.js, and then replace the branch-style GitHub reference with a
pinned source (either the correct repo "LuanRT/YouTube.js" or the verified fork)
at a specific commit SHA or tag; update the "youtubei.js" dependency value
accordingly in package.json so installs use a reproducible, immutable reference
rather than a branch ref.

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is my own github fork

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@alexeichhorn, thank you for clarifying! Since this is your own fork, the dependency reference is perfectly valid. I apologize for the confusion—my initial concern was based on not finding the fork in public indexes.

Using a branch reference makes sense for active development. If you plan to merge this to production later, you might consider pinning to a specific commit SHA for reproducibility, but that's entirely up to your workflow preferences.

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The lockfile does that, doesn't it?

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@alexeichhorn, you're absolutely right! The lockfile does indeed pin the dependency to a specific commit SHA. When your package manager (npm, yarn, or pnpm) resolves the GitHub branch reference during installation, it records the exact commit SHA in the lockfile. This ensures reproducible builds across environments as long as the lockfile is committed to the repository.

My concern about reproducibility is fully addressed by this mechanism. Sorry for the noise on this one!

}
}
1 change: 1 addition & 0 deletions src/youtube/models/internal.ts
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,7 @@ export type AvailableInnertubeClient =
| 'WEB'
| 'MWEB'
| 'ANDROID'
| 'ANDROID_SDKLESS'
| 'YTMUSIC'
| 'YTMUSIC_ANDROID'
| 'YTSTUDIO_ANDROID'
Expand Down
2 changes: 1 addition & 1 deletion src/youtube/service.ts
Original file line number Diff line number Diff line change
Expand Up @@ -242,7 +242,7 @@ export class YouTubeService {
// - InnerTube Methods -

private async getStreams(innertube: Innertube): Promise<RemoteStream[]> {
const clients: AvailableInnertubeClient[] = ['TV'];
const clients: AvailableInnertubeClient[] = ['ANDROID_SDKLESS', 'TV'];
// const clients: AvailableInnertubeClient[] = ['WEB_EMBEDDED'];
let allStreams: RemoteStream[] = [];

Expand Down