← Home

@asgardeo/auth-spa

Asgardeo Auth SPA SDK to be used in Single-Page Applications.

4
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

wso2-org

Keywords

Asgardeoauthenticationoidcoauth2spa

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff encoded-string-file:dist/asgardeo-spa.production.js AI (source-diff): Same rollup-plugin-web-worker-loader pattern; stable build artifact. ai
source-diff encoded-string-file:dist/asgardeo-spa.production.esm.js AI (source-diff): Base64 is rollup-plugin-web-worker-loader inlining worker code; stable build artifact for this package. ai
source-diff encoded-string-file:dist/polyfilled/asgardeo-spa.production.esm.js AI (source-diff): Same rollup-plugin-web-worker-loader pattern; stable build artifact. ai
source-diff encoded-string-file:dist/polyfilled/asgardeo-spa.production.min.js AI (source-diff): Same rollup-plugin-web-worker-loader pattern; stable build artifact. ai
source-diff encoded-string-file:dist/polyfilled/asgardeo-spa.production.js AI (source-diff): Same rollup-plugin-web-worker-loader pattern; stable build artifact. ai
source-diff encoded-string-file:dist/asgardeo-spa.production.min.js AI (source-diff): Same rollup-plugin-web-worker-loader pattern; stable build artifact. ai
phantom-deps phantom-dep:await-semaphore AI (phantom-deps): await-semaphore is explicitly declared as a runtime dependency; phantom-dep heuristic is a false positive here. ai

Versions (showing 4 of 4)

Version Deps Published
3.5.2 8 / 27
3.5.1 8 / 27
3.5.0 8 / 27
3.4.0 8 / 27

v3.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.