← Home

@auth/core

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

better-gustavobekacru

Keywords

authenticationauthjsjwtoauthoidcpasswordlessstandardvanillawebapi

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): CI publish retains SLSA attestation; gitHead absence is build-env metadata, not tampering. ai
source-diff obfuscated-file:lib/styles/index.js AI (source-diff): Minified CSS theme string, not obfuscation; stable for this package. ai
phantom-deps phantom-dep:preact AI (phantom-deps): preact is a genuine runtime dep for preact-render-to-string; referenced in config. ai
typosquat typosquat.levenshtein:cors AI (typosquat): Scoped @auth/core is the official Auth.js package, not a typo of cors. ai
semgrep semgrep:base64-decode AI (semgrep): Standard WebAuthn base64 encode/decode utility; stable for this package. ai
semgrep semgrep:shady-links-raw-ip AI (semgrep): 127.0.0.1 appears in documentation comments for Bungie provider setup. ai

Versions (showing 51 of 92)

View all versions
Version Deps Published
0.41.3 5 / 11
0.41.2 5 / 11
0.41.1 5 / 11
0.41.0 5 / 11
0.40.0 5 / 11
0.39.1 5 / 11
0.39.0 5 / 11
0.38.0 5 / 11
0.37.4 5 / 11
0.37.3 6 / 11
0.37.2 7 / 11
0.37.1 7 / 11
0.37.0 7 / 11
0.36.0 7 / 11
0.35.3 7 / 11
0.35.2 7 / 11
0.35.1 7 / 11
0.35.0 7 / 11
0.34.3 7 / 11
0.34.2 7 / 11
0.34.1 7 / 11
0.34.0 7 / 11
0.33.0 7 / 11
0.32.0 7 / 11
0.31.0 7 / 9
0.30.0 7 / 9
0.29.0 7 / 7
0.28.2 7 / 7
0.28.1 7 / 7
0.28.0 7 / 7
0.27.0 7 / 7
0.26.3 7 / 7
0.26.2 7 / 7
0.26.1 7 / 7
0.26.0 7 / 7
0.25.1 7 / 6
0.25.0 7 / 6
0.24.0 7 / 6
0.23.0 7 / 8
0.22.0 7 / 8
0.21.0 7 / 8
0.20.0 7 / 8
0.19.1 7 / 8
0.19.0 7 / 8
0.18.6 7 / 8
0.18.5 7 / 8
0.18.4 6 / 7
0.18.3 6 / 7
0.18.2 6 / 7
0.18.1 6 / 7
0.18.0 6 / 8

v0.41.3

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: better-gustavo.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.30.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.29.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.28.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.28.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.28.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.27.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.26.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.26.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.26.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.26.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.25.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.25.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.24.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.23.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.22.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.21.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.20.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.19.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.19.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.18.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.18.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.18.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.18.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.18.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.18.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.18.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.