← Home

@auth0/angular-jwt

7
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

ncluervic-devenriquepinaece-oktapubaloktadougmiller-oktazak.noursthellerjamescgarrett-oktamadhuri.rm23willvedddavid.renaud.oktajeff.shumanauth0-osscodepeteziluvatariacococojoeauth0npmauth0brokkrhzalazaaguiarzcharlesrealbalmacedajulien.wollscheidcristiandoucesambegostevehobbsdevsandrinodimattialzychowskijoshcanhelprob.colesrosnovskydavidpatrick0widcketadamjmcgrathjim.andersoonfrederikprijcksergii.biienkotomauth0jpadillajesselerhamzeh_auth0greglopez

Keywords

angularangular 2authenticationjwt

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
maintainer-change maintainer-added AI (maintainer-change): Org-wide maintainer roster sync under auth0-oss, matches known Auth0 team accounts. ai
maintainer-change maintainer-removed AI (maintainer-change): Consistent with org account consolidation, not takeover. ai
provenance publisher-changed-stale AI (provenance): Long-stable publisher change to official org account, no unpublish/removal. ai
publish-pattern dormant-publish AI (publish-pattern): Dormancy explained by stable maintained low-churn library, no malicious diff. ai
phantom-deps phantom-dep:tslib AI (phantom-deps): tslib is a known implicit Angular runtime dependency. ai

Versions (showing 7 of 7)

Version Deps Published
5.2.0 1 / 0
5.1.2 1 / 0
5.1.1 1 / 0
5.1.0 1 / 0
5.0.2 1 / 0
5.0.1 1 / 0
5.0.0 1 / 0

v5.1.2

2 findings
MEDIUM Publisher changed: sambego → auth0-oss (on 2022-12-20, unremoved on npm for 1306d) provenance

This version was published by a different npm account (auth0-oss) than the most recent previously approved version (sambego) on 2022-12-20. It has since remained available on npm for 1306 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.1.1

2 findings
MEDIUM Publisher changed: sambego → auth0-oss (on 2022-12-15, unremoved on npm for 1312d) provenance

This version was published by a different npm account (auth0-oss) than the most recent previously approved version (sambego) on 2022-12-15. It has since remained available on npm for 1312 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.1.0

2 findings
MEDIUM Publisher changed: sambego → auth0-oss (on 2022-10-03, unremoved on npm for 1385d) provenance

This version was published by a different npm account (auth0-oss) than the most recent previously approved version (sambego) on 2022-10-03. It has since remained available on npm for 1385 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.