← Home

@auth0/auth0-checkmate

A command line tool for checking configuration of your Auth0 tenant

4
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

auth0-ossauth0npmauth0brokkrjesseleoktajeffoktajeffbsmith-auth0sanjay.manikandhanniltorresatkohenry.mcardlenicolas.villalobosadam-mcgrath_oktajosecarlos-chavez_atkotj.oktasgarcia-atkoroger.chanmaaantonelewisbyrne-oktatarunpreet.kaur

Keywords

auth0analyzerconfiguration

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:shady-links-raw-ip AI (semgrep): The raw IP appears only in a code comment explaining SSRF prevention; no actual request to a raw IP is made. ai
semgrep semgrep:dynamic-require AI (semgrep): Dynamic require is used in the analyzer plugin loader to load files by resolved path — intentional and stable for this package. ai
dependencies unvetted-dep:handlebars AI (dependencies): Handlebars is a well-known templating library; ^4.7.8 is the current patched version with no active advisories. ai

Versions (showing 4 of 4)

Version Deps Published
1.7.5 16 / 7
1.7.3 16 / 7
1.6.18 16 / 7
1.6.17 16 / 7

v1.7.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.7.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.6.18

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.6.17

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.