← Home

@azure/msal-node

Microsoft Authentication Library for Node

100
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

azureadneagrawamanrath

Keywords

jstsnodeAADmsaloauth

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance no-provenance AI (provenance): Microsoft/AzureAD packages are published without Sigstore provenance; this is consistent across their npm releases and not a security risk for this well-known publisher. ai
semgrep semgrep:base64-decode AI (semgrep): Base64 decoding is a standard utility in an authentication library (e.g., for JWT parsing). No obfuscation or malicious payload concern. ai
semgrep semgrep:shady-links-raw-ip AI (semgrep): 169.254.169.254 is the standard Azure IMDS link-local endpoint, used by all Azure SDKs. Expected and documented behavior for this package. ai

Versions (showing 100 of 127)

Hide prereleases
Version Deps Published
5.4.2 2 / 16
5.4.1 2 / 16
5.4.0 2 / 16
5.3.1 2 / 16
5.3.0 2 / 16
5.2.5 2 / 16
5.2.4 2 / 16
5.2.3 2 / 16
5.2.2 2 / 16
5.2.1 2 / 16
5.2.0 2 / 16
5.1.5 2 / 16
5.1.4 3 / 17
5.1.3 3 / 17
5.1.2 3 / 17
5.1.1 3 / 17
5.1.0 3 / 17
5.0.6 3 / 17
5.0.5 3 / 17
5.0.4 3 / 17
5.0.3 3 / 17
5.0.2 3 / 17
5.0.1 3 / 17
3.8.10 3 / 17
3.8.9 3 / 17
3.8.8 3 / 17
3.8.7 3 / 17
3.8.6 3 / 17
3.8.5 3 / 17
3.8.4 3 / 17
3.8.3 3 / 17
3.8.2 3 / 17
3.8.1 3 / 17
3.8.0 3 / 17
3.7.4 3 / 17
3.7.3 3 / 17
3.7.2 3 / 17
3.7.1 3 / 17
3.7.0 3 / 17
3.6.4 3 / 17
3.6.3 3 / 17
3.6.2 3 / 17
3.6.1 3 / 17
3.6.0 3 / 17
3.5.3 3 / 17
3.5.2 3 / 16
3.5.1 3 / 16
3.5.0 3 / 16
3.4.1 3 / 16
3.4.0 3 / 16
3.3.0 3 / 16
3.2.3 3 / 16
3.2.2 3 / 16
3.2.1 3 / 16
3.2.0 3 / 16
3.1.0 3 / 16
3.0.1 3 / 16
2.16.3 3 / 16
2.16.2 3 / 16
2.16.1 3 / 16
2.16.0 3 / 16
2.15.0 3 / 16
2.14.0 3 / 16
2.13.1 3 / 17
2.13.0 3 / 17
2.12.0 3 / 17
2.11.1 3 / 17
2.11.0 3 / 17
2.10.0 3 / 17
2.9.2 3 / 17
2.6.6 3 / 17
2.6.5 3 / 17
2.6.4 3 / 17
2.6.3 3 / 17
2.6.2 3 / 17
2.6.1 3 / 17
2.6.0 3 / 17
2.5.1 3 / 17
2.5.0 3 / 17
2.4.0 3 / 17
2.3.0 3 / 17
2.2.0 3 / 17
2.1.0 3 / 17
2.0.2 3 / 16
2.0.1 3 / 16
2.0.0 3 / 16
1.18.4 3 / 10
1.18.3 3 / 10
1.18.2 3 / 10
1.18.1 3 / 10
1.18.0 3 / 10
1.17.3 3 / 10
1.17.2 3 / 10
1.17.1 3 / 10
1.17.0 3 / 10
1.16.0 3 / 10
1.15.0 3 / 10
1.14.6 3 / 10
1.14.5 3 / 10
1.14.4 3 / 10
Showing 100 of 127 Next page →

v5.4.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.4.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.4.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.3.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.1.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.