← Home

@better-auth/sso

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

bekacrubetter-gustavo

Keywords

ssoauthsamloauthoidcopenidopenid connectsingle sign ontypescriptbetter-auth

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Migrated to GitHub Actions CI/CD publishing with SLSA provenance; stable for this org. ai
semgrep semgrep:base64-decode AI (semgrep): Base64 decode used only for error-logging of SAML responses; no payload execution or exfiltration. ai
typosquat typosquat.levenshtein:qs AI (typosquat): Scoped package @better-auth/sso is clearly not a typosquat of qs; edit-distance match is coincidental. ai
dependencies unvetted-dep:samlify AI (dependencies): samlify is the standard SAML library for Node.js; expected dependency for an SSO/SAML plugin. ai

Versions (showing 51 of 88)

View all versions
Version Deps Published
1.6.25 5 / 9
1.6.24 5 / 9
1.6.23 5 / 9
1.6.22 5 / 9
1.6.21 5 / 9
1.6.20 5 / 9
1.6.19 5 / 9
1.6.18 5 / 9
1.6.17 5 / 9
1.6.16 5 / 9
1.6.15 5 / 9
1.6.14 5 / 9
1.6.13 5 / 9
1.6.12 5 / 9
1.6.11 5 / 9
1.6.10 5 / 9
1.6.9 5 / 9
1.6.8 5 / 9
1.6.7 5 / 9
1.6.6 5 / 9
1.6.5 5 / 9
1.6.4 5 / 9
1.6.3 5 / 9
1.6.2 5 / 9
1.6.1 5 / 9
1.6.0 5 / 9
1.5.6 7 / 9
1.5.5 7 / 9
1.5.4 6 / 9
1.5.3 6 / 9
1.5.2 6 / 9
1.5.1 6 / 9
1.5.0 6 / 9
1.4.22 6 / 8
1.4.21 6 / 8
1.4.20 6 / 8
1.4.19 6 / 8
1.4.18 6 / 8
1.4.17 6 / 8
1.4.16 6 / 8
1.4.15 6 / 8
1.4.14 6 / 8
1.4.13 6 / 8
1.4.12 6 / 8
1.4.11 6 / 8
1.4.10 5 / 9
1.4.9 6 / 8
1.4.8 6 / 8
1.4.7 5 / 8
1.4.6 5 / 8
1.4.5 5 / 8

v1.6.25

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.6.24

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.6.23

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.