← Home

@cerbos/hub

Client library for interacting with Cerbos Hub from server-side Node.js applications

17
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

alexolivierahaines

Keywords

CerbosCerbos Hubauthorizationaccess controlrolespermissionspolicysecurityrole-based access controlRBACattribute-based access controlABACpolicy decision pointPDP

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff encoded-string-file:lib/protobuf/cerbos/cloud/store/v1/store_pb.js AI (source-diff): Base64 protobuf file descriptor passed to fileDesc(); standard @bufbuild/protobuf codegen pattern. ai
source-diff encoded-string-file:src/protobuf/cerbos/cloud/apikey/v1/apikey_pb.ts AI (source-diff): Base64-encoded protobuf file descriptor passed to fileDesc(); standard @bufbuild/protobuf pattern, not obfuscation. ai
source-diff encoded-string-file:src/protobuf/cerbos/cloud/auth/v1/auth_pb.ts AI (source-diff): Base64-encoded protobuf file descriptor; same benign @bufbuild/protobuf pattern. ai
source-diff encoded-string-file:src/protobuf/cerbos/cloud/store/v1/store_pb.ts AI (source-diff): Base64-encoded protobuf file descriptor; same benign @bufbuild/protobuf pattern. ai
source-diff encoded-string-file:src/protobuf/buf/validate/validate_pb.ts AI (source-diff): Base64-encoded protobuf file descriptor; same benign @bufbuild/protobuf pattern. ai
source-diff encoded-string-file:lib/protobuf/cerbos/cloud/apikey/v1/apikey_pb.js AI (source-diff): Base64 protobuf file descriptor generated by @bufbuild/protobuf toolchain; stable pattern across all versions of this package. ai
typosquat typosquat.levenshtein:yup AI (typosquat): Scoped @cerbos/hub is a legitimate Cerbos SDK package; Levenshtein match to 'yup' is a false positive. ai

Versions (showing 17 of 17)

Version Deps Published
0.6.0 5 / 0
0.5.6 5 / 0
0.5.5 5 / 0
0.5.4 5 / 0
0.5.3 5 / 0
0.5.2 5 / 0
0.5.1 6 / 1
0.5.0 6 / 1
0.4.0 6 / 1
0.3.0 5 / 1
0.2.4 5 / 1
0.2.3 5 / 1
0.2.2 5 / 1
0.2.1 6 / 1
0.2.0 6 / 1
0.1.1 6 / 1
0.1.0 6 / 1

v0.6.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.