← Home

@cichol/cryptography

A cryptography library providing various IES presets based on Web Crypto API for personal projects.

12
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

cichol

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@std/assert AI (dependencies): JSR standard library package; well-known, low-risk dependency stable across versions. ai
dependencies unvetted-dep:@std/encoding AI (dependencies): JSR standard library package; well-known, low-risk dependency stable across versions. ai
phantom-deps phantom-dep:@babel/runtime-corejs3 AI (phantom-deps): Babel runtime is injected by the transpiler at build time, not directly imported in source; stable false positive for this package. ai

Versions (showing 12 of 12)

Version Deps Published
6.1.3 5 / 0
6.1.2 5 / 0
6.1.1 5 / 0
6.1.0 5 / 0
6.0.1 4 / 0
6.0.0 4 / 0
5.4.5 4 / 0
5.4.4 4 / 0
5.4.3 4 / 0
5.4.2 4 / 0
5.4.1 4 / 0
5.4.0 4 / 0

v6.1.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.1.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.4.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.4.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.4.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.4.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.