← Home

@clerk/astro

Clerk SDK for Astro

50
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

colinclerkbradenclerknikosdouvlisjescalanbrkalow-clerkdominic-clerk

Keywords

authauthenticationastroastro-integrationclerktypescriptpasswordlessastro-componentwithastro

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff source-size-tripled AI (source-diff): Explained by large generated .d.ts type bundle, not injected payload. ai
maintainer-change maintainer-added AI (maintainer-change): Routine Clerk team maintainer rotation, provenance unchanged/strong. ai
maintainer-change maintainer-removed AI (maintainer-change): Paired with new Clerk maintainer add; normal handoff. ai
dependencies unvetted-dep:@clerk/types AI (dependencies): @clerk/types is a first-party package in the same @clerk namespace; it is a stable, expected dependency for Clerk SDK packages. ai
publish-pattern dormant-publish AI (publish-pattern): Package has SLSA provenance attestation confirming CI/CD publication; Clerk uses automated release pipelines that may have gaps between releases. Dormancy alone is not a risk signal here. ai
publish-pattern new-deps-added AI (publish-pattern): @clerk/types is a first-party Clerk namespace package — a natural dependency for a Clerk SDK. Not analogous to supply-chain attack vectors involving third-party packages. ai
provenance slsa-provenance AI (provenance): Package consistently publishes with SLSA provenance via CI/CD; this is a positive signal that generalizes across versions. ai

Versions (showing 50 of 50)

Version Deps Published
4.0.2 4 / 2
4.0.1 4 / 2
4.0.0 4 / 2
3.4.20 4 / 2
3.4.19 4 / 2
3.4.18 4 / 2
3.4.17 4 / 2
3.4.16 4 / 2
3.4.15 4 / 2
3.4.14 4 / 2
3.4.13 4 / 2
3.4.12 4 / 2
3.4.11 4 / 2
3.4.10 4 / 2
3.4.9 4 / 2
3.4.8 4 / 2
3.4.7 4 / 2
3.4.6 4 / 2
3.4.5 4 / 2
3.4.4 4 / 2
3.4.3 4 / 2
3.4.2 4 / 2
3.4.1 4 / 2
3.4.0 4 / 2
3.3.3 4 / 2
3.3.2 4 / 2
3.3.1 4 / 2
3.3.0 4 / 2
3.2.6 4 / 2
3.2.5 4 / 2
3.2.4 4 / 2
3.2.3 4 / 2
3.2.2 4 / 2
3.2.1 4 / 2
3.2.0 4 / 2
3.1.0 4 / 2
3.0.23 4 / 2
3.0.22 4 / 2
3.0.21 4 / 2
3.0.20 4 / 2
3.0.19 4 / 2
3.0.18 4 / 2
3.0.17 4 / 2
3.0.16 4 / 2
3.0.15 4 / 2
2.17.14 5 / 1
2.17.13 5 / 1
2.17.12 5 / 1
2.17.11 5 / 1
1.5.7 5 / 3

v4.0.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.4.20

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.4.19

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.4.18

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.4.17

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.4.16

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.4.15

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.4.14

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.4.13

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.4.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.4.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.4.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.4.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.17.14

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.