← Home

@clerk/backend

85
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

colinclerkbradenclerknikosdouvlisjescalanbrkalow-clerkdominic-clerk

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff encoded-string-file:dist/fixtures/index.d.ts AI (source-diff): Test fixture file containing mock PEM/JWK keys for JWT testing — standard for an auth backend library. Not obfuscated payloads. ai
provenance publisher-changed AI (provenance): dominic-clerk is part of the Clerk org team; routine maintainer rotation confirmed by SLSA provenance from CI/CD. ai
maintainer-change maintainer-added AI (maintainer-change): dominic-clerk is a known Clerk org member with 43 approved packages; legitimate team addition. ai
dependencies unvetted-dep:@clerk/types AI (dependencies): @clerk/types is a first-party Clerk package; it is a stable, expected dependency of @clerk/backend across all versions. ai
dependencies unvetted-dep:standardwebhooks AI (dependencies): standardwebhooks is a legitimate open-standard webhook verification library; its use in @clerk/backend is expected and appropriate. Not a security concern. ai
phantom-deps phantom-dep:tslib AI (phantom-deps): tslib is a standard TypeScript runtime helper commonly used as an implicit dependency in compiled TS packages; stable false positive for this package. ai

Versions (showing 85 of 85)

Version Deps Published
3.13.1 3 / 5
3.13.0 3 / 5
3.12.0 3 / 5
3.11.7 3 / 5
3.11.6 3 / 5
3.11.5 3 / 5
3.11.4 3 / 5
3.11.3 3 / 5
3.11.2 3 / 5
3.11.1 3 / 5
3.11.0 3 / 5
3.10.0 3 / 5
3.9.0 3 / 5
3.8.5 3 / 5
3.8.4 3 / 6
3.8.3 3 / 6
3.8.2 3 / 6
3.8.1 3 / 6
3.8.0 3 / 6
3.7.1 3 / 6
3.7.0 3 / 6
3.6.1 3 / 6
3.6.0 3 / 6
3.5.0 3 / 6
3.4.14 3 / 6
3.4.13 3 / 6
3.4.12 3 / 6
3.4.11 3 / 6
3.4.10 3 / 6
3.4.9 3 / 6
3.4.8 3 / 6
3.4.7 3 / 6
3.4.6 3 / 6
3.4.5 3 / 6
3.4.4 3 / 6
3.4.3 3 / 6
3.4.2 3 / 6
3.4.1 3 / 6
3.4.0 3 / 6
3.3.0 3 / 6
3.2.14 3 / 6
3.2.12 3 / 6
3.2.11 3 / 6
3.2.10 3 / 6
3.2.9 3 / 6
3.2.3 3 / 6
2.33.6 4 / 6
2.33.5 4 / 6
2.33.4 4 / 6
2.33.3 4 / 6
2.33.1 4 / 6
2.33.0 4 / 6
2.32.2 4 / 6
2.32.1 4 / 6
2.32.0 4 / 6
2.31.2 4 / 6
2.31.1 4 / 6
2.31.0 4 / 6
2.30.1 4 / 6
2.30.0 4 / 6
2.29.7 4 / 6
2.29.6 4 / 6
2.29.5 4 / 6
2.29.4 4 / 6
2.29.3 4 / 6
2.29.2 4 / 6
2.29.1 4 / 6
2.29.0 5 / 5
2.28.0 5 / 5
2.27.1 5 / 5
2.27.0 5 / 5
2.26.0 5 / 5
2.25.1 5 / 5
2.25.0 5 / 5
2.24.0 5 / 5
2.23.2 5 / 5
2.23.1 5 / 5
2.23.0 5 / 5
2.22.0 5 / 5
2.21.0 5 / 5
2.20.1 5 / 5
2.20.0 5 / 5
2.19.3 5 / 5
2.19.2 5 / 5
2.19.1 5 / 5

v3.13.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.13.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.12.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.11.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.11.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.11.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.11.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.11.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.11.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.11.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.11.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.10.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.9.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.8.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.33.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.