← Home

@cubist-labs/cubesigner-sdk-key-import

Client-side key-import machinery for CubeSigner

30
Versions
MIT OR Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

mlfbrown_cubistamilicevicnoetzli

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff encoded-string-file:src/import.ts AI (source-diff): Same AWS Nitro CA cert in source; stable false positive for this package. ai
source-diff encoded-string-file:dist/import.js AI (source-diff): Long encoded string is the AWS Nitro Enclaves root CA cert, publicly documented and expected for enclave attestation verification. ai
semgrep semgrep:base64-decode AI (semgrep): Decoding a server-returned public key into Uint8Array; standard crypto operation, not a payload obfuscation pattern. ai

Versions (showing 30 of 30)

Version Deps Published
0.4.254 8 / 1
0.4.252 8 / 1
0.4.250 8 / 1
0.4.247 8 / 1
0.4.246 8 / 1
0.4.244 8 / 1
0.4.241 8 / 1
0.4.239 8 / 1
0.4.237 8 / 1
0.4.236 8 / 1
0.4.231 8 / 1
0.4.229 8 / 1
0.4.228 8 / 1
0.4.227 8 / 1
0.4.226 8 / 1
0.4.224 8 / 1
0.4.223 8 / 1
0.4.222 8 / 1
0.4.221 8 / 1
0.4.219 8 / 1
0.4.218 8 / 1
0.4.217 8 / 1
0.4.214 8 / 1
0.4.209 8 / 1
0.4.208 8 / 1
0.4.206 8 / 1
0.4.205 8 / 1
0.4.204 8 / 1
0.4.201 8 / 1
0.4.199 8 / 1