@fluojs/jwt
HTTP-agnostic JWT signing and verification core for Fluo authentication.
3
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
ayden94
Keywords
fluojwtauthenticationtokensigningverification
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| typosquat | typosquat.levenshtein:jest | AI (typosquat): @fluojs/jwt is a scoped JWT library, not a typo of jest; name reflects its JWT purpose. | ai | |
| typosquat | typosquat.levenshtein:got | AI (typosquat): @fluojs/jwt is a scoped JWT library; edit-distance match to 'got' is coincidental. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): @fluojs/jwt is a scoped JWT library; edit-distance match to 'joi' is coincidental. | ai | |
| phantom-deps | phantom-dep:@fluojs/di | AI (phantom-deps): @fluojs/di is a declared runtime dep from the same monorepo; phantom detection is a false positive here. | ai |
v1.0.2
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.1
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.0
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.