@furystack/auth-jwt
JWT Authentication Provider for FuryStack
15
Versions
GPL-2.0
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
gallayl
Keywords
FuryStackauthenticationJWTBearertokenlogin
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Transition from personal account to GitHub Actions CI/CD is documented by SLSA provenance; stable for this package. | ai | |
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): Raw IP is 127.0.0.1 in an integration test fixture — not a network exfiltration risk. | ai | |
| semgrep | semgrep:hex-decode | AI (semgrep): Hex decode used for timing-safe fingerprint comparison in JWT token service — legitimate cryptographic pattern. | ai |