@imtbl/auth
Authentication SDK for Immutable
23
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
tcurtin88alex-immutableimmutable-npm
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Immutable migrated publishing to GitHub Actions CI; SLSA attestation confirms legitimate pipeline. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): platform-sa removal reflects org-level CI migration; SLSA provenance confirms integrity. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Base64 decoding in jwt.ts is standard JWT payload parsing; not a malicious pattern for an auth SDK. | ai |
Versions (showing 23 of 23)
| Version | Deps | Published |
|---|---|---|
| 2.23.0 | 3 / 10 | |
| 2.22.0 | 4 / 10 | |
| 2.21.0 | 4 / 10 | |
| 2.20.2 | 4 / 10 | |
| 2.20.1 | 4 / 10 | |
| 2.20.0 | 4 / 10 | |
| 2.19.0 | 4 / 10 | |
| 2.18.0 | 4 / 10 | |
| 2.17.1 | 4 / 10 | |
| 2.17.0 | 4 / 10 | |
| 2.16.0 | 4 / 10 | |
| 2.15.0 | 4 / 10 | |
| 2.14.3 | 4 / 10 | |
| 2.14.0 | 4 / 10 | |
| 2.13.0 | 4 / 10 | |
| 2.12.7 | 4 / 10 | |
| 2.12.6 | 4 / 10 | |
| 2.12.5 | 4 / 10 | |
| 2.12.4 | 4 / 10 | |
| 2.12.3 | 4 / 10 | |
| 2.12.2 | 4 / 10 | |
| 2.12.1 | 3 / 10 | |
| 2.12.0 | 3 / 10 |
v2.23.0
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.22.0
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.21.0
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.20.2
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.