@imtbl/auth-next-server
Immutable Auth.js v5 integration for Next.js - Server-side utilities
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions CI publishing with SLSA attestation; legitimate automation change for Immutable SDK. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): JWT token parsing pattern; decoding base64 claims to read exp field is standard and benign for this auth library. | ai |
Versions (showing 16 of 16)
| Version | Deps | Published |
|---|---|---|
| 2.23.0 | 0 / 10 | |
| 2.22.0 | 0 / 10 | |
| 2.21.0 | 0 / 10 | |
| 2.20.2 | 0 / 10 | |
| 2.20.1 | 0 / 10 | |
| 2.20.0 | 0 / 10 | |
| 2.19.0 | 0 / 10 | |
| 2.18.0 | 0 / 10 | |
| 2.17.1 | 0 / 10 | |
| 2.17.0 | 0 / 10 | |
| 2.16.0 | 0 / 10 | |
| 2.15.0 | 0 / 10 | |
| 2.14.3 | 0 / 10 | |
| 2.14.0 | 0 / 10 | |
| 2.13.0 | 0 / 10 | |
| 2.12.7 | 0 / 10 |
v2.23.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.22.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.21.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.20.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.