@motebit/crypto-play-integrity
DEPRECATED — use @motebit/crypto-android-keystore for canonical sovereign-verifiable Android hardware attestation. This package was scaffolded against a pinned-Google-JWKS model that Google's Play Integrity API does not support (verification keys are per-
5
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
danielhakim
Keywords
motebitgoogleplay-integrityattestationandroidhardware-attestationjwtjwksverify
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@motebit/crypto | AI (dependencies): Internal monorepo sibling dependency; same publisher, same org scope, SLSA provenance present. | ai |