← Home

@otplib/totp

10
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

geraldyeo

Keywords

otptotprfc62382famfatime-basedone-time-passwordauthenticatorgoogle-authenticator

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Publisher changed to GitHub Actions CI/CD pipeline, corroborated by SLSA provenance attestation. This is a legitimate and documented publishing transition for this package. ai
provenance slsa-provenance AI (provenance): Package has SLSA provenance attestation via Sigstore; this is a positive supply chain integrity signal and should not trigger review. ai
typosquat typosquat.levenshtein:got AI (typosquat): @otplib/totp is a scoped TOTP implementation package in the otplib monorepo; the levenshtein match against 'got' is purely coincidental and not a typosquat. ai
dependencies unvetted-dep:@otplib/uri AI (dependencies): @otplib/uri is a sibling package in the same otplib monorepo, pinned to the same version. Not a third-party risk. ai
dependencies unvetted-dep:@otplib/core AI (dependencies): @otplib/core is a sibling package in the same otplib monorepo, pinned to the same version. Not a third-party risk. ai
dependencies unvetted-dep:@otplib/hotp AI (dependencies): @otplib/hotp is a sibling package in the same otplib monorepo, pinned to the same version. Not a third-party risk. ai

Versions (showing 10 of 10)

Version Deps Published
13.4.1 3 / 5
13.4.0 3 / 5
13.3.0 3 / 5
13.2.1 3 / 5
13.2.0 3 / 5
13.1.1 3 / 5
13.1.0 3 / 5
13.0.2 3 / 5
13.0.1 3 / 5
13.0.0 3 / 5

v13.4.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.4.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.