@phantom/auth2
Shared core utilities for the Auth2 OAuth2 PKCE flow
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@phantom/openapi-wallet-service | AI (phantom-deps): Same-org workspace dependency; monorepo pattern, stable across versions. | ai | |
| phantom-deps | phantom-dep:axios | AI (phantom-deps): Standard HTTP client; expected in OAuth2 PKCE flow implementations. | ai | |
| phantom-deps | phantom-dep:buffer | AI (phantom-deps): Standard Node.js polyfill; used in crypto operations, common in auth libraries. | ai | |
| phantom-deps | phantom-dep:@phantom/crypto | AI (phantom-deps): Same-org workspace dependency; monorepo pattern, stable across versions. | ai | |
| phantom-deps | phantom-dep:@phantom/base64url | AI (phantom-deps): Same-org workspace dependency; monorepo pattern, stable across versions. | ai | |
| phantom-deps | phantom-dep:bs58 | AI (phantom-deps): Standard base58 encoding library; used in crypto workflows, common in auth packages. | ai | |
| dependencies | unvetted-dep:@phantom/base64url | AI (dependencies): Internal @phantom scoped sibling package from the same Phantom SDK monorepo. | ai | |
| dependencies | unvetted-dep:@phantom/sdk-types | AI (dependencies): Internal @phantom scoped sibling package from the same Phantom SDK monorepo. | ai | |
| dependencies | unvetted-dep:@phantom/openapi-wallet-service | AI (dependencies): Internal @phantom scoped package from the same Phantom SDK org. | ai | |
| dependencies | unvetted-dep:@phantom/crypto | AI (dependencies): Internal @phantom scoped sibling package from the same Phantom SDK monorepo. | ai |
Versions (showing 6 of 6)
| Version | Deps | Published |
|---|---|---|
| 2.0.2 | 8 / 10 | |
| 2.0.1 | 8 / 10 | |
| 2.0.0 | 8 / 10 | |
| 1.0.2 | 6 / 11 | |
| 1.0.1 | 6 / 11 | |
| 1.0.0 | 6 / 11 |
v2.0.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.