← Home

@privy-io/public-api

24
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

payton-privysternhenriasta-liprivy-botahollenbachankushswar1joshnaviprivyandrewprivyadmin

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/cjs/schemas/wallet-api/index.js AI (source-diff): Minified build output; benign re-export barrel. ai
source-diff obfuscated-file:dist/cjs/schemas/policy.js AI (source-diff): Minified zod policy schema, no malicious behavior. ai
source-diff obfuscated-file:dist/cjs/schemas/passkey.js AI (source-diff): Minified zod schemas; build output. ai
source-diff obfuscated-file:dist/cjs/index.js AI (source-diff): Rollup/terser minified dist output, not obfuscation; stable for this build pipeline. ai
source-diff obfuscated-file:dist/cjs/routes/index.js AI (source-diff): Minified re-export barrel; build output. ai
source-diff obfuscated-file:dist/cjs/schemas/index.js AI (source-diff): Minified schema barrel; build output. ai
source-diff obfuscated-file:dist/cjs/schemas/wallet-api/wallets/index.js AI (source-diff): Standard rollup-minified bundle output; content is readable zod schema definitions, not obfuscated malware. ai
source-diff obfuscated-file:dist/esm/schemas/wallet-api/wallets/spark/index.mjs AI (source-diff): Standard rollup-minified ESM bundle; content is readable zod schema definitions, not obfuscated malware. ai
source-diff obfuscated-file:dist/esm/schemas/wallet-api/wallets/index.mjs AI (source-diff): Standard rollup-minified ESM bundle; content is readable zod schema definitions, not obfuscated malware. ai
source-diff obfuscated-file:dist/cjs/schemas/wallet-api/wallets/spark/index.js AI (source-diff): Standard rollup-minified bundle output; content is readable zod schema definitions, not obfuscated malware. ai

Versions (showing 24 of 124)

Version Deps Published
2.9.2 4 / 4
2.9.1 4 / 4
2.9.0 4 / 4
2.8.5 4 / 4
2.8.4 4 / 4
2.8.3 4 / 4
2.8.2 4 / 4
2.8.1 4 / 4
2.8.0 4 / 4
2.7.1 4 / 4
2.7.0 4 / 4
2.6.3 4 / 4
2.6.2 4 / 4
2.6.1 4 / 3
2.6.0 4 / 3
2.5.1 4 / 3
2.5.0 4 / 3
2.4.4 4 / 3
2.4.3 4 / 3
2.4.2 4 / 3
2.4.1 4 / 3
2.4.0 4 / 3
2.3.0 4 / 3
2.2.0 4 / 3

v2.9.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.9.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.9.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.8.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.8.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.8.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.8.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.8.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.8.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.7.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.6.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.6.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.6.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.4.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.4.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.4.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.4.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.