← Home

@privy-io/server-auth

81
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

payton-privysternhenriasta-liprivy-botahollenbachankushswar1joshnaviprivyandrewprivyadmin

Keywords

authenticationauthorizationidentityprivacyprivyuser dataweb3

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff source-size-tripled AI (source-diff): Bundled dist grows with vendored deps; expected for tsup build. ai
source-diff encoded-string-file:dist/index.mjs AI (source-diff): Same minified dual-format bundle output. ai
source-diff encoded-string-file:dist/index.js AI (source-diff): Minified tsup bundle with base58/encoding tables; stable build artifact for this SDK. ai
source-diff obfuscated-file:dist/dts/public-C1ux8ec7.d.mts AI (source-diff): TypeScript declaration file with long lines; not obfuscation. ai
source-diff obfuscated-file:dist/dts/public-BuHGq2ma.d.mts AI (source-diff): Rolled-up TypeScript declaration file; long lines from type merging. ai
source-diff obfuscated-file:dist/dts/public-DND8niKQ.d.mts AI (source-diff): Rolled-up TypeScript declaration file; long lines from type unions. ai
source-diff obfuscated-file:dist/dts/public-DQ5eO1J3.d.mts AI (source-diff): Rolled-up TypeScript declaration file; long lines from type merging. ai
source-diff obfuscated-file:dist/dts/public-BAGJecXe.d.mts AI (source-diff): TypeScript declaration file with long type lines; not obfuscated. ai
source-diff obfuscated-file:dist/dts/public-BBNB77KM.d.mts AI (source-diff): Rolled-up .d.mts type declaration; long lines from type merging. ai
source-diff obfuscated-file:dist/dts/public-C6oXB-Z2.d.mts AI (source-diff): Bundled TypeScript declaration file; long lines from type exports. ai
source-diff obfuscated-file:dist/dts/public-B2v7b6Xx.d.mts AI (source-diff): Bundled TypeScript declaration file; long lines expected. ai
publish-pattern dormant-publish AI (publish-pattern): Publisher privy-bot has 53 approved packages; dormancy reflects org workflow, not takeover. ai
source-diff obfuscated-file:dist/dts/public-BVWcMoQn.d.mts AI (source-diff): Bundled type declaration file; not obfuscation. ai
source-diff obfuscated-file:dist/dts/public-b_IxFqo5.d.mts AI (source-diff): Bundled type declarations; long lines from type exports. ai
phantom-deps phantom-dep:type-fest AI (phantom-deps): Type-only dep consumed at build time; not directly imported at runtime. ai
source-diff obfuscated-file:dist/dts/public-LncPfz4E.d.mts AI (source-diff): Rolled-up TypeScript declaration file. ai
phantom-deps phantom-dep:dotenv AI (phantom-deps): Used in test/config; declared runtime dep is harmless. ai
source-diff obfuscated-file:dist/esm/utils-DDjlFg8J.mjs AI (source-diff): Rollup-minified ESM bundle; mirrors CJS utils. ai
source-diff obfuscated-file:dist/cjs/utils-D9BZ7JAH.js AI (source-diff): Rollup-minified CJS bundle; utility/conversion functions. ai
source-diff obfuscated-file:dist/dts/public-DFSWLV8S.d.mts AI (source-diff): Generated TypeScript declaration file with long type lines. ai
source-diff obfuscated-file:dist/esm/utils-DRjOr8oi.mjs AI (source-diff): Rollup-minified ESM bundle; utility code. ai
source-diff obfuscated-file:dist/cjs/wallet-api/utils.js AI (source-diff): Rollup-minified CJS bundle; crypto utility code. ai
source-diff obfuscated-file:dist/cjs/utils-2_PewCqC.js AI (source-diff): Rollup-minified CJS bundle; readable utility code. ai
source-diff obfuscated-file:dist/esm/wallet-api/utils.mjs AI (source-diff): Rollup-minified ESM bundle; crypto utility code. ai
source-diff obfuscated-file:dist/cjs/client.js AI (source-diff): Rollup-minified CJS build output; readable business logic, no obfuscation. ai
source-diff obfuscated-file:dist/dts/public-Cpeu2dI0.d.mts AI (source-diff): TypeScript declaration file with long lines; not obfuscated. ai
source-diff large-new-source-files AI (source-diff): Build restructured from single files to Rollup chunks; expected for this package. ai
source-diff source-size-dropped AI (source-diff): Rollup bundling reduced file count/size; normal build tooling change. ai
source-diff obfuscated-file:dist/esm/utils-C7u2kNB0.mjs AI (source-diff): Rollup-minified ESM build output; readable utility functions. ai
source-diff obfuscated-file:dist/esm/wallet-api/index.mjs AI (source-diff): Rollup-minified ESM build output; readable business logic. ai
source-diff obfuscated-file:dist/esm/wallet-api/rpc/ethereum.mjs AI (source-diff): Rollup-minified ESM build output; readable business logic. ai
source-diff obfuscated-file:dist/esm/client.mjs AI (source-diff): Rollup-minified ESM build output; readable business logic. ai
source-diff obfuscated-file:dist/cjs/utils-b_q_8DAC.js AI (source-diff): Rollup-minified CJS build output; readable utility functions. ai
source-diff obfuscated-file:dist/cjs/wallet-api/index.js AI (source-diff): Rollup-minified CJS build output; readable business logic. ai
source-diff obfuscated-file:dist/cjs/wallet-api/rpc/ethereum.js AI (source-diff): Rollup-minified CJS build output; readable business logic. ai
source-diff obfuscated-file:dist/dts/index.d.mts AI (source-diff): TypeScript declaration file with long lines; not obfuscated. ai

Versions (showing 81 of 81)

Version Deps Published
1.32.5 15 / 24
1.32.4 15 / 24
1.32.3 15 / 24
1.32.2 15 / 24
1.32.1 15 / 24
1.32.0 15 / 24
1.31.1 15 / 24
1.31.0 15 / 24
1.30.0 14 / 24
1.29.0 14 / 24
1.28.8 14 / 24
1.28.7 14 / 24
1.28.6 14 / 24
1.28.5 14 / 24
1.28.4 14 / 24
1.28.3 14 / 24
1.28.2 14 / 24
1.28.1 14 / 24
1.28.0 14 / 24
1.27.4 14 / 24
1.27.3 14 / 24
1.27.2 14 / 24
1.27.1 14 / 24
1.27.0 14 / 24
1.26.2 14 / 24
1.26.1 14 / 24
1.26.0 12 / 26
1.25.1 12 / 26
1.25.0 12 / 24
1.24.0 12 / 24
1.23.0 12 / 24
1.22.2 12 / 24
1.22.1 12 / 24
1.20.2 12 / 23
1.20.1 12 / 23
1.20.0 12 / 23
1.19.3 11 / 24
1.19.2 11 / 11
1.19.1 11 / 11
1.19.0 11 / 11
1.18.12 11 / 11
1.18.11 11 / 11
1.18.10 11 / 11
1.18.9 11 / 12
1.18.8 11 / 12
1.18.7 11 / 12
1.18.6 11 / 12
1.18.5 11 / 12
1.18.4 11 / 14
1.18.3 11 / 14
1.18.2 11 / 14
1.18.1 11 / 14
1.18.0 11 / 14
1.17.2 11 / 13
1.16.2 10 / 13
1.15.3 9 / 13
1.15.2 9 / 13
1.15.0 9 / 12
1.14.4 7 / 12
1.14.3 7 / 12
1.14.2 7 / 11
1.14.1 7 / 11
1.14.0 7 / 11
1.13.1 7 / 11
1.13.0 7 / 11
1.12.2 7 / 11
1.12.1 7 / 11
1.12.0 7 / 11
1.11.1 7 / 11
1.11.0 7 / 11
1.10.0 6 / 11
1.9.7 6 / 11
1.9.6 6 / 11
1.9.5 6 / 11
1.9.4 6 / 11
1.9.3 6 / 11
1.9.2 6 / 11
1.9.1 6 / 11
1.9.0 6 / 11
1.8.0 6 / 11
1.7.4 6 / 11

v1.20.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.20.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.20.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.19.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.19.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.19.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.19.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.18.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.18.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.18.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.18.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.18.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.18.7

3 findings
HIGH Long encoded string in modified file: dist/index.js source-diff

Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: dist/index.mjs source-diff

Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.18.6

3 findings
HIGH Long encoded string in modified file: dist/index.js source-diff

Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: dist/index.mjs source-diff

Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.18.5

3 findings
HIGH Long encoded string in modified file: dist/index.js source-diff

Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: dist/index.mjs source-diff

Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.18.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.18.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.18.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.18.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.17.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.16.2

3 findings
HIGH Long encoded string in modified file: dist/index.js source-diff

Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: dist/index.mjs source-diff

Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.15.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.15.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.15.0

3 findings
HIGH Long encoded string in modified file: dist/index.js source-diff

Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: dist/index.mjs source-diff

Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.14.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.14.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.14.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.14.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.14.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.13.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.13.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.12.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.12.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.12.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.11.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.11.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.10.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.8.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.7.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.