← Home

@supabase/auth-js

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

etienne_supamandarini

Keywords

authsupabaseauthauthentication

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@supabase/node-fetch AI (dependencies): @supabase/node-fetch is Supabase's own maintained fork of node-fetch, a stable and intentional dependency used across the Supabase ecosystem. Not a supply chain risk. ai
semgrep semgrep:api-obfuscation-reflect AI (semgrep): Reflect.get() is used inside a Proxy trap handler to return actual values for symbols — standard idiomatic JavaScript, not obfuscation. Stable false positive for this package. ai

Versions (showing 51 of 107)

View all versions
Version Deps Published
2.110.9 1 / 12
2.110.8 1 / 12
2.110.7 1 / 12
2.110.6 1 / 12
2.110.5 1 / 12
2.110.4 1 / 12
2.110.3 1 / 12
2.110.2 1 / 12
2.110.1 1 / 12
2.110.0 1 / 12
2.109.0 1 / 12
2.108.2 1 / 12
2.108.1 1 / 12
2.108.0 1 / 12
2.107.0 1 / 12
2.106.0 1 / 1
2.105.4 1 / 1
2.105.3 1 / 1
2.105.2 1 / 1
2.105.1 1 / 1
2.105.0 1 / 1
2.104.1 1 / 1
2.104.0 1 / 1
2.103.3 1 / 1
2.103.2 1 / 1
2.103.1 1 / 1
2.103.0 1 / 1
2.102.1 1 / 1
2.102.0 1 / 1
2.101.1 1 / 1
2.101.0 1 / 1
2.100.1 1 / 1
2.100.0 1 / 1
2.99.3 1 / 1
2.99.2 1 / 1
2.99.1 1 / 1
2.99.0 1 / 1
2.98.0 1 / 1
2.97.0 1 / 1
2.96.0 1 / 1
2.95.3 1 / 1
2.95.2 1 / 1
2.95.1 1 / 1
2.95.0 1 / 1
2.94.1 1 / 1
2.94.0 1 / 1
2.93.3 1 / 1
2.93.2 1 / 1
2.93.1 1 / 1
2.93.0 1 / 1
2.92.0 1 / 1

v2.110.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.110.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.110.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.110.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.110.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.110.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.110.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.110.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.110.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.110.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.109.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.