@verii/crypto
Set of crypto functions used in Verii projects
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:cborg | AI (phantom-deps): cborg is declared in package.json and referenced in config; phantom-dep heuristic false positive for this package. | ai | |
| phantom-deps | phantom-dep:bigint-crypto-utils | AI (phantom-deps): bigint-crypto-utils is declared in package.json and referenced in config; phantom-dep heuristic false positive for this package. | ai | |
| semgrep | semgrep:hex-decode | AI (semgrep): Hex decode is used for multihash buffer construction (IPFS-style content addressing), a standard cryptographic pattern with no obfuscation or exfiltration. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Base64 decode is standard input parsing for a decryption function; no malicious payload hiding pattern present. | ai | |
| typosquat | typosquat.levenshtein:bcrypt | AI (typosquat): Scoped package @verii/crypto is a legitimate general crypto utility from the LFDT-Verii org; coincidental edit distance to bcrypt, not an impersonation. | ai |
Versions (showing 9 of 9)
| Version | Deps | Published |
|---|---|---|
| 1.1.3 | 9 / 12 | |
| 1.1.2 | 9 / 12 | |
| 1.1.1 | 9 / 12 | |
| 1.1.0 | 9 / 12 | |
| 1.0.9 | 9 / 11 | |
| 1.0.8 | 9 / 11 | |
| 1.0.7 | 9 / 11 | |
| 1.0.6 | 9 / 11 | |
| 1.0.0 | 9 / 11 |
v1.1.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.1.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.1.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.