@wovin/crypto
A secure, isomorphic TypeScript library providing cryptographic primitives (AES, ECDH, Ed25519) and mnemonic-based key derivation. Implements PBKDF2-HMAC-SHA512 for key stretching and supports multiple key derivation paths (ECDH, EdDSA, HKDF).
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:iso-signatures | AI (dependencies): Pinned version used in a crypto utility package; no malware indicators; stable dependency pattern for this package. | ai | |
| dependencies | unvetted-dep:besonders-logger | AI (dependencies): Logging utility dependency; pinned version, no install scripts or malware indicators; stable for this package. | ai | |
| phantom-deps | phantom-dep:iso-base | AI (phantom-deps): Referenced in config files; bundled output may consume it indirectly. | ai | |
| phantom-deps | phantom-dep:@noble/hashes | AI (phantom-deps): Crypto utility likely consumed transitively or via bundled output. | ai | |
| typosquat | typosquat.levenshtein:bcrypt | AI (typosquat): Scoped @wovin org package; Levenshtein match to bcrypt is coincidental, not impersonation. | ai | |
| phantom-deps | phantom-dep:@stablelib/ed25519 | AI (phantom-deps): Ed25519 dep likely consumed in bundled output for the ./ed25519 export. | ai | |
| phantom-deps | phantom-dep:besonders-logger | AI (phantom-deps): Logger referenced in config; may be conditionally imported. | ai | |
| phantom-deps | phantom-dep:@wovin/core | AI (phantom-deps): Same org scope; phantom-dep heuristic unreliable for monorepo sibling packages. | ai |
Versions (showing 7 of 7)
| Version | Deps | Published |
|---|---|---|
| 0.1.36 | 8 / 5 | |
| 0.1.24 | 8 / 5 | |
| 0.1.23 | 8 / 5 | |
| 0.1.22 | 8 / 5 | |
| 0.1.21 | 8 / 5 | |
| 0.1.20 | 8 / 5 | |
| 0.1.19 | 8 / 5 |
v0.1.36
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.
v0.1.24
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.
v0.1.23
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.
v0.1.22
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.
v0.1.21
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.
v0.1.20
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.
v0.1.19
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.