auth0
17
Versions
—
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
auth0-ossauth0npmauth0brokkrjesseleoktajeffoktajeffbsmith-auth0sanjay.manikandhannirjoniltorresatkojaskirat_atkohenry.mcardlenicolas.villaloboschoahjosecarlos-chavez_atkoskatkotj.oktasgarcia-atkoroger.chanmaaantonelewisbyrne-oktatarunpreet.kaur
Keywords
auth0authenticationloginauthjwtmanagement apijson web token
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-added | AI (maintainer-change): Routine team rotation on established Auth0 org package, no other malicious signal. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Consistent with org-managed maintainer list churn, no takeover indicators. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size increase is from dual CJS+ESM build output and large generated type declaration files, not injected payloads. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): auth0-legacy is an npm alias for auth0@^4.37.1 (the prior vetted version), used as a legacy compatibility shim in the v5 major release. | ai | |
| source-diff | obfuscated-file:dist/cjs/management/__generated/models/index.js | AI (source-diff): Auto-generated TS enum exports, not obfuscation; stable pattern for this package. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Established Auth0 official SDK; SLSA provenance confirms CI/CD publish, not account takeover. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Auth0 SDK regularly adds new API client files in major/minor releases; no injected code indicators. | ai | |
| dependencies | unvetted-dep:auth0-legacy | AI (dependencies): auth0-legacy is an npm alias for auth0@^4.27.0 (same package, prior major); used for legacy compat, not a third-party risk. | ai |
Versions (showing 17 of 17)
| Version | Deps | Published |
|---|---|---|
| 6.1.0 | 3 / 24 | |
| 6.0.0 | 3 / 24 | |
| 5.14.0 | 3 / 24 | |
| 5.12.0 | 3 / 24 | |
| 5.11.0 | 3 / 24 | |
| 5.10.0 | 3 / 24 | |
| 5.9.1 | 3 / 24 | |
| 5.9.0 | 3 / 24 | |
| 5.8.0 | 3 / 24 | |
| 5.7.0 | 3 / 24 | |
| 5.6.0 | 3 / 24 | |
| 5.1.0 | 3 / 24 | |
| 4.37.1 | 3 / 26 | |
| 4.37.0 | 3 / 27 | |
| 4.36.0 | 3 / 27 | |
| 4.35.0 | 3 / 27 | |
| 4.34.0 | 3 / 27 |
v6.1.0
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.0.0
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.14.0
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.1.0
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.