← Home

passport-auth0

1
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

auth0-ossziluvatariacopubaloktaauth0npmauth0brokkrhzalazaaguiarzcharlesreancluerjulien.wollscheidcristiandoucesambegosandrinodimattialzychowskidavidpatrick0sergii.biienkojpadillajesselerhamzeh_auth0oktajeffoktajeffdavid.renaud.oktamadhuri.rm23npirani_oktasoumya.bodavulajamescgarrett-oktasthellerjfromanielloedgarchirivella-oktasanjay.manikandhanrithuc23enriquepinasgarcia-atkoroger.chanjoshbetz_auth0andriy0kmaaantonejason.gervaisshafatkhanpsychoticbratbrohowismynamealreadytakenlewisbyrne-oktatarunpreet.kaurharish.sundarbsmith-auth0dannyturcotteauth0-wernersafder.areepattamannil

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:base64-decode AI (semgrep): Base64 decoding in lib/jwt.js is standard JWT token parsing logic — transparent, two-line helper function with no obfuscation. Expected and benign for this package. ai
phantom-deps phantom-dep:passport-oauth2 AI (phantom-deps): passport-oauth2 is a legitimate declared dependency; indirect usage via passport-oauth is a benign structural pattern for this OAuth strategy package. ai

Versions (showing 1 of 1)

Version Deps Published
1.4.5 3 / 3