← Home

tfhe

TFHE-rs is a fully homomorphic encryption (FHE) library that implements Zama's variant of TFHE.

7
Versions
BSD-3-Clause-Clear
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures gitHead linked

Maintainers

zama-fhe-bot

Keywords

fullyhomomorphicencryptionfhecryptography

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
npm-metadata bundled-binaries AI (npm-metadata): WASM build artifact is the library's core deliverable, documented in files/main. ai
maintainer-change maintainer-removed AI (maintainer-change): Publishing now via GitHub Actions/CI provenance, not a hostile takeover indicator. ai

Versions (showing 7 of 7)

Version Deps Published
1.7.0 0 / 0
1.6.3 0 / 0
1.6.2 0 / 0
1.6.1 0 / 0
1.6.0 0 / 0
1.5.5 0 / 0
1.5.4 0 / 0

v1.7.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.6.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.5.5

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • tfhe_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.5.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.