← Home

@chainsafe/libp2p-noise

1
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

wemeetagain

Keywords

cryptolibp2pnoise

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@libp2p/utils AI (dependencies): Legitimate libp2p ecosystem dependency consistent with this package's purpose as a libp2p noise implementation. ai
dependencies unvetted-dep:@chainsafe/as-chacha20poly1305 AI (dependencies): ChainSafe's own WASM ChaCha20Poly1305 implementation, directly relevant to this noise protocol package from the same org. ai

Versions (showing 1 of 1)

Version Deps Published
17.0.0 13 / 22

v17.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.