← Home

@noble/secp256k1

Fastest 5KB JS implementation of secp256k1 ECDH & ECDSA signatures compliant with RFC6979

23
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

paulmillr

Keywords

secp256k1rfc6979signatureecdsanoblecryptographyelliptic curveecccurveschnorrbitcoinethereum

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): paulmillr intentionally migrated @noble packages to GitHub Actions CI publishing with SLSA/Sigstore attestation as a supply chain hardening measure. This transition is expected and stable. ai
publish-pattern dormant-publish AI (publish-pattern): Mature, stable cryptographic library with infrequent but legitimate releases. SLSA attestation confirms release origin; dormancy is consistent with the package's release cadence. ai

Versions (showing 23 of 23)

Show 1 prerelease
Version Deps Published
3.1.0 0 / 6
3.0.0 0 / 6
2.3.0 0 / 8
2.2.3 0 / 6
2.1.0 0 / 6
2.0.0 0 / 5
1.7.1 0 / 12
1.7.0 0 / 12
1.6.3 0 / 12
1.6.2 0 / 12
1.6.1 0 / 12
1.6.0 0 / 12
1.5.5 0 / 12
1.5.4 0 / 12
1.5.3 0 / 12
1.5.2 0 / 12
1.5.0 0 / 12
1.4.0 0 / 12
1.3.4 0 / 11
1.3.3 0 / 11
1.3.2 0 / 11
1.3.1 0 / 11
1.3.0 0 / 12

v3.1.0

2 findings
HIGH Publisher changed: paulmillr → GitHub Actions (on 2026-04-11) provenance

This version was published by a different npm account than previous versions on 2026-04-11. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.