← Home

hypercore-id-encoding

Convert Hypercore keys to/from z-base32 or hex

1
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

mafintoshandrewosh

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:b4a AI (dependencies): b4a is a standard Holepunch/Hypercore ecosystem utility (Buffer/Uint8Array compat); its use here is expected and appropriate for this package's purpose. ai
dependencies unvetted-dep:z32 AI (dependencies): z32 is the canonical z-base32 encoder used throughout the Hypercore ecosystem; directly required by this package's stated functionality. ai

Versions (showing 1 of 1)

Version Deps Published
1.3.0 2 / 4

v1.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.