@opengovsg/auth

Framework-agnostic building blocks for a safe-by-default OTP login flow: PKCE-style session binding and one-time-password generation/verification with the ordering that closes known timing, brute-force, and replay attacks already built in.

100

Security score

0 known advisories in v0.0.0-20260811084355

0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.advisory penalty −0 · staleness penalty −0

Weekly downloads

Downloads across all versions in the last 7 days, from the official npm downloads API (api.npmjs.org).

Unpacked size

Size of v0.0.0-20260811084355 on disk after npm install extracts the tarball, as reported by the npm registry.

111.6 kB

Dependencies

Direct runtime dependencies declared by v0.0.0-20260811084355. Transitive dependencies are not counted here — use the lockfile audit for the full tree.

1

Last publish

When v0.0.0-20260811084355 was published to the registry. Long gaps can indicate an unmaintained package.

1 month ago

Security advisories

Vulnerabilities affecting v0.0.0-20260811084355 specifically, from OSV.dev — the open database aggregating the GitHub Advisory Database (GHSA) and CVEs. Links open the full advisory.

No known vulnerabilities affect v0.0.0-20260811084355.