590 packages matching “possession”

dsh-possession

v0.0.1 · 18 days ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

Possession - who has the ball - name reserved; first release in development.

14Downloads across all versions in the last 7 days, from the official npm downloads API.MITLicense declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v0.0.1 (the latest release), from the OSV.dev database.

dpop-auth

v1.2.1 · 9 days ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

Device-bound authentication with DPoP (Demonstration of Proof-of-Possession) tokens for enhanced security

211Downloads across all versions in the last 7 days, from the official npm downloads API.Apache-2.0License declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v1.2.1 (the latest release), from the OSV.dev database.

@pagopa/io-wallet-oauth2

v1.5.8 · 11 days ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

OAuth 2.0 helpers for IT-Wallet flows, including Pushed Authorization Requests, PKCE, DPoP, JAR/JARM utilities, access-token handling, wallet/client attestation helpers, and MRTD proof-of-possession support.

391Downloads across all versions in the last 7 days, from the official npm downloads API.Apache-2.0License declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v1.5.8 (the latest release), from the OSV.dev database.

@celo/bls12377js

v0.1.1 · 4 years ago

85
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

This package implements BLS12-377 in TypeScript. It also contains functions for the generation of BLS proofs of possession, as done in [Celo](https://github.com/celo-org/celo-monorepo).

402Downloads across all versions in the last 7 days, from the official npm downloads API.MITLicense declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v0.1.1 (the latest release), from the OSV.dev database.

@bounded-authority-protocol/verifier

v0.5.0 · 8 days ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

Provider-neutral, deterministic verifier SDK for bounded proof-of-possession authority — a typed TypeScript reimplementation of the Bounded Authority Protocol verification profiles (wire contract-majors 1, 2, and 3).

352Downloads across all versions in the last 7 days, from the official npm downloads API.Apache-2.0License declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v0.5.0 (the latest release), from the OSV.dev database.

@bitspark/archon-sdk

v0.14.0 · 1 day ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

archon-sdk: proof of possession and the signed envelope, one layer above the identity floor. Deterministic given its inputs; no RNG, no clock, no socket.

125Downloads across all versions in the last 7 days, from the official npm downloads API.Apache-2.0License declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v0.14.0 (the latest release), from the OSV.dev database.

@vesper-core/ghost-ledger

v0.1.0-alpha.1 · 16 days ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

Cryptographic resilience middleware: volatile RAM ledger, Error Trapping Matrix, DPoP asymmetric proof-of-possession signing, and platform-agnostic transport adapters.

16Downloads across all versions in the last 7 days, from the official npm downloads API.MITLicense declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v0.1.0-alpha.1 (the latest release), from the OSV.dev database.

vaid-pop

v0.3.0 · 2 months ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

The VAID proof-of-possession signing primitive (TypeScript): RFC 8785 (JCS) -> SHA-256 -> Ed25519, byte-identical to the Rust and Python implementations against the frozen conformance vectors.

103Downloads across all versions in the last 7 days, from the official npm downloads API.Apache-2.0License declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v0.3.0 (the latest release), from the OSV.dev database.

hono-dpop

v0.3.0 · 5 months ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

DPoP (RFC 9449) proof-of-possession middleware for Hono.

11Downloads across all versions in the last 7 days, from the official npm downloads API.MITLicense declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v0.3.0 (the latest release), from the OSV.dev database.

scopeblind-agent

v1.2.0 · 6 months ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

Agent identity SDK for ScopeBlind. DPoP proof-of-possession for AI agents, CLIs, and MCP servers. Generates holder-binding commitments for signed decision receipts.

43Downloads across all versions in the last 7 days, from the official npm downloads API.Apache-2.0License declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v1.2.0 (the latest release), from the OSV.dev database.

@skhema/agent-sdk

v0.1.4 · 3 months ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

Client SDK for Skhema registered agents — local keypair generation, enrollment-token redemption, and proof-of-possession request signing (Agent Auth Protocol).

19Downloads across all versions in the last 7 days, from the official npm downloads API.MITLicense declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v0.1.4 (the latest release), from the OSV.dev database.

oauth2-dpop

v1.0.0 · 4 years ago

85
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

OAuth 2.0 Demonstrating Proof-of-Possession at the Application Layer (DPoP) server-side implementation for Node.js

18Downloads across all versions in the last 7 days, from the official npm downloads API.MITLicense declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v1.0.0 (the latest release), from the OSV.dev database.

@noz-ele/x509-http-signatures

v0.1.0 · 1 month ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

X.509 proof of possession for HTTP requests using RFC 9440, RFC 9421, and EdgCA.

7Downloads across all versions in the last 7 days, from the official npm downloads API.MITLicense declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v0.1.0 (the latest release), from the OSV.dev database.

obsideo-mcp

v0.7.5 · 11 days ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

MCP server for Obsideo: S3-compatible storage that is encrypted client-side by default, with continuous cryptographic possession proofs you can verify yourself. Instant no-email trial, self-serve signup (12 GB free, no card), put/get/ls/rm/verify/usage to

439Downloads across all versions in the last 7 days, from the official npm downloads API.PolyForm-Shield-1.0.0License declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v0.7.5 (the latest release), from the OSV.dev database.

@marketnow/trust-core

v2.0.3 · 16 days ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

UTA Verification Core — the full agent-trust stack in one zero-dependency package: 12-stage verification pipeline, Ed25519 (RFC 8032) + JCS (RFC 8785) canonicalization, proof-of-possession, behavioral baselines with statistical drift detection (7 signal c

81Downloads across all versions in the last 7 days, from the official npm downloads API.(MIT OR Apache-2.0)License declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v2.0.3 (the latest release), from the OSV.dev database.

@mandarelabs/vault

v0.1.0 · 5 days ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

Mandare vault: OS-keychain-backed credential storage, credential injection, and short-lived proof-of-possession scoped tokens — agents never see raw secrets

116Downloads across all versions in the last 7 days, from the official npm downloads API.AGPL-3.0-onlyLicense declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v0.1.0 (the latest release), from the OSV.dev database.

@ninshorg/client

v0.1.0 · 28 days ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

Browser client for Ninsho — DPoP proof-of-possession with a non-extractable key, automatic refresh. Zero dependencies.

11Downloads across all versions in the last 7 days, from the official npm downloads API.MITLicense declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v0.1.0 (the latest release), from the OSV.dev database.

veritas-verify

v0.1.0 · 3 months ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

VERITAS verification library — verify W3C Verifiable Credentials, proof-of-possession, and ECDSA signatures from the VERITAS identity protocol

4Downloads across all versions in the last 7 days, from the official npm downloads API.MITLicense declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v0.1.0 (the latest release), from the OSV.dev database.

@schwaizer/ocp-hub

v0.10.0 · 1 month ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

OCP Hub building blocks. Root export: the WSS profile — ES256 keys, delegated QR pairing with proof-of-possession, session lifecycle. `/embed` export: the minimal HTTP+SSE turn profile, site-key and origin enforcement, quotas, widget document. `/server` e

47Downloads across all versions in the last 7 days, from the official npm downloads API.Apache-2.0License declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v0.10.0 (the latest release), from the OSV.dev database.

agenza-verify

v0.1.1 · 3 months ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

AGENZA verification library — verify W3C Verifiable Credentials, proof-of-possession, and ECDSA signatures from the AGENZA identity protocol

5Downloads across all versions in the last 7 days, from the official npm downloads API.MITLicense declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v0.1.1 (the latest release), from the OSV.dev database.
1 / 30Next