Звіт у форматі JSON машиночитний
{
"data": {
"repo": {
"topics": [],
"is_fork": true,
"size_kb": 23630,
"has_wiki": true,
"homepage": null,
"languages": {
"JavaScript": 4487,
"TypeScript": 1136056
},
"pushed_at": "2026-07-23T16:22:55Z",
"created_at": "2025-04-22T14:39:53Z",
"owner_type": "Organization",
"updated_at": "2026-07-23T16:24:17Z",
"description": "Passwordless authentication with Amazon Cognito: FIDO2 (WebAuthn, support for Passkeys), Totp MFA, Totp and Passkey Step Up",
"is_archived": false,
"is_disabled": false,
"license_spdx": "Apache-2.0",
"default_branch": "main",
"license_spdx_raw": "Apache-2.0",
"primary_language": "TypeScript",
"significant_languages": [
"TypeScript"
]
},
"owner": {
"blog": "www.meow.com",
"name": "Meow",
"type": "Organization",
"login": "joinmeow",
"company": null,
"location": "United States of America",
"followers": 4,
"avatar_url": "https://avatars.githubusercontent.com/u/78460202?v=4",
"created_at": "2021-02-03T03:32:11Z",
"is_verified": null,
"public_repos": 4,
"account_age_days": 2000
},
"license": {
"state": "standard",
"spdx_id": "Apache-2.0",
"raw_spdx": "Apache-2.0",
"file_present": true,
"scorecard_found": true,
"profile_has_license": false
},
"activity": {
"releases": [
{
"tag": "v1.0.104",
"kind": "patch",
"published_at": "2026-07-20T22:36:18Z"
},
{
"tag": "v1.0.103",
"kind": "patch",
"published_at": "2026-07-17T18:24:38Z"
},
{
"tag": "v1.0.102",
"kind": "patch",
"published_at": "2026-06-24T02:04:29Z"
},
{
"tag": "v1.0.101",
"kind": "patch",
"published_at": "2026-06-23T20:34:07Z"
},
{
"tag": "v1.0.100",
"kind": "patch",
"published_at": "2026-06-17T17:26:46Z"
},
{
"tag": "v1.0.99",
"kind": "patch",
"published_at": "2026-05-31T15:49:03Z"
},
{
"tag": "v1.0.98",
"kind": "patch",
"published_at": "2025-11-04T18:22:08Z"
},
{
"tag": "v1.0.97",
"kind": "patch",
"published_at": "2025-10-06T20:02:32Z"
},
{
"tag": "v1.0.96",
"kind": "patch",
"published_at": "2025-10-06T15:42:06Z"
},
{
"tag": "v1.0.95",
"kind": "patch",
"published_at": "2025-10-05T19:50:05Z"
},
{
"tag": "v1.0.94",
"kind": "patch",
"published_at": "2025-10-03T00:04:41Z"
},
{
"tag": "v1.0.92",
"kind": "patch",
"published_at": "2025-10-02T22:13:38Z"
},
{
"tag": "v1.0.91",
"kind": "patch",
"published_at": "2025-10-02T21:53:37Z"
},
{
"tag": "v1.0.90",
"kind": "patch",
"published_at": "2025-09-09T20:17:24Z"
},
{
"tag": "v1.0.88",
"kind": "patch",
"published_at": "2025-07-28T15:12:46Z"
},
{
"tag": "v1.0.87",
"kind": "patch",
"published_at": "2025-07-23T13:32:39Z"
},
{
"tag": "v1.0.86",
"kind": "patch",
"published_at": "2025-07-23T12:02:57Z"
},
{
"tag": "v1.0.85",
"kind": "patch",
"published_at": "2025-07-22T19:16:58Z"
},
{
"tag": "v1.0.84",
"kind": "patch",
"published_at": "2025-07-22T18:32:27Z"
},
{
"tag": "v1.0.83",
"kind": "patch",
"published_at": "2025-07-20T22:05:13Z"
},
{
"tag": "v1.0.82",
"kind": "patch",
"published_at": "2025-07-20T16:09:18Z"
},
{
"tag": "v1.0.81",
"kind": "patch",
"published_at": "2025-07-08T18:20:39Z"
},
{
"tag": "v1.0.80",
"kind": "patch",
"published_at": "2025-06-09T21:00:10Z"
},
{
"tag": "v1.0.79",
"kind": "patch",
"published_at": "2025-06-09T01:33:45Z"
},
{
"tag": "v1.0.78",
"kind": "patch",
"published_at": "2025-06-09T01:25:02Z"
},
{
"tag": "v1.0.77",
"kind": "patch",
"published_at": "2025-06-09T00:28:16Z"
},
{
"tag": "v1.0.76",
"kind": "patch",
"published_at": "2025-06-08T23:25:12Z"
},
{
"tag": "v1.0.75",
"kind": "patch",
"published_at": "2025-06-08T22:49:40Z"
},
{
"tag": "v1.0.74",
"kind": "patch",
"published_at": "2025-06-08T22:39:31Z"
},
{
"tag": "v1.0.73",
"kind": "patch",
"published_at": "2025-06-08T22:32:48Z"
},
{
"tag": "v1.0.72",
"kind": "patch",
"published_at": "2025-06-08T22:03:35Z"
},
{
"tag": "v1.0.71",
"kind": "patch",
"published_at": "2025-05-30T02:03:25Z"
},
{
"tag": "v1.0.70",
"kind": "patch",
"published_at": "2025-05-28T22:24:59Z"
},
{
"tag": "v1.0.69",
"kind": "patch",
"published_at": "2025-05-18T17:25:59Z"
},
{
"tag": "v1.0.68",
"kind": "patch",
"published_at": "2025-05-18T13:13:07Z"
},
{
"tag": "v1.0.67",
"kind": "patch",
"published_at": "2025-05-17T20:31:59Z"
},
{
"tag": "v1.0.66",
"kind": "patch",
"published_at": "2025-05-17T18:54:51Z"
},
{
"tag": "v1.0.65",
"kind": "patch",
"published_at": "2025-05-17T15:08:16Z"
},
{
"tag": "v1.0.64",
"kind": "patch",
"published_at": "2025-05-17T14:41:50Z"
},
{
"tag": "v1.0.63",
"kind": "patch",
"published_at": "2025-05-16T21:54:47Z"
},
{
"tag": "v1.0.62",
"kind": "patch",
"published_at": "2025-05-16T19:58:44Z"
},
{
"tag": "v1.0.61",
"kind": "patch",
"published_at": "2025-05-16T19:31:04Z"
},
{
"tag": "v1.0.60",
"kind": "patch",
"published_at": "2025-05-16T18:31:56Z"
},
{
"tag": "v1.0.59",
"kind": "patch",
"published_at": "2025-05-16T17:51:25Z"
},
{
"tag": "v1.0.58",
"kind": "patch",
"published_at": "2025-05-16T17:19:30Z"
},
{
"tag": "v1.0.57",
"kind": "patch",
"published_at": "2025-05-16T02:27:24Z"
},
{
"tag": "v1.0.56",
"kind": "patch",
"published_at": "2025-05-16T01:10:06Z"
},
{
"tag": "v1.0.55",
"kind": "patch",
"published_at": "2025-05-15T15:57:07Z"
},
{
"tag": "v1.0.54",
"kind": "patch",
"published_at": "2025-05-15T15:43:32Z"
},
{
"tag": "v1.0.53",
"kind": "patch",
"published_at": "2025-05-15T01:15:08Z"
},
{
"tag": "v1.0.52",
"kind": "patch",
"published_at": "2025-05-13T20:43:51Z"
},
{
"tag": "v1.0.51",
"kind": "patch",
"published_at": "2025-05-13T12:34:24Z"
},
{
"tag": "v1.0.50",
"kind": "patch",
"published_at": "2025-05-12T22:17:31Z"
},
{
"tag": "v1.0.49",
"kind": "patch",
"published_at": "2025-05-10T18:47:14Z"
},
{
"tag": "v1.0.48",
"kind": "patch",
"published_at": "2025-05-10T17:32:48Z"
},
{
"tag": "v1.0.47",
"kind": "patch",
"published_at": "2025-05-09T23:17:15Z"
},
{
"tag": "v1.0.46",
"kind": "patch",
"published_at": "2025-05-09T18:00:53Z"
},
{
"tag": "v1.0.45",
"kind": "patch",
"published_at": "2025-05-09T16:15:05Z"
},
{
"tag": "v1.0.44",
"kind": "patch",
"published_at": "2025-05-09T15:27:02Z"
},
{
"tag": "v1.0.43",
"kind": "patch",
"published_at": "2025-05-09T13:46:53Z"
},
{
"tag": "v1.0.42",
"kind": "patch",
"published_at": "2025-05-09T13:36:04Z"
},
{
"tag": "v1.0.41",
"kind": "patch",
"published_at": "2025-05-09T12:42:14Z"
},
{
"tag": "v1.0.40",
"kind": "patch",
"published_at": "2025-05-09T12:28:33Z"
},
{
"tag": "v1.0.39",
"kind": "patch",
"published_at": "2025-05-09T02:08:42Z"
},
{
"tag": "v1.0.38",
"kind": "patch",
"published_at": "2025-05-09T01:50:24Z"
},
{
"tag": "v1.0.37",
"kind": "patch",
"published_at": "2025-05-09T01:28:47Z"
},
{
"tag": "v1.0.36",
"kind": "patch",
"published_at": "2025-05-09T01:14:20Z"
},
{
"tag": "v1.0.35",
"kind": "patch",
"published_at": "2025-05-09T00:43:19Z"
},
{
"tag": "v1.0.34",
"kind": "patch",
"published_at": "2025-05-09T00:00:09Z"
},
{
"tag": "v1.0.33",
"kind": "patch",
"published_at": "2025-05-08T23:05:08Z"
},
{
"tag": "v1.0.32",
"kind": "patch",
"published_at": "2025-05-08T19:10:49Z"
},
{
"tag": "v1.0.31",
"kind": "patch",
"published_at": "2025-05-08T18:15:39Z"
},
{
"tag": "v1.0.30",
"kind": "patch",
"published_at": "2025-05-07T01:33:16Z"
},
{
"tag": "v1.0.29",
"kind": "patch",
"published_at": "2025-05-06T23:37:16Z"
},
{
"tag": "v1.0.28",
"kind": "patch",
"published_at": "2025-05-06T22:15:53Z"
},
{
"tag": "v1.0.27",
"kind": "patch",
"published_at": "2025-05-06T21:03:22Z"
},
{
"tag": "v1.0.26",
"kind": "patch",
"published_at": "2025-05-06T19:23:16Z"
},
{
"tag": "v1.0.25",
"kind": "patch",
"published_at": "2025-05-06T18:59:43Z"
},
{
"tag": "v1.0.24",
"kind": "patch",
"published_at": "2025-05-06T18:24:46Z"
},
{
"tag": "v1.0.23",
"kind": "patch",
"published_at": "2025-05-06T17:40:15Z"
},
{
"tag": "v1.0.22",
"kind": "patch",
"published_at": "2025-05-06T16:23:22Z"
},
{
"tag": "v1.0.21",
"kind": "patch",
"published_at": "2025-05-06T13:38:10Z"
},
{
"tag": "v1.0.20",
"kind": "patch",
"published_at": "2025-05-05T19:22:29Z"
},
{
"tag": "v1.0.19",
"kind": "patch",
"published_at": "2025-05-05T16:29:37Z"
},
{
"tag": "v1.0.18",
"kind": "patch",
"published_at": "2025-05-05T12:35:20Z"
},
{
"tag": "v1.0.17",
"kind": "patch",
"published_at": "2025-05-04T20:03:20Z"
},
{
"tag": "v1.0.16",
"kind": "patch",
"published_at": "2025-05-02T20:52:39Z"
},
{
"tag": "v1.0.15",
"kind": "patch",
"published_at": "2025-05-02T20:19:30Z"
},
{
"tag": "v1.0.14",
"kind": "patch",
"published_at": "2025-05-02T19:59:33Z"
},
{
"tag": "v1.0.13",
"kind": "patch",
"published_at": "2025-05-01T16:19:53Z"
},
{
"tag": "v1.0.12",
"kind": "patch",
"published_at": "2025-05-01T12:34:20Z"
},
{
"tag": "v1.0.11",
"kind": "patch",
"published_at": "2025-04-24T23:51:58Z"
},
{
"tag": "v1.0.10",
"kind": "patch",
"published_at": "2025-04-24T18:32:54Z"
},
{
"tag": "v1.0.9",
"kind": "patch",
"published_at": "2025-04-24T18:07:35Z"
},
{
"tag": "v1.0.8",
"kind": "patch",
"published_at": "2025-04-24T17:30:56Z"
},
{
"tag": "v1.0.7",
"kind": "patch",
"published_at": "2025-04-24T16:40:20Z"
}
],
"recent_commits": [
{
"oid": "2ddce40e8a2b8cce16f32bf03fd4b5051de26594",
"body": "cognitoIdpEndpoint is the target for every cognito-idp API call\n(InitiateAuth, RespondToAuthChallenge, GetTokensFromRefreshToken,\nRevokeToken, GetUser, SignUp, ChangePassword, ...). Passwords\n(USER_PASSWORD_AUTH), SRP parameters, refresh/access tokens and any\noptional clientSecret are POSTed to it, \n[…]\ning hostedUi.domain http:// rejection. Bare AWS region shorthand\n(e.g. eu-west-1) is unaffected — it is handled by the auto-prefix path.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)",
"is_bot": false,
"headline": "fix(security): require https for cognitoIdpEndpoint (#110)",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-07-23T16:22:55Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "72e1fd04e0be2667d7c69e2b563d5017fb215ab9",
"body": "fido2.baseUrl is the base URL for every FIDO2 backend API call\n(register passkey, list/delete credentials). The user's ID token is sent\nas an `Authorization: Bearer <idToken>` header to that URL, so a\nplaintext http:// base would expose the token in transit.\n\nconfigure() validated hostedUi.domain ag\n[…]\n plaintext http:// fido2.baseUrl at\nconfigure() time, mirroring the existing hostedUi.domain http:// check\nin placement and error style.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)",
"is_bot": false,
"headline": "fix(security): require https for fido2.baseUrl (#111)",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-07-23T16:22:27Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "ac145cc518b432d2b3d4b454baa2ae1ee6f9c64a",
"body": null,
"is_bot": false,
"headline": "Bump version from 1.0.103 to 1.0.104",
"author_name": "GitHub Action",
"author_login": "actions-user",
"committed_at": "2026-07-20T22:35:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e87dfdffd03ab314c231f3d9108af2a6a74e2374",
"body": "… scope (#108)\n\nHosted-UI / OAuth access tokens only carry the OAuth scopes that were\nrequested at sign-in. Cognito GetUser requires\naws.cognito.signin.user.admin, so for redirect sessions the MFA-status\nfetch fails deterministically with NotAuthorizedException and the hook\nretries it per token (and\n[…]\nser; without\nthe scope, publish the default TOTP status (disabled) and mark\nmfaStatusReady immediately. Same guard in refreshTotpMfaStatus.\nUnparseable tokens fail open and keep the previous behavior.",
"is_bot": false,
"headline": "fix(react): skip GetUser MFA-status fetch when token lacks user.admin…",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-07-20T22:34:31Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ab3efa53ec4aa9d9441702ccc580c6c8a111baba",
"body": null,
"is_bot": false,
"headline": "Bump version from 1.0.102 to 1.0.103",
"author_name": "GitHub Action",
"author_login": "actions-user",
"committed_at": "2026-07-17T18:24:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "25fd5254cb20d30ce8403f74515ce3bb0da7826b",
"body": "…t can't wedge auth (#107)\n\ncreateFetchWithRetry awaited fetch with no per-attempt timeout, so a black-holed\nconnection (TLS up, no response, no error) hung forever. Because auth requests\nrun on the critical sign-in/refresh path, one hung call — e.g. ConfirmDevice\nduring device confirmation, which r\n[…]\nast attempt). Default 25s; configurable via a\nnew createFetchWithRetry parameter. Applies to every Cognito call, so ConfirmDevice,\nRespondToAuthChallenge, and refresh all fail fast instead of hanging.",
"is_bot": false,
"headline": "fix(client): bound each fetch attempt with a timeout so a hung reques…",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-07-17T18:20:52Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ccf3af1fca4bd1562ff01cd5bcabf7f46efc1dbe",
"body": null,
"is_bot": false,
"headline": "Bump version from 1.0.101 to 1.0.102",
"author_name": "GitHub Action",
"author_login": "actions-user",
"committed_at": "2026-06-24T02:04:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ba5e93fe4e0d3e407d94f5a7c99954acfd9a3f64",
"body": "…ignal API (#106)\n\nWhen the relying party rejects a sign-in because it does not recognize the\npresented credential (a discoverable passkey revoked server-side but still\noffered at the login screen), Cognito returns a UserLambdaValidationException\ncarrying {\"reason\":\"unknown_credential\"}. authenticat\n[…]\n plus a produced assertion: cancels,\naborts, network/throttle failures, wrong signature, and generic NotAuthorized\nall keep the existing failure path, so a valid passkey is never signalled as\nunknown.",
"is_bot": false,
"headline": "feat(client): surface unknown-credential sign-in rejections for the S…",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-24T02:03:44Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "de9d7afdbac03a3a37aa37aca8549faf3fb8c6ab",
"body": null,
"is_bot": false,
"headline": "Bump version from 1.0.100 to 1.0.101",
"author_name": "GitHub Action",
"author_login": "actions-user",
"committed_at": "2026-06-23T20:33:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "64ea8e32b66b70f06ab6289a942d7ffbfbcccbc5",
"body": "* feat(client): add WebAuthn Signal API wrappers\n\nAdd signalAllAcceptedCredentials, signalUnknownCredential and\nsignalCurrentUserDetails over the W3C PublicKeyCredential.signal* static\nmethods. Each is feature-gated via getClientCapabilities() and no-ops where the\nbrowser lacks support. The WebAuthn\n[…]\nix rather than the current hostname.\nResolve the rpId from an explicit argument or the configured fido2.rp.id only,\nand no-op when neither is available rather than signalling against a guessed\ndomain.",
"is_bot": false,
"headline": "feat(client): add WebAuthn Signal API wrappers (#105)",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-23T19:41:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e624ca2be4ba7ddcf578c378565a7a1f5eb13131",
"body": null,
"is_bot": false,
"headline": "Bump version from 1.0.99 to 1.0.100",
"author_name": "GitHub Action",
"author_login": "actions-user",
"committed_at": "2026-06-17T17:26:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6ff0a56ccaafc689b2df73e068e2f4e65ba5ba58",
"body": "When another tab signs out it removes the Cognito token keys from\nstorage, firing a storage event in this tab. The handler only called\nloadTokens (which nulls tokens) but never dispatched SIGN_OUT, so\nper-user React state (totpMfaStatus, mfaStatusReady, deviceKey,\nauthMethod, ...) survived until the\n[…]\n removal and a LastAuthUser removal each reset\ndeviceKey/totpMfaStatus/mfaStatusReady; a token change (refresh) keeps\nthe user signed in with state intact. The removal tests fail on the\nprevious code.",
"is_bot": false,
"headline": "Reset per-user state on a cross-tab sign-out (#103)",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-17T17:09:20Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "77436c4968b14db832cebb897cbf0e1825a1bf2c",
"body": "…in (#100)\n\nThree small hardening fixes from the re-review's core-cleanups bucket:\n\n- initiateAuth no longer mutates the caller's authParameters object\n (it set authParameters.DEVICE_KEY = deviceKey, which stuck on an\n object reused across retry attempts). The device key is merged into\n the reque\n[…]\nh sends DEVICE_KEY without mutating the caller's\nobject (incl. reuse across two calls); http:// hostedUi.domain throws;\na bare domain is accepted. The behaviour-change tests fail on the\nprevious code.",
"is_bot": false,
"headline": "Misc safety: no authParameters mutation, reject http:// hostedUi.doma…",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-17T17:08:55Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e17e4cf3b509a17eb9e0e1734a1aabecdb1b64dd",
"body": "* Retry transient renewal initiate in conditional FIDO2 flow\n\nThe conditional-mediation renewal loop re-initiates a fresh Cognito\nCUSTOM_AUTH challenge at the top of each iteration. A transient network\nfailure of that initiateFido2Challenge() call threw and killed the whole\nconditional-autofill flow\n[…]\nker pointing at a dead, superseded flow rather\nthan returning to \"no live conditional flow\". Restore only a still-live\nprevious flow, else clear to undefined, so the invariant (non-null ⇒ live)\nholds.",
"is_bot": false,
"headline": "Retry transient renewal initiate in conditional FIDO2 flow (#102)",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-17T17:08:34Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1162e23c608e6a6c6c1185c272e49f2094923d86",
"body": "* Track refresh failures and backoff retry timer per user\n\nMove consecutiveRefreshFailures from a module global into per-user\nRefreshState, and track the failure-backoff retry timer so it can be\ncancelled on sign-out / abort / forced refresh instead of firing for a\ntorn-down session. One user's repe\n[…]\nMap) could arm a retry nothing could cancel.\n\nCancel retryTimer in clearExistingTimer too, and bail the failure catch when\nthere is no username. Regression test added for the re-schedule cancellation.",
"is_bot": false,
"headline": "Track refresh failures and backoff retry timer per user (#101)",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-17T17:08:17Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "090cd82d89396c579600d07d6b2a45531982b0f3",
"body": "…104)\n\n* Rehydrate deviceKey from storage in the SRP and plaintext tokensCb\n\nThe FIDO2 sign-in tokensCb rehydrates the device key from the\nremembered-device record when the tokens don't carry one (since #64),\nbut the SRP and plaintext tokensCb did not: SRP only set deviceKey when\npresent, and plaint\n[…]\ntical FIDO2/SRP/plaintext rehydrate blocks (which diverged once — the\nbug the previous commit fixed) collapse into one shared rehydrateDeviceKey()\nhelper. Add a regression test for the cross-tab case.",
"is_bot": false,
"headline": "Rehydrate deviceKey from storage in the SRP and plaintext tokensCb (#…",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-17T17:07:02Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "32215579e7dc3a376d5ad9893a4051780c6995ec",
"body": "processTokens is the only thing that arms the next refresh, and it runs\nonly on a fresh sign-in / refresh — never on a page reload, where the\ntokens are read back from storage. So after a reload nothing scheduled\nthe next refresh until the +5-minute watchdog tick. With short access\ntokens (Cognito a\n[…]\nt.\n\nTest: a session restored from storage schedules a refresh on mount; the\nsigned-out case still calls scheduleRefresh (which no-ops). Both fail on\nthe previous code, which never scheduled on reload.",
"is_bot": false,
"headline": "Schedule a token refresh on page reload (#99)",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-15T17:20:07Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cda691f78d9ad1c0af387b5594d52b28e00d1ef0",
"body": "…#97)\n\nThree related warts in the processTokens scheduling machinery:\n\n1. Identity-checked schedule deletion. A completed refresh runs its\n nested processTokens (which registers the NEXT schedule for the new\n tokens) BEFORE the old schedule's tokensCb fires. The tokensCb\n deleted the user's ac\n[…]\n: newDeviceMetadata=undefined schedules immediately (no deferral);\na real new device key defers 2 minutes; sign-out cancels a pending\ndeferral. The two behavior-change tests fail on the previous code.",
"is_bot": false,
"headline": "Fix processTokens refresh-scheduling dedup and fresh-login deferral (…",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-15T17:15:30Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "899d1d336df59fde027f19db7c507094f573a549",
"body": "…sions (#98)\n\n* Resolve CodeQL alerts: two polynomial-ReDoS regexes and workflow permissions\n\nCodeQL code-scanning flagged three open alerts:\n\n- HIGH js/polynomial-redos in client/config.ts (trailing-slash trim\n /\\/+$/): replace with a linear backward scan. Backtracking on a long\n run of \"/\" was p\n[…]\nrightmost one\nwith a non-empty suffix (and non-empty prefix), which is what the regex\nresolves to — still O(n), no backtracking. Verified equivalent to the\nregex across single- and multi-marker cases.",
"is_bot": false,
"headline": "Resolve CodeQL alerts: two polynomial-ReDoS regexes + workflow permis…",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-15T17:14:47Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "93c2e55fa9790379267c4b187e3b43df1fb5fe01",
"body": "Bumps the npm_and_yarn group with 1 update in the / directory: [esbuild](https://github.com/evanw/esbuild).\n\n\nUpdates `esbuild` from 0.25.8 to 0.28.1\n- [Release notes](https://github.com/evanw/esbuild/releases)\n- [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG-2025.md)\n- [Commits](h\n[…]\n dependency-type: indirect\n dependency-group: npm_and_yarn\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump esbuild in the npm_and_yarn group across 1 directory (#90)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-15T17:07:54Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b02822e635fb47a9792008d018264d4a286fc8d9",
"body": "…r (#96)\n\nOn a getUser error the hook retained the last-known MFA status, marked\nmfaStatusReady true, and scheduled a silent retry every ~7s by clearing\nthe token guard and nudging a re-run. There was no cap: a persistent\nfailure (network outage, or a backend that keeps erroring) retried\nforever.\n\nC\n[…]\nhile retries\nstop.\n\nTest: getUser failing every time yields exactly 1 initial + 3 retries =\n4 fetches then stops (the previous code kept polling); a token rotation\nresets the budget and fetches again.",
"is_bot": false,
"headline": "Cap the MFA-status fetch retry so a failing getUser can't poll foreve…",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-15T16:52:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cc1c76821192f55d05a7bc341fa0f66109c9135c",
"body": "* Honor an explicit advancedSecurity.region as an allowlist override\n\n#70 added a hardcoded allowlist of regions known to host the Advanced\nSecurity script and stopped defaulting unknown regions to us-east-1.\nBut it also gated an EXPLICITLY configured advancedSecurity.region\nbehind that allowlist, s\n[…]\n the allowlist. A malformed value is rejected outright rather than\nfalling through to the endpoint-derived region. Regression test loads a\nhost-injection region string and asserts nothing is injected.",
"is_bot": false,
"headline": "Honor an explicit advancedSecurity.region as an allowlist override (#95)",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-15T16:38:55Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1482b75a02f0d181e6f0d6f32b03c4184723eadd",
"body": "#92 widened the React OAuth-callback gate to also fire on an `error`\nparam so denied sign-ins surface instead of hanging silently. It checks\n`error` in both the query and the URL fragment, unconditionally.\n\nPer RFC 6749, response errors come back in the query for the code flow\n(§4.1.2.1) and in the \n[…]\n first — this just stops the spurious entry\nat the gate.\n\nTests: a code-flow fragment error no longer invokes the handler; an\nimplicit-flow fragment error still does and surfaces the provider message.",
"is_bot": false,
"headline": "Gate implicit-flow OAuth fragment errors to responseType \"token\" (#94)",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-15T16:10:33Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "58c417acec1cd6d44d0fe9e09083a01f26b12b69",
"body": "…dow (#93)\n\n* Close FIDO2 conditional renewal/takeover seam during the initiate window\n\nThe conditional-autofill renewal loop tracked takeovers only via\npendingConditionalGet, which exists solely while a navigator.credentials\n.get() is pending. Between renewal iterations — after the previous get()\ni\n[…]\nin once it has\nsuperseded the conditional one.\n\nTest: a conditional getter that performs a modal takeover and then\nresolves with a credential ends the flow with superseded=true rather\nthan completing.",
"is_bot": false,
"headline": "Close FIDO2 conditional renewal/takeover seam during the initiate win…",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-15T16:08:08Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d49f2bf27b9ffa4b4548f269f419ba1f106b3abe",
"body": "Two bugs in the hook's OAuth-callback effect:\n\n1. The gate only fired for code/access_token, so an error-only redirect\n (user denied consent: ?error=access_denied with no code/token, in the\n query for the code flow or the fragment for implicit) never invoked\n handleCognitoOAuthCallback. The ha\n[…]\nGNED_IN; null result resolves to NOT_SIGNED_IN (not stuck at\nSIGNING_IN); tokens reach SIGNED_IN; a non-callback URL never invokes\nthe handler. The two behavior-change tests fail on the previous hook.",
"is_bot": false,
"headline": "Fix React OAuth callback gate for errors and stuck busy status (#92)",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-15T15:37:19Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e227267b66592b2c50b3a8ac5d2831295e223b01",
"body": "* Route forceRefreshTokens through the per-user refresh lock\n\nforceRefreshTokens (exposed by the React hook, called on a 401) passed\nforce:true, which conflated two concerns: skip the cross-tab dedup\ncheck AND bypass the per-user refresh lock. Bypassing the lock let a\nforced refresh race a concurren\n[…]\nes to a private\nperformRefresh that carries skipLock. Only the in-lock immediate-\nrefresh path calls performRefresh with skipLock:true. Verified the\ngenerated refresh.d.ts no longer mentions skipLock.",
"is_bot": false,
"headline": "Route forceRefreshTokens through the per-user refresh lock (#91)",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-15T15:25:23Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e9b3b4ff7b5529a75303ede5eecd6fb990d22389",
"body": "…an takeover (#89)\n\n* Fix sign-out and lock liveness: timeout fallback, heartbeat cap, orphan takeover\n\nThree liveness gaps around the cross-tab storage lock:\n\n1. signOut now catches LockTimeoutError and proceeds without the lock.\n Previously another tab's heartbeat-renewed refresh lock made signO\n[…]\ned-token write) is\ncompensated; fresh sign-in clears a stale tombstone; the E2E\nhung-refresh race still passes. The signOut leftover-keys test now\nasserts the tombstone is the one deliberate survivor.",
"is_bot": false,
"headline": "Fix sign-out and lock liveness: timeout fallback, heartbeat cap, orph…",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-15T14:32:55Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "af5251cf768cd8ce16308e9d1ef104e51f0a5a51",
"body": "…#88)\n\nThe stale-device hardening added to the plaintext flow (#67) never\nreached its SRP sibling, leaving the worst behavior in the most-used\nflow: srp.ts sent device keys from placeholder records (no device\npassword), and a device forgotten server-side PERMANENTLY bricked SRP\nsign-in - every attem\n[…]\n-api.ts and device.ts import each\nother, and a requireActual factory re-enters that cycle and splits the\nmodule identity (device.ts ends up calling a different confirmDevice\nthan the test configured).",
"is_bot": false,
"headline": "Bring SRP flow to device-key parity; never persist unconfirmed keys (…",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-12T16:37:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3a8a950e464f487dafaaafb8487f8636ea645f25",
"body": "* Make refresh-bugs suite deterministic under parallel load\n\nThe suite failed ~25% of runs on loaded machines. Root cause:\nprocessTokens launches fire-and-forget scheduleRefresh chains whose\nhops (storage-lock jitter sleeps, poll loops) outlive the test that\nstarted them; with static imports a strag\n[…]\nfor isolation (they belong to the\ndiscarded module graph) but the teardown comment claimed otherwise.\nCancel each suite username's timers via cleanupUserRefreshState\nbefore resetting the module graph.",
"is_bot": false,
"headline": "Make refresh-bugs suite deterministic under parallel load (#87)",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-11T15:31:32Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fa16ca3af307056f882b6aa84e478745686de989",
"body": "* Add opt-in Hosted UI sign-out via signOutWithRedirect\n\nLocal signOut only clears storage and revokes the refresh token; the\nCognito Hosted UI (managed login) session cookie survives, so on a\nshared device the next signInWithRedirect within the hour silently\nsigns in as the previous user. Add an op\n[…]\ndow\nshrinks from a network round-trip to microtasks. Regular signOut\nordering is unchanged (local-first, so a network failure can never\nkeep a user signed in). Ordering pinned by tests for both modes.",
"is_bot": false,
"headline": "Add opt-in Hosted UI sign-out via signOutWithRedirect (#68)",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-11T13:42:02Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ea8744ee16be560e641efb4ef8f98aeb605fb3d6",
"body": "* Send DEVICE_KEY in USER_PASSWORD_AUTH initiateAuth call\n\nThe plaintext password flow looked up the remembered device key only\nafter initiateAuth had already been sent, and never passed it along, so\nCognito could not recognize a remembered device: users were always\nprompted for MFA and the pre-buil\n[…]\ner browser\n now fully self-heal in one sign-in).\n\n3. clearDeviceKey now awaits the storage removals before dispatching,\n so a sign-in started right after it resolves cannot read the old\n record.",
"is_bot": false,
"headline": "Send DEVICE_KEY in USER_PASSWORD_AUTH initiateAuth call (#67)",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-11T13:06:52Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3163c2fe8041250aface58d2a7acac8a3d3d6905",
"body": "…ow (#66)\n\n* Surface fragment-delivered OAuth errors and deprecate implicit flow\n\nPer RFC 6749 §4.2.2.1, implicit-flow error responses arrive in the URL\nfragment, but the callback handler only read url.searchParams, so real\nIdP errors were swallowed and surfaced as a misleading \"Access token\nmissing\n[…]\nattack stays blocked: the fallback never\nruns when the fragment holds valid tokens. Also rephrase the channel\ncomments to distinguish RFC-specified server behavior from this\nclient's hardening policy.",
"is_bot": false,
"headline": "Surface fragment-delivered OAuth errors and deprecate the implicit fl…",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-11T13:05:45Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7b49703bcacfdf6e14cd3e292c46f2f37253d063",
"body": "…O2 request (#76)\n\n* Abort pending conditional credentials.get() before starting a new request\n\nPer the Credential Management API, only one credentials.get() request may\nbe pending at a time. With the documented usage pattern - a conditional\n(autofill) request kicked off at page load, followed by th\n[…]\nso the autofill flow would restart behind the modal request's\nback and keep renewing indefinitely. Rethrow superseded aborts so the\nflow ends cleanly; regression test covers the renewal-boundary race.",
"is_bot": false,
"headline": "Abort pending conditional credentials.get() before starting a new FID…",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-11T00:59:41Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "762177be4dbe88d0f41e9ed7d382846852c0a5e4",
"body": "* Reset per-user state on sign-out in React hook\n\nThe SIGN_OUT reducer action was defined but never dispatched, so the\nReact signOut method left deviceKey, totpMfaStatus, mfaStatusReady and\nactivity timestamps from the previous user in place. A subsequent user\non the same provider instance could the\n[…]\nin a session, and\nsign-out is a session boundary: reset it so the next user's fetch\nruns immediately. Regression test signs user B in within the cooldown\nand asserts an immediate fetch with B's token.",
"is_bot": false,
"headline": "Reset per-user state on sign-out in React hook (#64)",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-11T00:59:11Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ddf4a3d8b8b10ca059c1bcc59b97c86d20bcfac0",
"body": "…its (#62)\n\nThe post-exchange URL cleanup used history.pushState, which adds a new\nhistory entry and leaves the callback URL carrying ?code=...&state=...\n(or #access_token=... in the implicit flow) one step back in session\nhistory. Worse, no error path cleaned the URL at all: on state mismatch,\nmiss\n[…]\nes in the implicit flow, which previously threw without scrubbing.\nFalls back to pushState for custom MinimalHistory implementations\nwithout replaceState (replaceState is added as an optional member).",
"is_bot": false,
"headline": "Scrub OAuth code/tokens from URL with replaceState on all callback ex…",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-11T00:58:47Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a225f9d40becb55236a9efdfc33af481193342cf",
"body": "…bility listener (#60)\n\n* Keep global refresh listeners alive across sign-out\n\nsignOut called cleanupRefreshSystem(username), which tore down the\nglobal visibilitychange listener, refresh watchdog, and page-unload\nhandlers for the rest of the page lifetime. Since these are only\nregistered once at mo\n[…]\nther lookup in this file since #55) so the\nlock is honored whenever a refresh token still exists. With the lock\nhonored, the handler serializes behind signOut and then no-ops once\nthe tokens are gone.",
"is_bot": false,
"headline": "Fix signOut permanently tearing down global refresh watchdog and visi…",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-10T23:15:46Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0d5792f526b14c6c213b6b91a863b183cf3715cd",
"body": "…h cooldown (#61)\n\nWhen the access token changed within 5s of the previous getUser call\n(e.g. OAuth code exchange completing after stored tokens loaded, or a\nforced refresh right after sign-in), updateTokens reset mfaStatusReady\nto false but the MFA status effect early-returned on the cooldown\nwitho\n[…]\nw the cooldown branch schedules a setTimeout for the remaining\ncooldown that nudges the effect to re-run (INCREMENT_RECHECK_STATUS),\nwith cleanup on dependency change/unmount so timers cannot pile up.",
"is_bot": false,
"headline": "Fix mfaStatusReady deadlock when access token rotates within MFA fetc…",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-10T23:15:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e5b2dc57ef7e31902784970450d3ec45e7dd825d",
"body": "The plaintext (USER_PASSWORD_AUTH) flow looked up and stored remembered-\ndevice records under the username as entered, which may be an alias\n(e-mail / phone), while the SRP flow keys them by USER_ID_FOR_SRP. A\ndevice confirmed via one flow was then invisible to the other, silently\nlosing device reme\n[…]\ness token's username claim) and use it\nfor device record lookups and for the rest of the auth flow, with a\nbackward-compat fallback lookup under the username as entered so legacy\nrecords keep working.",
"is_bot": false,
"headline": "Key plaintext-flow device records by canonical user id (#71)",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-10T23:14:46Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "04f2aa9ffb0a7c3cc05b009070c70eb5d6aff17b",
"body": "…n-ASCII usernames (#75)\n\nRegistration encoded the server-sent user.id with Latin-1 byte-stuffing\n(charCodeAt mod 256) while usernameless sign-in decodes the returned\nuserHandle with TextDecoder (UTF-8). For non-ASCII usernames the bytes\nwere corrupted at registration, so the derived USERNAME never \n[…]\n\nare symmetric, and throw a clear Fido2ValidationError if the encoded\nhandle exceeds the 64-byte WebAuthn limit instead of failing opaquely.\nASCII user handles are byte-identical under both encodings.",
"is_bot": false,
"headline": "Fix userHandle encoding to UTF-8 so usernameless sign-in works for no…",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-10T23:14:14Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1b6f2e03fecc7f9296913fc4e5681fcbe7b7b24e",
"body": "handleCognitoOAuthCallback() overwrote the shared in-progress flag with\n\"processing\" before verifying the current URL matched the configured\nredirect URL. The URL-mismatch branch then returned null without\nrestoring the flag, so any invocation on a non-callback URL (e.g. the\nReact hook firing on an \n[…]\nthe redirect-URL comparison ahead of the flag transition so\nnon-callback invocations leave the flag untouched. All paths after the\n\"processing\" write either complete the flow or clear state and throw.",
"is_bot": false,
"headline": "Check redirect URL before marking OAuth callback as processing (#65)",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-10T23:13:31Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c0df6f6c281fcfcfee03c1a6626e172d9a6a73e2",
"body": "…y (#57)\n\n* Make setTimeoutWallClock resilient to device sleep for the whole delay\n\nPreviously, delays >= 30s used a plain setTimeout for all but the final\n30 seconds, and browsers don't reliably credit setTimeout time spent in\nsystem sleep. If the device slept during that phase (almost the entire\nd\n[…]\nresh() deadlocks. Add an\nawaitPumpingTimers helper that advances mock time in 100ms steps (settling\nmicrotasks between steps via real-timer waits) and use it for all\nscheduleRefresh calls in the file.",
"is_bot": false,
"headline": "Make setTimeoutWallClock resilient to device sleep for the whole dela…",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-10T21:13:37Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c8621e1468bcec5b6cc36f6c2e85ca922c561f40",
"body": "The CognitoSecurityProvider previously awaited script injection with a\n5-second timeout on every auth API call whenever the Amazon Cognito\nAdvanced Security script could not load (ad blockers, CSP, unsupported\nregions), and re-appended a fresh script tag on each attempt. An SRP\nsign-in flow could ac\n[…]\nire-and-forget, attempted at most once per page\nload, and skipped for custom proxy endpoints and regions where AWS does\nnot host the script (previously such endpoints silently defaulted to\nus-east-1).",
"is_bot": false,
"headline": "Never block auth calls on threat-protection script loading (#70)",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-10T21:07:08Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9033903f9e328c377b4733dd3583248a081dc4c0",
"body": "…okens (#69)\n\nThe 5-minute deduplication window in processTokens compared only\nwall-clock age of the previous schedule entry. After a successful\nrefresh, processTokens runs for the new tokens while the previous\nentry is still tracked (refresh.ts clears it via tokensCb only after\nprocessTokens return\n[…]\nently disabling retry backoff and abort propagation\nfor the replacement schedule). Add a regression test asserting a\nrefresh-driven processTokens arms the next refresh timer without\naborting anything.",
"is_bot": false,
"headline": "Fix refresh-schedule dedup suppressing next refresh for short-lived t…",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-10T21:06:31Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5f60ac1452eb2b9da33565a48dedfa1a92d9ecd2",
"body": "The documented fallback pattern `error.name === 'NotAllowedError'` could\nnever match because fromDOMException wraps the DOMException in a\nFido2CredentialError whose name is \"Fido2CredentialError\", and both\nNotAllowedError and InvalidStateError mapped to the same CREDENTIAL_ERROR\ncode, leaving no pro\n[…]\nERROR fallback\n- Fix the JSDoc examples in fido2.ts and the docs in ERROR_HANDLING.md\n and client/react/README.md to use the working pattern\n- Add regression tests for the new codes and the predicate",
"is_bot": false,
"headline": "Add discriminating error codes for WebAuthn credential failures (#63)",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-10T21:05:25Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "af2490b368037b73c28dedc2b82006365989d0e3",
"body": "The Fido2ConfigError thrown when isConditionalMediationAvailable()\nresolves false was inside the same try block whose catch only\ndebug-logged and continued, so the guard never fired and the code\nproceeded to call navigator.credentials.get with conditional mediation\non browsers that explicitly report\n[…]\nt false propagates as\nFido2ConfigError, keep the lenient fallthrough when the capability\ncheck itself throws, and make the debug message truthful about\nproceeding. Add regression tests for both cases.",
"is_bot": false,
"headline": "Fix unreachable conditional-mediation guard in fido2getCredential (#59)",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-10T21:04:39Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "58174921e5c1d978a08fa4fb3a781c73707e08a9",
"body": "fido2getCredential unconditionally overrode userVerification to\n\"preferred\" when mediation was \"conditional\", silently downgrading a\nserver-requested \"required\". The WebAuthn spec has no such requirement;\n\"preferred\" is only passkeys.dev UX guidance. With the downgrade, an\nauthenticator may skip use\n[…]\n).\n\nNow the requested value is passed through unchanged and \"preferred\" is\napplied only as a default when no userVerification was requested. The\ntimeout removal for conditional mediation is unchanged.",
"is_bot": false,
"headline": "Respect requested userVerification for conditional mediation (#58)",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-10T21:03:45Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8388acd84cedfa0b45af2d02aabe4eba1a820c70",
"body": "…oIdpEndpoint fallback (#56)\n\ngetAuthorizeEndpoint()/getTokenEndpoint() fell back to cognitoIdpEndpoint\nwhen hostedUi.domain was omitted. With the documented region-only\nconfiguration (e.g. cognitoIdpEndpoint: \"eu-west-1\") this produced\nhttps://eu-west-1/oauth2/authorize, sending signInWithRedirect(\n[…]\nis not a bare AWS region), so https://eu-west-1 or other dotless\nhosts cannot slip through; plaintext http:// origins are rejected,\nbecause OAuth2 authorization codes and tokens travel to that origin.",
"is_bot": false,
"headline": "Require hostedUi.domain for OAuth2 endpoints instead of broken cognit…",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-10T21:02:22Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "068f9fba5c3ba456ecfe10dab874ad492da31afa",
"body": "…#86)\n\nPR #52 added the onTokensStored(cb) subscriber API to client/storage.ts;\nthe React hook calls the returned unsubscribe function in its mount\neffect cleanup. PR #74 added react-context-stability.test.tsx, which\nmocks ../storage without making onTokensStored return a function, so\nthe cleanup ca\n[…]\nact suites already use\n(mockOnTokensStored.mockReturnValue(() => {})), and harden the hook\ncleanup with a typeof check so a future mock omission degrades\ngracefully instead of throwing during unmount.",
"is_bot": false,
"headline": "Fix react-context-stability test suite broken by parallel PR merges (…",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-10T20:21:06Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c8b7664193b23d5b953cab54bce2fda0560628d8",
"body": "Debug output previously included full refresh/access/ID tokens, SRP\nsecret blocks, device keys and the OAuth state/PKCE challenge whenever\nan application wired the debug callback to console.log or a remote\nlogger. Add redactSecret and redactTokensFromObject helpers to\nclient/util.ts and apply them a\n[…]\nall, which still logged SECRET_BLOCK and DEVICE_KEY verbatim during\nremembered-device authentication, and the ConfirmDevice response log.\nA regression test covers the device challenge flow end to end.",
"is_bot": false,
"headline": "Redact tokens and device keys from debug logging (#78)",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-10T18:57:20Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e561cdb5e4cddcecb76707907e8ea92b94a25c96",
"body": "signOut's storage cleanup missed the per-user keys the library actually\nwrites: Passwordless.<clientId>.<username>.authMethod,\n.lastRefreshAttempt and .lastRefreshCompleted. A leftover\nlastRefreshAttempt written shortly before sign-out makes\nshouldAttemptRefresh veto the first refresh after an immed\n[…]\nthe .expireAt and\n.refreshingTokens removals as legacy-key migration hygiene, and add a\nregression test asserting no per-user residue remains after sign-out\n(while the remembered-device key persists).",
"is_bot": false,
"headline": "Remove leftover per-user storage keys on sign-out (#81)",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-10T18:56:56Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2a4526a12cf96d9d802033285da6e84b0dcbcae2",
"body": "… refresh (#55)\n\nrefreshTokens()/forceRefreshTokens() without an explicit tokens argument\nresolved the user and refresh token via retrieveTokens(), which returns\nundefined once the stored access token's exp is in the past. That made\nrefresh fail with \"Cannot determine user identity for refresh lock\"\n[…]\nen load, reuse-exception\nrecovery, cross-tab coordination helpers, forceRefreshTokens timer\nlookup) to retrieveTokensForRefresh(), which does not gate on\naccess-token expiry, and add regression tests.",
"is_bot": false,
"headline": "Use retrieveTokensForRefresh in refresh paths so expired sessions can…",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-10T18:56:19Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "26a244a7b52c02b1bf39d1a20c8be26be40a6359",
"body": "The storage lock could be double-acquired across tabs, causing\nconcurrent token refreshes and (with refresh-token rotation)\nRefreshTokenReuseException / session loss:\n\n- The storage event listener treated ANY foreign write to the lock key\n as a release, including another waiter's acquisition, so a \n[…]\nownership verify\nthat acquisition uses, standing down if a competing write landed after\nours. Release already only removes the key when it still holds our id,\nso a takeover survives release untouched.",
"is_bot": false,
"headline": "Fix cross-tab storage lock to enforce mutual exclusion (#54)",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-10T18:55:18Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "dbf43b14757a2a26a5feea20180cd94996e5ecb0",
"body": "The conditional-mediation fast path in prepareFido2SignIn called\ninitiateAuth (CUSTOM_AUTH) first and then awaited an indefinitely-pending\nautofill credentials.get(). Cognito invalidates the challenge session\nafter AuthSessionValidity minutes (3 by default), so any user picking an\nautofill passkey m\n[…]\nnvisible to the user. The loop stops when the credential resolves, on\nerror, or when the caller aborts. Also document the session-validity\nconstraint on PreparedFido2SignIn and the prepared parameter.",
"is_bot": false,
"headline": "Renew Cognito session while conditional passkey request is pending (#53)",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-10T18:54:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9c1327655c25cadb5a2203c51d105b2b916754fd",
"body": "…#52)\n\nBackground refreshes persist refreshed tokens via storeTokens, but the\nReact hook's only re-sync path was the \"storage\" event, which per the\nWHATWG HTML spec never fires in the document that performed the write.\nIn the active tab the hook therefore kept the stale access token until\nexpiry and\n[…]\nsubscribe in the React hook's\nmount effect to reload tokens from storage on same-context stores.\nThe subscription is removed on unmount and reloads are no-ops after\nabort. Public API is additive only.",
"is_bot": false,
"headline": "Propagate background token refresh into React state in the same tab (…",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-10T18:54:11Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c863424b2bab73e1acaa4c93b2875f935be53799",
"body": "… (#51)\n\nThe HKDF salt was derived from the raw SHA-256 digest hex of the\nscramble parameter u (leading zero bytes preserved), but Cognito's\nserver and the reference client (amazon-cognito-identity-js) encode u\nas a big integer: leading zero bytes stripped, with a '00' sign byte\nprepended only when \n[…]\n\narrayBufferToBigInt(uBuf).toString(16) passed through padHex, and add\nregression tests covering both the leading-zero-byte case and the\nsign-byte case against an independent reference implementation.",
"is_bot": false,
"headline": "Fix SRP HKDF salt to use big-integer encoding of scramble parameter u…",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-10T18:52:55Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b903644934969b054bb16443b434d1a678550cdc",
"body": "The unmount cleanup in useAwaitableState sets isMounted.current = false\nbut nothing ever set it back to true. Under React 18+ StrictMode's\nmount -> unmount -> remount cycle (default in dev), refs survive the\nsimulated remount, so resolve() and reject() — both guarded by\nisMounted.current — became pe\n[…]\naitable() returned a\npromise that never settled, hanging every MFA/new-password prompt flow\nin dev. Reset the flag in the effect body before returning the cleanup,\nand add StrictMode regression tests.",
"is_bot": false,
"headline": "Fix useAwaitableState hanging under React StrictMode (#72)",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-10T18:52:14Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2ec99f9e9d22c20257cf06e3f8282dcb0ccaa9ce",
"body": "Abort the SRP handshake when the server-supplied B is congruent to\n0 mod N (required by RFC 5054 section 2.5.3) or when the scramble\nparameter u is 0 (required by the SRP-6a design). Both checks live in\ncalculateSrpSignature so they cover the user-password and device-\npassword flows. Also make hexToArrayBuffer reject empty or non-hex\ninput with a descriptive error instead of throwing an opaque TypeError\nfrom a non-null assertion on a failed match.",
"is_bot": false,
"headline": "Add SRP-6a safety checks for B mod N and u, validate hex input (#73)",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-10T18:51:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c4dd0f6013a2d6be4fd921d63fcac2ef0b1b4fd0",
"body": "With tokenRefresh.useActivityTracking enabled, a 1s interval dispatched\nSET_NOW_TICK into the provider's reducer, and the derived\ntimeSinceLastActivityMs was a dep of the context useMemo — so the context\nvalue identity changed every second, re-rendering every usePasswordless()\nconsumer even if it ne\n[…]\n.\nAlso correct the inaccurate memo-deps comment claiming the API methods\nwere memoized with useCallback, and add render-count regression tests\ncovering the live fields and the config-flag propagation.",
"is_bot": false,
"headline": "Stop per-second context churn when activity tracking is enabled (#74)",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-10T18:51:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "67a926af658549c3888bfc665166d64986d200e6",
"body": "At device confirmation, x was hashed over the raw 16 random salt bytes\nand those raw bytes were uploaded in DeviceSecretVerifierConfig.Salt.\nCognito stores/echoes the salt as a big integer, so a salt with a\nleading zero byte (P ~ 1/128) came back stripped in the\nDEVICE_PASSWORD_VERIFIER SALT paramet\n[…]\nquals what the\nserver stores and echoes. The explicit top-bit masking is no longer\nneeded since padHex now provides the \"00\" sign prefix when the MSB is\nset, exactly like the reference implementation.",
"is_bot": false,
"headline": "Canonicalize device-verifier salt as big integer before hashing (#77)",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-10T18:49:45Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "57ce5dedcb68ac88cef7affb56a2af247155c75e",
"body": "The wait helper in createFetchWithRetry registered an \"abort\" listener\non the caller's AbortSignal for every backoff sleep, but { once: true }\nonly removes the listener when the signal actually aborts. When the\ntimer resolved normally, the listener stayed attached, so a long-lived\nsignal reused acro\n[…]\no the handler reference is shared by both\npaths: the timer callback now removes the abort listener before\nresolving, and the abort handler still clears the timer and rejects\nwith AbortError as before.",
"is_bot": false,
"headline": "Remove abort listener when retry backoff timer fires normally (#79)",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-10T18:48:37Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ff8d61545aee65751dc603ceaef9445cfc2b2f78",
"body": "…#80)\n\nThe catch-all in authenticateWithFido2 emitted FIDO2_SIGNIN_FAILED for\nevery error, including deliberate cancellations (Fido2AbortError from a\ncancelled WebAuthn ceremony, or an unwrapped DOMException AbortError\nescaping the Cognito fetch calls when the caller invokes the returned\nabort()). S\n[…]\nn-ins.\n\nNow the catch path detects abort errors and reverts the status to\nSIGNED_OUT (the idle state the flow started from) while still\nrethrowing, so callers' promise rejection behavior is unchanged.",
"is_bot": false,
"headline": "Report aborted FIDO2 sign-in as SIGNED_OUT, not FIDO2_SIGNIN_FAILED (…",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-10T18:48:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b476aef2cf9166fc9804e9f59d09d9ae619c0fe0",
"body": "The region regex /^[a-z]{2}-[a-z]+-\\d$/ in client/config.ts and\nclient/cognito-api.ts (AWS_REGION_REGEXP) only matched standard-partition\nregions. Multi-segment regions such as us-gov-west-1, us-gov-east-1\n(GovCloud) and eusc-de-east-1 (European Sovereign Cloud) were treated as\nhostnames instead: co\n[…]\nt-1 resolves to cognito-idp.eusc-de-east-1.amazonaws.eu\ninstead of the nonexistent .amazonaws.com host.\n\nAdds table-driven regression tests covering both code paths and the\nper-partition DNS suffixes.",
"is_bot": false,
"headline": "Broaden AWS region regex to support partitioned regions (#82)",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-10T18:47:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "dd6206ecc9351863db19d15581c8c4d101ed6069",
"body": "…nput (#83)\n\nbufferFromBase64Url threw a raw TypeError (\"Cannot read properties of\nnull\") on an empty string because String.match returns null, and silently\ndecoded garbage for characters outside the base64url alphabet. Decoders\nnow return an empty buffer for empty input and throw a clear Error for\n\n[…]\nted in the decoder as an unclassified TypeError instead of a\nFido2ValidationError. Both checks now reject empty strings.\n\nAdds regression tests for the decoder edge cases and the tightened\nvalidation.",
"is_bot": false,
"headline": "Harden base64url decoding and FIDO2 option validation against empty i…",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-10T18:46:26Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "416b979cf22bcb44007df0d438cdf103ca803046",
"body": "btoa() throws InvalidCharacterError for any customState containing\nnon-Latin1 characters (e.g. emoji or accented UTF-8 app state), aborting\nsign-in. It also emits \"+\", \"/\" and \"=\" which are not URL-safe. Encode\nthe customState as base64url of its UTF-8 bytes using the existing\nbufferToBase64Url help\n[…]\nn succeeds, split the random hex prefix\nfrom the base64url suffix, decode it, and return it as the optional\ncustomState field on the resolved TokensFromSignIn. Flows without\ncustomState are unchanged.",
"is_bot": false,
"headline": "Make OAuth customState UTF-8 safe and surface it on the callback (#84)",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-10T18:46:05Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "eb3a12b66630a5f8f4d220af1afe75fa7a9d1987",
"body": "signOut() retrieved the session via retrieveTokens(), which drops tokens\nwhose access token has expired as a safety net and returns undefined. So\nwhen a user signed out after their access token expired, signOut logged\n\"No tokens in storage to delete\", reported SIGNED_OUT, but left\nrefreshToken, Last\n[…]\ntests covering an expired access token with a valid\nrefresh token (storage cleared + token revoked) and access-only sessions\nwith no refresh token, both valid and expired (storage cleared, no\nrevoke).",
"is_bot": false,
"headline": "Fix signOut no-op when access token is already expired (#85)",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-06-10T18:45:33Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "43f19da4fa41954f658c6c5b3cf903e577fb5dda",
"body": null,
"is_bot": false,
"headline": "Bump version from 1.0.98 to 1.0.99",
"author_name": "GitHub Action",
"author_login": "actions-user",
"committed_at": "2026-05-31T15:48:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "155e8c1626900b1ce1efc0a1a64040afd53f7bda",
"body": "The enterprise Actions policy requires every action — including GitHub-owned\nones — to be pinned to a full-length commit SHA. Tags (actions/checkout@v4,\nactions/setup-node@v4) are rejected and the run fails at startup\n(startup_failure) before any step ran. This is what was blocking every\nworkflow_dispatch.\n\nPin to the latest releases:\n- actions/checkout -> de0fac2e4500dabe0009e67214ff5f5447ce83dd (v6.0.2)\n- actions/setup-node -> 48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e (v6.4.0)",
"is_bot": false,
"headline": "publish: pin actions to full-length commit SHAs (#50)",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-05-31T15:48:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3804d7efda2fe370c6ede669812ee5dc49fad8d1",
"body": "The repo restricts Actions to an allowlist (allowed_actions=selected) that\ndoes not include softprops/action-gh-release, so the publish workflow failed\nat startup (startup_failure) the moment it was dispatched.\n\nReplace that third-party action with the pre-installed gh CLI\n(`gh release create`), whi\n[…]\no allowlist entry and removes a\nthird-party dependency from the release path. Release-notes input is passed\nvia env to avoid shell injection, preserving the prior body + auto-generated\nnotes behavior.",
"is_bot": false,
"headline": "publish: create GitHub Release via gh CLI (allowlist-safe) (#49)",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-05-31T15:21:22Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2267d89cf502e2e15c5c39bf0d98d80f33119759",
"body": "…#48)\n\n* publish: use npm Trusted Publishing (OIDC) instead of NPM_TOKEN\n\nSwitch the npm publish step to OIDC-based Trusted Publishing:\n- add `id-token: write` permission (kept `contents: write` for the\n version commit/tag/push and GitHub release)\n- bump Node to 22.x and upgrade npm to >= 11.5.1 (T\n[…]\n\n default registry lets OIDC handle authentication.\n- Pin `npm@11.5.1` instead of `npm@latest` to avoid a mutable supply-chain\n dependency on the privileged (id-token + contents:write) release path.",
"is_bot": false,
"headline": "publish.yml: use npm Trusted Publishing (OIDC) instead of NPM_TOKEN (…",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-05-30T21:06:58Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ba586b6504029e13316a6455c31f491e73d4c9e8",
"body": "Bumps the npm_and_yarn group with 2 updates in the / directory: [minimatch](https://github.com/isaacs/minimatch) and [js-yaml](https://github.com/nodeca/js-yaml).\n\n\nUpdates `minimatch` from 3.1.2 to 3.1.5\n- [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md)\n- [Commits](https://g\n[…]\n dependency-type: indirect\n dependency-group: npm_and_yarn\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump the npm_and_yarn group across 1 directory with 2 updates (#47)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-29T19:32:05Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3a0011993c935c7a39d129471ebad23954c17988",
"body": "The library talks to Cognito entirely through its own fetch-based client\n(srp.ts, cognito-api.ts, hosted-oauth.ts). @aws-sdk/client-cognito-identity-provider\nis not imported anywhere in the source and is not re-exported from any\npackage entrypoint, so it is dead weight in the dependency tree.\n\nRemov\n[…]\nuntime behavior. This supersedes the lockfile-only bumps\nin #40/#39, which only churned versions of those same unused transitives.\n\nVerified: tsc (client/tsconfig) clean, full jest suite passes (182).",
"is_bot": false,
"headline": "Remove unused @aws-sdk/client-cognito-identity-provider dependency (#46)",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-05-29T19:27:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "702536390d4dcc2afd60b82dde6ea7b00722fd0f",
"body": "Bumps the npm_and_yarn group with 1 update in the / directory: [fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser).\n\n\nUpdates `fast-xml-parser` from 4.4.1 to 5.7.2\n- [Release notes](https://github.com/NaturalIntelligence/fast-xml-parser/releases)\n- [Changelog](https://github.co\n[…]\n dependency-type: indirect\n dependency-group: npm_and_yarn\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump fast-xml-parser in the npm_and_yarn group across 1 directory (#40)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-29T18:49:07Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "71e68e902f72f7d7c7d29e7bc0645c2e4aa39c15",
"body": "Bumps the npm_and_yarn group with 1 update in the / directory: [picomatch](https://github.com/micromatch/picomatch).\n\n\nUpdates `picomatch` from 2.3.1 to 2.3.2\n- [Release notes](https://github.com/micromatch/picomatch/releases)\n- [Changelog](https://github.com/micromatch/picomatch/blob/master/CHANGEL\n[…]\n dependency-type: indirect\n dependency-group: npm_and_yarn\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump picomatch in the npm_and_yarn group across 1 directory (#41)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-29T18:49:03Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2c90089fefd74841a0ae9087a07c9155c55dfba8",
"body": "Bumps the npm_and_yarn group with 1 update in the / directory: [flatted](https://github.com/WebReflection/flatted).\n\n\nUpdates `flatted` from 3.3.1 to 3.4.2\n- [Commits](https://github.com/WebReflection/flatted/compare/v3.3.1...v3.4.2)\n\n---\nupdated-dependencies:\n- dependency-name: flatted\n dependency\n[…]\n dependency-type: indirect\n dependency-group: npm_and_yarn\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump flatted in the npm_and_yarn group across 1 directory (#42)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-29T18:48:59Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a6a0e37bfa680ffe8fd0fcdf57061bb6179413ac",
"body": "…p login loop) (#43)\n\n* Tolerate client clock skew when validating token expiry\n\nA device whose clock is fast by more than the access token's lifetime\ntreated every freshly-issued token as already-expired: token validity\ncompared the server-issued `exp` claim against local `Date.now()` with no\nskew \n[…]\nCarry clockDriftMs over.\n- common.ts: signOut now removes the persisted clockDriftMs storage key\n alongside the other per-user keys.\n- test/clock-skew.test.ts: add a sign-out cleanup regression test.",
"is_bot": false,
"headline": "Tolerate client clock skew when validating token expiry (fixes deskto…",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2026-05-29T18:35:02Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9af1cbf6a0fe103ecc36288fc4c5b121609ec64a",
"body": null,
"is_bot": false,
"headline": "Bump version from 1.0.97 to 1.0.98",
"author_name": "GitHub Action",
"author_login": "actions-user",
"committed_at": "2025-11-04T18:21:47Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0a57c18aabc3b9561e24ffa62e5e3c617fd54a14",
"body": "* Ensure UI never hangs on MFA status loading failures\n\n* add silent retry for mfa status\n\n* run earlier",
"is_bot": false,
"headline": "Ensure UI never hangs on MFA status loading failures (#37)",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2025-11-04T18:21:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d9b10157e45c70316905bc7d6876048cd2f83f75",
"body": null,
"is_bot": false,
"headline": "Bump version from 1.0.96 to 1.0.97",
"author_name": "GitHub Action",
"author_login": "actions-user",
"committed_at": "2025-10-06T20:02:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8a35c15c5c03ac3e01ebfaaa4e202f65dde0d384",
"body": "* Add comprehensive debug logging for FIDO2 authentication flows\n\n* simpler flow\n\n* merge server and client credentials in auth flow",
"is_bot": false,
"headline": "Add comprehensive debug logging to FIDO2 authentication flows (#35)",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2025-10-06T20:01:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c076c2e3927ffe8eca2c2b419e83c3e7245be1f8",
"body": null,
"is_bot": false,
"headline": "Bump version from 1.0.95 to 1.0.96",
"author_name": "GitHub Action",
"author_login": "actions-user",
"committed_at": "2025-10-06T15:41:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "af05372cb331f705f18aea1b2164e0bd10244ca2",
"body": "… autofill (#34)\n\n* Add prepareFido2SignIn for WebAuthn conditional mediation and passkey autofill\n\n* update tests\n\n* handle case when username is different",
"is_bot": false,
"headline": "Add prepareFido2SignIn for WebAuthn conditional mediation and passkey…",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2025-10-06T15:40:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f73a826cdbfeb353fd2896f8df163267b29e6006",
"body": null,
"is_bot": false,
"headline": "Bump version from 1.0.94 to 1.0.95",
"author_name": "GitHub Action",
"author_login": "actions-user",
"committed_at": "2025-10-05T19:49:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "223c4a9afabc6d59845e02634cfb5f7d120f0fc0",
"body": "* Add WebAuthn conditional mediation and passkey autofill support\n\n* rm create mediation",
"is_bot": false,
"headline": "Add WebAuthn conditional mediation and passkey autofill support (#33)",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2025-10-05T19:49:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "61eab67deb8e3bfde3227879a19d676fafda481d",
"body": "…cation flows (#32)\n\n* Add support for conditional mediation and automatic passkey creation\n\n* proper types and immediate mode\n\n* refactor tests",
"is_bot": false,
"headline": "Add WebAuthn mediation support for conditional and immediate authenti…",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2025-10-05T19:13:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "112c801a45c9b7c0e4e0461d7eba07c7e76cc326",
"body": null,
"is_bot": false,
"headline": "Bump version from 1.0.93 to 1.0.94",
"author_name": "GitHub Action",
"author_login": "actions-user",
"committed_at": "2025-10-03T00:04:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2db9179d0f520cddab113ddbb48b3a05472b34a3",
"body": null,
"is_bot": false,
"headline": "fix build (#31)",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2025-10-03T00:03:47Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d893ddca8f3d8d96c5fe4eae45da25d67865dc7b",
"body": null,
"is_bot": false,
"headline": "Bump version from 1.0.92 to 1.0.93",
"author_name": "GitHub Action",
"author_login": "actions-user",
"committed_at": "2025-10-02T23:53:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f261fb4b0f035bc34eb10eaa513c6c3c6895159a",
"body": null,
"is_bot": false,
"headline": "user friendly error messages (#30)",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2025-10-02T23:52:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "59cc1a0dd9a9b2bd4e1b998db6f6829b6a9e4462",
"body": null,
"is_bot": false,
"headline": "Bump version from 1.0.91 to 1.0.92",
"author_name": "GitHub Action",
"author_login": "actions-user",
"committed_at": "2025-10-02T22:13:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1b7bb64e506e1a73049452b48c1e43a9e5e85c25",
"body": null,
"is_bot": false,
"headline": "export errors in package (#29)",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2025-10-02T22:12:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "eff8756a7a991f699f1bd2d70a506e67100314ff",
"body": null,
"is_bot": false,
"headline": "Bump version from 1.0.90 to 1.0.91",
"author_name": "GitHub Action",
"author_login": "actions-user",
"committed_at": "2025-10-02T21:53:18Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "01d5888f8e1efb51f8c9306b4e3cf70819088802",
"body": "* Add typed error handling with custom error classes for FIDO2/WebAuthn operations\n\n* tests and better runtime checker\n\n* add more tests",
"is_bot": false,
"headline": "Add typed error handling for WebAuthn operations (#28)",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2025-10-02T21:52:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8127dc061d49bbb7a9a8e63af927866db7588ada",
"body": null,
"is_bot": false,
"headline": "Bump version from 1.0.89 to 1.0.90",
"author_name": "GitHub Action",
"author_login": "actions-user",
"committed_at": "2025-09-09T20:17:05Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d4b74532af98697a58a40daee40885681e4e5812",
"body": null,
"is_bot": false,
"headline": "Bump version from 1.0.88 to 1.0.89",
"author_name": "GitHub Action",
"author_login": "actions-user",
"committed_at": "2025-09-09T19:58:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4eb658593dfde16f721fe218ef0c88c288ebad63",
"body": "* react: add reliable MFA readiness signal (mfaStatusReady)\n\n- Add mfaStatusReady to PasswordlessState and initialize to false\n- Extend action union with SET_MFA_STATUS_READY and reducer case\n- Include mfaStatusReady in context memo deps and hook state\n- Mark readiness true after successful getUser/\n[…]\nhat TOTP MFA status has been fetched and is current for the active access token.\n\n* test(react): increase hooks.tsx patch coverage (REDIRECT parsing, OAuth callback, error boundary, activity tracking)",
"is_bot": false,
"headline": "react: add reliable MFA readiness signal (mfaStatusReady) (#27)",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2025-09-09T19:57:35Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "94e2ed9173c40ef18a81049741d754e22454e74a",
"body": null,
"is_bot": false,
"headline": "Bump version from 1.0.87 to 1.0.88",
"author_name": "GitHub Action",
"author_login": "actions-user",
"committed_at": "2025-07-28T15:12:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4c8e57dac8821d98a05ca0692340e78a3311f8b8",
"body": "* Add grace period during token refresh to prevent temporary logout\n\n* Add grace period during token refresh to prevent temporary logout\n\nThis fix addresses the \"30-minute lottery bug\" where users were temporarily\nlogged out when their tokens expired during page navigation while refresh\nwas in progr\n[…]\nsers remain signed in during the refresh process,\npreventing the temporary logout that occurred in 0.08% of sessions.\n\n* Update hooks.tsx\n\n* prettier\n\n* fix NaN check\n\n* fix test to match source logic",
"is_bot": false,
"headline": "Add grace period during token refresh to prevent temporary logout (#25)",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2025-07-28T14:44:35Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "607fc3a657558e9b927d5ae8b0b90e328d85c47e",
"body": null,
"is_bot": false,
"headline": "Bump version from 1.0.86 to 1.0.87",
"author_name": "GitHub Action",
"author_login": "actions-user",
"committed_at": "2025-07-23T13:32:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "40dbb3794dd75dae31c306a54e55d4faf9d7bf03",
"body": null,
"is_bot": false,
"headline": "add more tests (#24)",
"author_name": "Amit Biswas",
"author_login": "akbisw",
"committed_at": "2025-07-23T13:31:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "dcdf7e57c0cce438e354307b1586e55a654a87e6",
"body": null,
"is_bot": false,
"headline": "Bump version from 1.0.85 to 1.0.86",
"author_name": "GitHub Action",
"author_login": "actions-user",
"committed_at": "2025-07-23T12:02:40Z",
"body_truncated": false,
"is_coding_agent": false
}
],
"releases_count": 96,
"commits_last_year": 97,
"latest_release_at": "2026-07-20T22:36:18Z",
"latest_release_tag": "v1.0.104",
"releases_from_tags": false,
"days_since_last_push": 4,
"active_weeks_last_year": 11,
"days_since_latest_release": 6,
"mean_days_between_releases": 32
},
"community": {
"has_readme": false,
"has_license": false,
"has_description": false,
"has_contributing": false,
"health_percentage": null,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"ecosystem": {
"packages": [
{
"name": "@joinmeow/cognito-passwordless-auth",
"exists": true,
"license": "Apache-2.0",
"keywords": [
"AWS",
"Cognito",
"FIDO2",
"Passwordless",
"WebAuthn",
"passkeys"
],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/@joinmeow/cognito-passwordless-auth",
"is_deprecated": false,
"latest_version": "1.0.104",
"repository_url": "https://github.com/joinmeow/amazon-cognito-passwordless-auth",
"versions_count": 100,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 2,
"monthly_downloads": 8713,
"first_published_at": "2025-04-23T17:21:03.075000Z",
"latest_published_at": "2026-07-20T22:36:16.595000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 6
}
]
},
"popularity": {
"forks": 0,
"stars": 0,
"watchers": 0,
"fork_history": {
"days": [],
"complete": true,
"collected": 0,
"total_forks": 0
},
"star_history": {
"days": [],
"complete": true,
"collected": 0,
"total_stars": 0,
"collected_at": null
},
"open_issues_and_prs": 1
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [],
"has_llms_txt": false,
"has_dockerfile": false,
"has_mcp_signal": false,
"bootstrap_files": [],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [
"client/tsconfig.json"
],
"toolchain_manifests": [],
"largest_source_bytes": 96149,
"source_files_sampled": 92,
"oversized_source_files": 3,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"dependencies": {
"manifests": [
"package.json"
],
"advisories": {
"error": null,
"scope": "published_package",
"source": "osv",
"findings": [],
"collected": true,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 3,
"malicious_count": 0,
"assessed_package": "npm:@joinmeow/cognito-passwordless-auth@1.0.104",
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"npm"
],
"dependencies": [
{
"name": "aws-jwt-verify",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^4.0.1"
},
{
"name": "cbor",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^9.0.2"
}
],
"all_dependencies": {
"error": null,
"source": "github-sbom",
"packages": [
{
"name": "aws-jwt-verify",
"direct": true,
"version": "4.0.1",
"ecosystem": "npm"
},
{
"name": "cbor",
"direct": true,
"version": "9.0.2",
"ecosystem": "npm"
},
{
"name": "@ampproject/remapping",
"direct": false,
"version": "2.3.0",
"ecosystem": "npm"
},
{
"name": "@asamuzakjp/css-color",
"direct": false,
"version": "3.2.0",
"ecosystem": "npm"
},
{
"name": "@babel/code-frame",
"direct": false,
"version": "7.27.1",
"ecosystem": "npm"
},
{
"name": "@babel/compat-data",
"direct": false,
"version": "7.27.3",
"ecosystem": "npm"
},
{
"name": "@babel/core",
"direct": false,
"version": "7.27.3",
"ecosystem": "npm"
},
{
"name": "@babel/generator",
"direct": false,
"version": "7.27.3",
"ecosystem": "npm"
},
{
"name": "@babel/helper-compilation-targets",
"direct": false,
"version": "7.27.2",
"ecosystem": "npm"
},
{
"name": "@babel/helper-module-imports",
"direct": false,
"version": "7.27.1",
"ecosystem": "npm"
},
{
"name": "@babel/helper-module-transforms",
"direct": false,
"version": "7.27.3",
"ecosystem": "npm"
},
{
"name": "@babel/helper-plugin-utils",
"direct": false,
"version": "7.27.1",
"ecosystem": "npm"
},
{
"name": "@babel/helper-string-parser",
"direct": false,
"version": "7.27.1",
"ecosystem": "npm"
},
{
"name": "@babel/helper-validator-identifier",
"direct": false,
"version": "7.27.1",
"ecosystem": "npm"
},
{
"name": "@babel/helper-validator-option",
"direct": false,
"version": "7.27.1",
"ecosystem": "npm"
},
{
"name": "@babel/helpers",
"direct": false,
"version": "7.27.3",
"ecosystem": "npm"
},
{
"name": "@babel/parser",
"direct": false,
"version": "7.27.3",
"ecosystem": "npm"
},
{
"name": "@babel/plugin-syntax-async-generators",
"direct": false,
"version": "7.8.4",
"ecosystem": "npm"
},
{
"name": "@babel/plugin-syntax-bigint",
"direct": false,
"version": "7.8.3",
"ecosystem": "npm"
},
{
"name": "@babel/plugin-syntax-class-properties",
"direct": false,
"version": "7.12.13",
"ecosystem": "npm"
},
{
"name": "@babel/plugin-syntax-class-static-block",
"direct": false,
"version": "7.14.5",
"ecosystem": "npm"
},
{
"name": "@babel/plugin-syntax-import-attributes",
"direct": false,
"version": "7.27.1",
"ecosystem": "npm"
},
{
"name": "@babel/plugin-syntax-import-meta",
"direct": false,
"version": "7.10.4",
"ecosystem": "npm"
},
{
"name": "@babel/plugin-syntax-json-strings",
"direct": false,
"version": "7.8.3",
"ecosystem": "npm"
},
{
"name": "@babel/plugin-syntax-jsx",
"direct": false,
"version": "7.27.1",
"ecosystem": "npm"
},
{
"name": "@babel/plugin-syntax-logical-assignment-operators",
"direct": false,
"version": "7.10.4",
"ecosystem": "npm"
},
{
"name": "@babel/plugin-syntax-nullish-coalescing-operator",
"direct": false,
"version": "7.8.3",
"ecosystem": "npm"
},
{
"name": "@babel/plugin-syntax-numeric-separator",
"direct": false,
"version": "7.10.4",
"ecosystem": "npm"
},
{
"name": "@babel/plugin-syntax-object-rest-spread",
"direct": false,
"version": "7.8.3",
"ecosystem": "npm"
},
{
"name": "@babel/plugin-syntax-optional-catch-binding",
"direct": false,
"version": "7.8.3",
"ecosystem": "npm"
},
{
"name": "@babel/plugin-syntax-optional-chaining",
"direct": false,
"version": "7.8.3",
"ecosystem": "npm"
},
{
"name": "@babel/plugin-syntax-private-property-in-object",
"direct": false,
"version": "7.14.5",
"ecosystem": "npm"
},
{
"name": "@babel/plugin-syntax-top-level-await",
"direct": false,
"version": "7.14.5",
"ecosystem": "npm"
},
{
"name": "@babel/plugin-syntax-typescript",
"direct": false,
"version": "7.27.1",
"ecosystem": "npm"
},
{
"name": "@babel/runtime",
"direct": false,
"version": "7.27.6",
"ecosystem": "npm"
},
{
"name": "@babel/template",
"direct": false,
"version": "7.27.2",
"ecosystem": "npm"
},
{
"name": "@babel/traverse",
"direct": false,
"version": "7.27.3",
"ecosystem": "npm"
},
{
"name": "@babel/types",
"direct": false,
"version": "7.27.3",
"ecosystem": "npm"
},
{
"name": "@bcoe/v8-coverage",
"direct": false,
"version": "0.2.3",
"ecosystem": "npm"
},
{
"name": "@cspotcode/source-map-support",
"direct": false,
"version": "0.8.1",
"ecosystem": "npm"
},
{
"name": "@csstools/color-helpers",
"direct": false,
"version": "5.0.2",
"ecosystem": "npm"
},
{
"name": "@csstools/css-calc",
"direct": false,
"version": "2.1.4",
"ecosystem": "npm"
},
{
"name": "@csstools/css-color-parser",
"direct": false,
"version": "3.0.10",
"ecosystem": "npm"
},
{
"name": "@csstools/css-parser-algorithms",
"direct": false,
"version": "3.0.5",
"ecosystem": "npm"
},
{
"name": "@csstools/css-tokenizer",
"direct": false,
"version": "3.0.4",
"ecosystem": "npm"
},
{
"name": "@esbuild/aix-ppc64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/android-arm",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/android-arm64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/android-x64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/darwin-arm64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/darwin-x64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/freebsd-arm64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/freebsd-x64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-arm",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-arm64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-ia32",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-loong64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-mips64el",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-ppc64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-riscv64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-s390x",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-x64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/netbsd-arm64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/netbsd-x64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/openbsd-arm64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/openbsd-x64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/openharmony-arm64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/sunos-x64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/win32-arm64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/win32-ia32",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/win32-x64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@eslint-community/eslint-utils",
"direct": false,
"version": "4.4.0",
"ecosystem": "npm"
},
{
"name": "@eslint-community/regexpp",
"direct": false,
"version": "4.10.1",
"ecosystem": "npm"
},
{
"name": "@eslint/eslintrc",
"direct": false,
"version": "2.1.4",
"ecosystem": "npm"
},
{
"name": "@eslint/js",
"direct": false,
"version": "8.57.0",
"ecosystem": "npm"
},
{
"name": "@humanwhocodes/config-array",
"direct": false,
"version": "0.11.14",
"ecosystem": "npm"
},
{
"name": "@humanwhocodes/module-importer",
"direct": false,
"version": "1.0.1",
"ecosystem": "npm"
},
{
"name": "@humanwhocodes/object-schema",
"direct": false,
"version": "2.0.3",
"ecosystem": "npm"
},
{
"name": "@istanbuljs/load-nyc-config",
"direct": false,
"version": "1.1.0",
"ecosystem": "npm"
},
{
"name": "@istanbuljs/schema",
"direct": false,
"version": "0.1.3",
"ecosystem": "npm"
},
{
"name": "@jest/console",
"direct": false,
"version": "29.7.0",
"ecosystem": "npm"
},
{
"name": "@jest/core",
"direct": false,
"version": "29.7.0",
"ecosystem": "npm"
},
{
"name": "@jest/environment",
"direct": false,
"version": "29.7.0",
"ecosystem": "npm"
},
{
"name": "@jest/environment",
"direct": false,
"version": "30.0.0-beta.3",
"ecosystem": "npm"
},
{
"name": "@jest/environment-jsdom-abstract",
"direct": false,
"version": "30.0.0-beta.3",
"ecosystem": "npm"
},
{
"name": "@jest/expect",
"direct": false,
"version": "29.7.0",
"ecosystem": "npm"
},
{
"name": "@jest/expect-utils",
"direct": false,
"version": "29.7.0",
"ecosystem": "npm"
},
{
"name": "@jest/fake-timers",
"direct": false,
"version": "29.7.0",
"ecosystem": "npm"
},
{
"name": "@jest/fake-timers",
"direct": false,
"version": "30.0.0-beta.3",
"ecosystem": "npm"
},
{
"name": "@jest/globals",
"direct": false,
"version": "29.7.0",
"ecosystem": "npm"
},
{
"name": "@jest/pattern",
"direct": false,
"version": "30.0.0-beta.3",
"ecosystem": "npm"
},
{
"name": "@jest/reporters",
"direct": false,
"version": "29.7.0",
"ecosystem": "npm"
},
{
"name": "@jest/schemas",
"direct": false,
"version": "29.6.3",
"ecosystem": "npm"
},
{
"name": "@jest/schemas",
"direct": false,
"version": "30.0.0-beta.3",
"ecosystem": "npm"
},
{
"name": "@jest/source-map",
"direct": false,
"version": "29.6.3",
"ecosystem": "npm"
},
{
"name": "@jest/test-result",
"direct": false,
"version": "29.7.0",
"ecosystem": "npm"
},
{
"name": "@jest/test-sequencer",
"direct": false,
"version": "29.7.0",
"ecosystem": "npm"
},
{
"name": "@jest/transform",
"direct": false,
"version": "29.7.0",
"ecosystem": "npm"
},
{
"name": "@jest/types",
"direct": false,
"version": "29.6.3",
"ecosystem": "npm"
},
{
"name": "@jest/types",
"direct": false,
"version": "30.0.0-beta.3",
"ecosystem": "npm"
},
{
"name": "@jridgewell/gen-mapping",
"direct": false,
"version": "0.3.8",
"ecosystem": "npm"
},
{
"name": "@jridgewell/resolve-uri",
"direct": false,
"version": "3.1.2",
"ecosystem": "npm"
},
{
"name": "@jridgewell/set-array",
"direct": false,
"version": "1.2.1",
"ecosystem": "npm"
},
{
"name": "@jridgewell/sourcemap-codec",
"direct": false,
"version": "1.4.15",
"ecosystem": "npm"
},
{
"name": "@jridgewell/trace-mapping",
"direct": false,
"version": "0.3.25",
"ecosystem": "npm"
},
{
"name": "@jridgewell/trace-mapping",
"direct": false,
"version": "0.3.9",
"ecosystem": "npm"
},
{
"name": "@nodelib/fs.scandir",
"direct": false,
"version": "2.1.5",
"ecosystem": "npm"
},
{
"name": "@nodelib/fs.stat",
"direct": false,
"version": "2.0.5",
"ecosystem": "npm"
},
{
"name": "@nodelib/fs.walk",
"direct": false,
"version": "1.2.8",
"ecosystem": "npm"
},
{
"name": "@sinclair/typebox",
"direct": false,
"version": "0.27.8",
"ecosystem": "npm"
},
{
"name": "@sinclair/typebox",
"direct": false,
"version": "0.34.33",
"ecosystem": "npm"
},
{
"name": "@sinonjs/commons",
"direct": false,
"version": "3.0.1",
"ecosystem": "npm"
},
{
"name": "@sinonjs/fake-timers",
"direct": false,
"version": "10.3.0",
"ecosystem": "npm"
},
{
"name": "@sinonjs/fake-timers",
"direct": false,
"version": "13.0.5",
"ecosystem": "npm"
},
{
"name": "@testing-library/dom",
"direct": false,
"version": "10.4.0",
"ecosystem": "npm"
},
{
"name": "@testing-library/react",
"direct": false,
"version": "16.3.0",
"ecosystem": "npm"
},
{
"name": "@tsconfig/node10",
"direct": false,
"version": "1.0.11",
"ecosystem": "npm"
},
{
"name": "@tsconfig/node12",
"direct": false,
"version": "1.0.11",
"ecosystem": "npm"
},
{
"name": "@tsconfig/node14",
"direct": false,
"version": "1.0.3",
"ecosystem": "npm"
},
{
"name": "@tsconfig/node16",
"direct": false,
"version": "1.0.4",
"ecosystem": "npm"
},
{
"name": "@types/aria-query",
"direct": false,
"version": "5.0.4",
"ecosystem": "npm"
},
{
"name": "@types/babel__core",
"direct": false,
"version": "7.20.5",
"ecosystem": "npm"
},
{
"name": "@types/babel__generator",
"direct": false,
"version": "7.27.0",
"ecosystem": "npm"
},
{
"name": "@types/babel__template",
"direct": false,
"version": "7.4.4",
"ecosystem": "npm"
},
{
"name": "@types/babel__traverse",
"direct": false,
"version": "7.20.7",
"ecosystem": "npm"
},
{
"name": "@types/graceful-fs",
"direct": false,
"version": "4.1.9",
"ecosystem": "npm"
},
{
"name": "@types/istanbul-lib-coverage",
"direct": false,
"version": "2.0.6",
"ecosystem": "npm"
},
{
"name": "@types/istanbul-lib-report",
"direct": false,
"version": "3.0.3",
"ecosystem": "npm"
},
{
"name": "@types/istanbul-reports",
"direct": false,
"version": "3.0.4",
"ecosystem": "npm"
},
{
"name": "@types/jest",
"direct": false,
"version": "29.5.14",
"ecosystem": "npm"
},
{
"name": "@types/jsdom",
"direct": false,
"version": "21.1.7",
"ecosystem": "npm"
},
{
"name": "@types/json5",
"direct": false,
"version": "0.0.29",
"ecosystem": "npm"
},
{
"name": "@types/node",
"direct": false,
"version": "20.14.5",
"ecosystem": "npm"
},
{
"name": "@types/prop-types",
"direct": false,
"version": "15.7.12",
"ecosystem": "npm"
},
{
"name": "@types/react",
"direct": false,
"version": "18.3.3",
"ecosystem": "npm"
},
{
"name": "@types/stack-utils",
"direct": false,
"version": "2.0.3",
"ecosystem": "npm"
},
{
"name": "@types/tough-cookie",
"direct": false,
"version": "4.0.5",
"ecosystem": "npm"
},
{
"name": "@types/yargs",
"direct": false,
"version": "17.0.33",
"ecosystem": "npm"
},
{
"name": "@types/yargs-parser",
"direct": false,
"version": "21.0.3",
"ecosystem": "npm"
},
{
"name": "@typescript-eslint/eslint-plugin",
"direct": false,
"version": "7.13.1",
"ecosystem": "npm"
},
{
"name": "@typescript-eslint/parser",
"direct": false,
"version": "7.13.1",
"ecosystem": "npm"
},
{
"name": "@typescript-eslint/scope-manager",
"direct": false,
"version": "7.13.1",
"ecosystem": "npm"
},
{
"name": "@typescript-eslint/type-utils",
"direct": false,
"version": "7.13.1",
"ecosystem": "npm"
},
{
"name": "@typescript-eslint/types",
"direct": false,
"version": "7.13.1",
"ecosystem": "npm"
},
{
"name": "@typescript-eslint/typescript-estree",
"direct": false,
"version": "7.13.1",
"ecosystem": "npm"
},
{
"name": "@typescript-eslint/utils",
"direct": false,
"version": "7.13.1",
"ecosystem": "npm"
},
{
"name": "@typescript-eslint/visitor-keys",
"direct": false,
"version": "7.13.1",
"ecosystem": "npm"
},
{
"name": "@ungap/structured-clone",
"direct": false,
"version": "1.2.0",
"ecosystem": "npm"
},
{
"name": "acorn",
"direct": false,
"version": "8.12.0",
"ecosystem": "npm"
},
{
"name": "acorn-jsx",
"direct": false,
"version": "5.3.2",
"ecosystem": "npm"
},
{
"name": "acorn-walk",
"direct": false,
"version": "8.3.3",
"ecosystem": "npm"
},
{
"name": "agent-base",
"direct": false,
"version": "7.1.3",
"ecosystem": "npm"
},
{
"name": "ajv",
"direct": false,
"version": "6.12.6",
"ecosystem": "npm"
},
{
"name": "ansi-escapes",
"direct": false,
"version": "4.3.2",
"ecosystem": "npm"
},
{
"name": "ansi-escapes",
"direct": false,
"version": "7.0.0",
"ecosystem": "npm"
},
{
"name": "ansi-regex",
"direct": false,
"version": "5.0.1",
"ecosystem": "npm"
},
{
"name": "ansi-regex",
"direct": false,
"version": "6.1.0",
"ecosystem": "npm"
},
{
"name": "ansi-styles",
"direct": false,
"version": "4.3.0",
"ecosystem": "npm"
},
{
"name": "ansi-styles",
"direct": false,
"version": "5.2.0",
"ecosystem": "npm"
},
{
"name": "ansi-styles",
"direct": false,
"version": "6.2.1",
"ecosystem": "npm"
},
{
"name": "anymatch",
"direct": false,
"version": "3.1.3",
"ecosystem": "npm"
},
{
"name": "arg",
"direct": false,
"version": "4.1.3",
"ecosystem": "npm"
},
{
"name": "argparse",
"direct": false,
"version": "1.0.10",
"ecosystem": "npm"
},
{
"name": "argparse",
"direct": false,
"version": "2.0.1",
"ecosystem": "npm"
},
{
"name": "aria-query",
"direct": false,
"version": "5.3.0",
"ecosystem": "npm"
},
{
"name": "array-buffer-byte-length",
"direct": false,
"version": "1.0.1",
"ecosystem": "npm"
},
{
"name": "array-includes",
"direct": false,
"version": "3.1.8",
"ecosystem": "npm"
},
{
"name": "array-union",
"direct": false,
"version": "2.1.0",
"ecosystem": "npm"
},
{
"name": "array.prototype.findlast",
"direct": false,
"version": "1.2.5",
"ecosystem": "npm"
},
{
"name": "array.prototype.findlastindex",
"direct": false,
"version": "1.2.5",
"ecosystem": "npm"
},
{
"name": "array.prototype.flat",
"direct": false,
"version": "1.3.2",
"ecosystem": "npm"
},
{
"name": "array.prototype.flatmap",
"direct": false,
"version": "1.3.2",
"ecosystem": "npm"
},
{
"name": "array.prototype.toreversed",
"direct": false,
"version": "1.1.2",
"ecosystem": "npm"
},
{
"name": "array.prototype.tosorted",
"direct": false,
"version": "1.1.4",
"ecosystem": "npm"
},
{
"name": "arraybuffer.prototype.slice",
"direct": false,
"version": "1.0.3",
"ecosystem": "npm"
},
{
"name": "async",
"direct": false,
"version": "3.2.6",
"ecosystem": "npm"
},
{
"name": "available-typed-arrays",
"direct": false,
"version": "1.0.7",
"ecosystem": "npm"
},
{
"name": "babel-jest",
"direct": false,
"version": "29.7.0",
"ecosystem": "npm"
},
{
"name": "babel-plugin-istanbul",
"direct": false,
"version": "6.1.1",
"ecosystem": "npm"
},
{
"name": "babel-plugin-jest-hoist",
"direct": false,
"version": "29.6.3",
"ecosystem": "npm"
},
{
"name": "babel-preset-current-node-syntax",
"direct": false,
"version": "1.1.0",
"ecosystem": "npm"
},
{
"name": "babel-preset-jest",
"direct": false,
"version": "29.6.3",
"ecosystem": "npm"
},
{
"name": "balanced-match",
"direct": false,
"version": "1.0.2",
"ecosystem": "npm"
},
{
"name": "brace-expansion",
"direct": false,
"version": "1.1.11",
"ecosystem": "npm"
},
{
"name": "brace-expansion",
"direct": false,
"version": "2.1.1",
"ecosystem": "npm"
},
{
"name": "braces",
"direct": false,
"version": "3.0.3",
"ecosystem": "npm"
},
{
"name": "browserslist",
"direct": false,
"version": "4.25.0",
"ecosystem": "npm"
},
{
"name": "bs-logger",
"direct": false,
"version": "0.2.6",
"ecosystem": "npm"
},
{
"name": "bser",
"direct": false,
"version": "2.1.1",
"ecosystem": "npm"
},
{
"name": "buffer-from",
"direct": false,
"version": "1.1.2",
"ecosystem": "npm"
},
{
"name": "call-bind",
"direct": false,
"version": "1.0.7",
"ecosystem": "npm"
},
{
"name": "callsites",
"direct": false,
"version": "3.1.0",
"ecosystem": "npm"
},
{
"name": "camelcase",
"direct": false,
"version": "5.3.1",
"ecosystem": "npm"
},
{
"name": "camelcase",
"direct": false,
"version": "6.3.0",
"ecosystem": "npm"
},
{
"name": "caniuse-lite",
"direct": false,
"version": "1.0.30001720",
"ecosystem": "npm"
},
{
"name": "chalk",
"direct": false,
"version": "4.1.2",
"ecosystem": "npm"
},
{
"name": "chalk",
"direct": false,
"version": "5.4.1",
"ecosystem": "npm"
},
{
"name": "char-regex",
"direct": false,
"version": "1.0.2",
"ecosystem": "npm"
},
{
"name": "ci-info",
"direct": false,
"version": "3.9.0",
"ecosystem": "npm"
},
{
"name": "ci-info",
"direct": false,
"version": "4.2.0",
"ecosystem": "npm"
},
{
"name": "cjs-module-lexer",
"direct": false,
"version": "1.4.3",
"ecosystem": "npm"
},
{
"name": "cli-cursor",
"direct": false,
"version": "5.0.0",
"ecosystem": "npm"
},
{
"name": "cli-truncate",
"direct": false,
"version": "4.0.0",
"ecosystem": "npm"
},
{
"name": "cliui",
"direct": false,
"version": "8.0.1",
"ecosystem": "npm"
},
{
"name": "co",
"direct": false,
"version": "4.6.0",
"ecosystem": "npm"
},
{
"name": "collect-v8-coverage",
"direct": false,
"version": "1.0.2",
"ecosystem": "npm"
},
{
"name": "color-convert",
"direct": false,
"version": "2.0.1",
"ecosystem": "npm"
},
{
"name": "color-name",
"direct": false,
"version": "1.1.4",
"ecosystem": "npm"
},
{
"name": "colorette",
"direct": false,
"version": "2.0.20",
"ecosystem": "npm"
},
{
"name": "commander",
"direct": false,
"version": "14.0.0",
"ecosystem": "npm"
},
{
"name": "concat-map",
"direct": false,
"version": "0.0.1",
"ecosystem": "npm"
},
{
"name": "convert-source-map",
"direct": false,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "create-jest",
"direct": false,
"version": "29.7.0",
"ecosystem": "npm"
},
{
"name": "create-require",
"direct": false,
"version": "1.1.1",
"ecosystem": "npm"
},
{
"name": "cross-spawn",
"direct": false,
"version": "7.0.6",
"ecosystem": "npm"
},
{
"name": "cssstyle",
"direct": false,
"version": "4.3.1",
"ecosystem": "npm"
},
{
"name": "csstype",
"direct": false,
"version": "3.1.3",
"ecosystem": "npm"
},
{
"name": "data-urls",
"direct": false,
"version": "5.0.0",
"ecosystem": "npm"
},
{
"name": "data-view-buffer",
"direct": false,
"version": "1.0.1",
"ecosystem": "npm"
},
{
"name": "data-view-byte-length",
"direct": false,
"version": "1.0.1",
"ecosystem": "npm"
},
{
"name": "data-view-byte-offset",
"direct": false,
"version": "1.0.0",
"ecosystem": "npm"
},
{
"name": "debug",
"direct": false,
"version": "3.2.7",
"ecosystem": "npm"
},
{
"name": "debug",
"direct": false,
"version": "4.4.1",
"ecosystem": "npm"
},
{
"name": "decimal.js",
"direct": false,
"version": "10.5.0",
"ecosystem": "npm"
},
{
"name": "dedent",
"direct": false,
"version": "1.6.0",
"ecosystem": "npm"
},
{
"name": "deep-is",
"direct": false,
"version": "0.1.4",
"ecosystem": "npm"
},
{
"name": "deepmerge",
"direct": false,
"version": "4.3.1",
"ecosystem": "npm"
},
{
"name": "define-data-property",
"direct": false,
"version": "1.1.4",
"ecosystem": "npm"
},
{
"name": "define-properties",
"direct": false,
"version": "1.2.1",
"ecosystem": "npm"
},
{
"name": "dequal",
"direct": false,
"version": "2.0.3",
"ecosystem": "npm"
},
{
"name": "detect-newline",
"direct": false,
"version": "3.1.0",
"ecosystem": "npm"
},
{
"name": "diff",
"direct": false,
"version": "4.0.2",
"ecosystem": "npm"
},
{
"name": "diff-sequences",
"direct": false,
"version": "29.6.3",
"ecosystem": "npm"
},
{
"name": "dir-glob",
"direct": false,
"version": "3.0.1",
"ecosystem": "npm"
},
{
"name": "doctrine",
"direct": false,
"version": "2.1.0",
"ecosystem": "npm"
},
{
"name": "doctrine",
"direct": false,
"version": "3.0.0",
"ecosystem": "npm"
},
{
"name": "dom-accessibility-api",
"direct": false,
"version": "0.5.16",
"ecosystem": "npm"
},
{
"name": "ejs",
"direct": false,
"version": "3.1.10",
"ecosystem": "npm"
},
{
"name": "electron-to-chromium",
"direct": false,
"version": "1.5.161",
"ecosystem": "npm"
},
{
"name": "emittery",
"direct": false,
"version": "0.13.1",
"ecosystem": "npm"
},
{
"name": "emoji-regex",
"direct": false,
"version": "10.4.0",
"ecosystem": "npm"
},
{
"name": "emoji-regex",
"direct": false,
"version": "8.0.0",
"ecosystem": "npm"
},
{
"name": "entities",
"direct": false,
"version": "6.0.0",
"ecosystem": "npm"
},
{
"name": "environment",
"direct": false,
"version": "1.1.0",
"ecosystem": "npm"
},
{
"name": "error-ex",
"direct": false,
"version": "1.3.2",
"ecosystem": "npm"
},
{
"name": "es-abstract",
"direct": false,
"version": "1.23.3",
"ecosystem": "npm"
},
{
"name": "es-define-property",
"direct": false,
"version": "1.0.0",
"ecosystem": "npm"
},
{
"name": "es-errors",
"direct": false,
"version": "1.3.0",
"ecosystem": "npm"
},
{
"name": "es-iterator-helpers",
"direct": false,
"version": "1.0.19",
"ecosystem": "npm"
},
{
"name": "es-object-atoms",
"direct": false,
"version": "1.0.0",
"ecosystem": "npm"
},
{
"name": "es-set-tostringtag",
"direct": false,
"version": "2.0.3",
"ecosystem": "npm"
},
{
"name": "es-shim-unscopables",
"direct": false,
"version": "1.0.2",
"ecosystem": "npm"
},
{
"name": "es-to-primitive",
"direct": false,
"version": "1.2.1",
"ecosystem": "npm"
},
{
"name": "esbuild",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "escalade",
"direct": false,
"version": "3.2.0",
"ecosystem": "npm"
},
{
"name": "escape-string-regexp",
"direct": false,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "escape-string-regexp",
"direct": false,
"version": "4.0.0",
"ecosystem": "npm"
},
{
"name": "eslint",
"direct": false,
"version": "8.57.0",
"ecosystem": "npm"
},
{
"name": "eslint-import-resolver-node",
"direct": false,
"version": "0.3.9",
"ecosystem": "npm"
},
{
"name": "eslint-module-utils",
"direct": false,
"version": "2.8.1",
"ecosystem": "npm"
},
{
"name": "eslint-plugin-header",
"direct": false,
"version": "3.1.1",
"ecosystem": "npm"
},
{
"name": "eslint-plugin-import",
"direct": false,
"version": "2.29.1",
"ecosystem": "npm"
},
{
"name": "eslint-plugin-react",
"direct": false,
"version": "7.34.2",
"ecosystem": "npm"
},
{
"name": "eslint-plugin-react-hooks",
"direct": false,
"version": "4.6.2",
"ecosystem": "npm"
},
{
"name": "eslint-plugin-security",
"direct": false,
"version": "3.0.1",
"ecosystem": "npm"
},
{
"name": "eslint-scope",
"direct": false,
"version": "7.2.2",
"ecosystem": "npm"
},
{
"name": "eslint-visitor-keys",
"direct": false,
"version": "3.4.3",
"ecosystem": "npm"
},
{
"name": "espree",
"direct": false,
"version": "9.6.1",
"ecosystem": "npm"
},
{
"name": "esprima",
"direct": false,
"version": "4.0.1",
"ecosystem": "npm"
},
{
"name": "esquery",
"direct": false,
"version": "1.5.0",
"ecosystem": "npm"
},
{
"name": "esrecurse",
"direct": false,
"version": "4.3.0",
"ecosystem": "npm"
},
{
"name": "estraverse",
"direct": false,
"version": "5.3.0",
"ecosystem": "npm"
},
{
"name": "esutils",
"direct": false,
"version": "2.0.3",
"ecosystem": "npm"
},
{
"name": "eventemitter3",
"direct": false,
"version": "5.0.1",
"ecosystem": "npm"
},
{
"name": "execa",
"direct": false,
"version": "5.1.1",
"ecosystem": "npm"
},
{
"name": "exit",
"direct": false,
"version": "0.1.2",
"ecosystem": "npm"
},
{
"name": "expect",
"direct": false,
"version": "29.7.0",
"ecosystem": "npm"
},
{
"name": "fast-deep-equal",
"direct": false,
"version": "3.1.3",
"ecosystem": "npm"
},
{
"name": "fast-glob",
"direct": false,
"version": "3.3.2",
"ecosystem": "npm"
},
{
"name": "fast-json-stable-stringify",
"direct": false,
"version": "2.1.0",
"ecosystem": "npm"
},
{
"name": "fast-levenshtein",
"direct": false,
"version": "2.0.6",
"ecosystem": "npm"
},
{
"name": "fastq",
"direct": false,
"version": "1.17.1",
"ecosystem": "npm"
},
{
"name": "fb-watchman",
"direct": false,
"version": "2.0.2",
"ecosystem": "npm"
},
{
"name": "file-entry-cache",
"direct": false,
"version": "6.0.1",
"ecosystem": "npm"
},
{
"name": "filelist",
"direct": false,
"version": "1.0.4",
"ecosystem": "npm"
},
{
"name": "fill-range",
"direct": false,
"version": "7.1.1",
"ecosystem": "npm"
},
{
"name": "find-up",
"direct": false,
"version": "4.1.0",
"ecosystem": "npm"
},
{
"name": "find-up",
"direct": false,
"version": "5.0.0",
"ecosystem": "npm"
},
{
"name": "flat-cache",
"direct": false,
"version": "3.2.0",
"ecosystem": "npm"
},
{
"name": "flatted",
"direct": false,
"version": "3.4.2",
"ecosystem": "npm"
},
{
"name": "for-each",
"direct": false,
"version": "0.3.3",
"ecosystem": "npm"
},
{
"name": "fs.realpath",
"direct": false,
"version": "1.0.0",
"ecosystem": "npm"
},
{
"name": "fsevents",
"direct": false,
"version": "2.3.3",
"ecosystem": "npm"
},
{
"name": "function-bind",
"direct": false,
"version": "1.1.2",
"ecosystem": "npm"
},
{
"name": "function.prototype.name",
"direct": false,
"version": "1.1.6",
"ecosystem": "npm"
},
{
"name": "functions-have-names",
"direct": false,
"version": "1.2.3",
"ecosystem": "npm"
},
{
"name": "gensync",
"direct": false,
"version": "1.0.0-beta.2",
"ecosystem": "npm"
},
{
"name": "get-caller-file",
"direct": false,
"version": "2.0.5",
"ecosystem": "npm"
},
{
"name": "get-east-asian-width",
"direct": false,
"version": "1.3.0",
"ecosystem": "npm"
},
{
"name": "get-intrinsic",
"direct": false,
"version": "1.2.4",
"ecosystem": "npm"
},
{
"name": "get-package-type",
"direct": false,
"version": "0.1.0",
"ecosystem": "npm"
},
{
"name": "get-stream",
"direct": false,
"version": "6.0.1",
"ecosystem": "npm"
},
{
"name": "get-symbol-description",
"direct": false,
"version": "1.0.2",
"ecosystem": "npm"
},
{
"name": "glob",
"direct": false,
"version": "7.2.3",
"ecosystem": "npm"
},
{
"name": "glob-parent",
"direct": false,
"version": "5.1.2",
"ecosystem": "npm"
},
{
"name": "glob-parent",
"direct": false,
"version": "6.0.2",
"ecosystem": "npm"
},
{
"name": "globals",
"direct": false,
"version": "11.12.0",
"ecosystem": "npm"
},
{
"name": "globals",
"direct": false,
"version": "13.24.0",
"ecosystem": "npm"
},
{
"name": "globalthis",
"direct": false,
"version": "1.0.4",
"ecosystem": "npm"
},
{
"name": "globby",
"direct": false,
"version": "11.1.0",
"ecosystem": "npm"
},
{
"name": "gopd",
"direct": false,
"version": "1.0.1",
"ecosystem": "npm"
},
{
"name": "graceful-fs",
"direct": false,
"version": "4.2.11",
"ecosystem": "npm"
},
{
"name": "graphemer",
"direct": false,
"version": "1.4.0",
"ecosystem": "npm"
},
{
"name": "has-bigints",
"direct": false,
"version": "1.0.2",
"ecosystem": "npm"
},
{
"name": "has-flag",
"direct": false,
"version": "4.0.0",
"ecosystem": "npm"
},
{
"name": "has-property-descriptors",
"direct": false,
"version": "1.0.2",
"ecosystem": "npm"
},
{
"name": "has-proto",
"direct": false,
"version": "1.0.3",
"ecosystem": "npm"
},
{
"name": "has-symbols",
"direct": false,
"version": "1.0.3",
"ecosystem": "npm"
},
{
"name": "has-tostringtag",
"direct": false,
"version": "1.0.2",
"ecosystem": "npm"
},
{
"name": "hasown",
"direct": false,
"version": "2.0.2",
"ecosystem": "npm"
},
{
"name": "html-encoding-sniffer",
"direct": false,
"version": "4.0.0",
"ecosystem": "npm"
},
{
"name": "html-escaper",
"direct": false,
"version": "2.0.2",
"ecosystem": "npm"
},
{
"name": "http-proxy-agent",
"direct": false,
"version": "7.0.2",
"ecosystem": "npm"
},
{
"name": "https-proxy-agent",
"direct": false,
"version": "7.0.6",
"ecosystem": "npm"
},
{
"name": "human-signals",
"direct": false,
"version": "2.1.0",
"ecosystem": "npm"
},
{
"name": "husky",
"direct": false,
"version": "9.1.7",
"ecosystem": "npm"
},
{
"name": "iconv-lite",
"direct": false,
"version": "0.6.3",
"ecosystem": "npm"
},
{
"name": "ignore",
"direct": false,
"version": "5.3.1",
"ecosystem": "npm"
},
{
"name": "import-fresh",
"direct": false,
"version": "3.3.0",
"ecosystem": "npm"
},
{
"name": "import-local",
"direct": false,
"version": "3.2.0",
"ecosystem": "npm"
},
{
"name": "imurmurhash",
"direct": false,
"version": "0.1.4",
"ecosystem": "npm"
},
{
"name": "inflight",
"direct": false,
"version": "1.0.6",
"ecosystem": "npm"
},
{
"name": "inherits",
"direct": false,
"version": "2.0.4",
"ecosystem": "npm"
},
{
"name": "internal-slot",
"direct": false,
"version": "1.0.7",
"ecosystem": "npm"
},
{
"name": "is-array-buffer",
"direct": false,
"version": "3.0.4",
"ecosystem": "npm"
},
{
"name": "is-arrayish",
"direct": false,
"version": "0.2.1",
"ecosystem": "npm"
},
{
"name": "is-async-function",
"direct": false,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "is-bigint",
"direct": false,
"version": "1.0.4",
"ecosystem": "npm"
},
{
"name": "is-boolean-object",
"direct": false,
"version": "1.1.2",
"ecosystem": "npm"
},
{
"name": "is-callable",
"direct": false,
"version": "1.2.7",
"ecosystem": "npm"
},
{
"name": "is-core-module",
"direct": false,
"version": "2.13.1",
"ecosystem": "npm"
},
{
"name": "is-data-view",
"direct": false,
"version": "1.0.1",
"ecosystem": "npm"
},
{
"name": "is-date-object",
"direct": false,
"version": "1.0.5",
"ecosystem": "npm"
},
{
"name": "is-extglob",
"direct": false,
"version": "2.1.1",
"ecosystem": "npm"
},
{
"name": "is-finalizationregistry",
"direct": false,
"version": "1.0.2",
"ecosystem": "npm"
},
{
"name": "is-fullwidth-code-point",
"direct": false,
"version": "3.0.0",
"ecosystem": "npm"
},
{
"name": "is-fullwidth-code-point",
"direct": false,
"version": "4.0.0",
"ecosystem": "npm"
},
{
"name": "is-fullwidth-code-point",
"direct": false,
"version": "5.0.0",
"ecosystem": "npm"
},
{
"name": "is-generator-fn",
"direct": false,
"version": "2.1.0",
"ecosystem": "npm"
},
{
"name": "is-generator-function",
"direct": false,
"version": "1.0.10",
"ecosystem": "npm"
},
{
"name": "is-glob",
"direct": false,
"version": "4.0.3",
"ecosystem": "npm"
},
{
"name": "is-map",
"direct": false,
"version": "2.0.3",
"ecosystem": "npm"
},
{
"name": "is-negative-zero",
"direct": false,
"version": "2.0.3",
"ecosystem": "npm"
},
{
"name": "is-number",
"direct": false,
"version": "7.0.0",
"ecosystem": "npm"
},
{
"name": "is-number-object",
"direct": false,
"version": "1.0.7",
"ecosystem": "npm"
},
{
"name": "is-path-inside",
"direct": false,
"version": "3.0.3",
"ecosystem": "npm"
},
{
"name": "is-potential-custom-element-name",
"direct": false,
"version": "1.0.1",
"ecosystem": "npm"
},
{
"name": "is-regex",
"direct": false,
"version": "1.1.4",
"ecosystem": "npm"
},
{
"name": "is-set",
"direct": false,
"version": "2.0.3",
"ecosystem": "npm"
},
{
"name": "is-shared-array-buffer",
"direct": false,
"version": "1.0.3",
"ecosystem": "npm"
},
{
"name": "is-stream",
"direct": false,
"version": "2.0.1",
"ecosystem": "npm"
},
{
"name": "is-string",
"direct": false,
"version": "1.0.7",
"ecosystem": "npm"
},
{
"name": "is-symbol",
"direct": false,
"version": "1.0.4",
"ecosystem": "npm"
},
{
"name": "is-typed-array",
"direct": false,
"version": "1.1.13",
"ecosystem": "npm"
},
{
"name": "is-weakmap",
"direct": false,
"version": "2.0.2",
"ecosystem": "npm"
},
{
"name": "is-weakref",
"direct": false,
"version": "1.0.2",
"ecosystem": "npm"
},
{
"name": "is-weakset",
"direct": false,
"version": "2.0.3",
"ecosystem": "npm"
},
{
"name": "isarray",
"direct": false,
"version": "2.0.5",
"ecosystem": "npm"
},
{
"name": "isexe",
"direct": false,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "istanbul-lib-coverage",
"direct": false,
"version": "3.2.2",
"ecosystem": "npm"
},
{
"name": "istanbul-lib-instrument",
"direct": false,
"version": "5.2.1",
"ecosystem": "npm"
},
{
"name": "istanbul-lib-instrument",
"direct": false,
"version": "6.0.3",
"ecosystem": "npm"
},
{
"name": "istanbul-lib-report",
"direct": false,
"version": "3.0.1",
"ecosystem": "npm"
},
{
"name": "istanbul-lib-source-maps",
"direct": false,
"version": "4.0.1",
"ecosystem": "npm"
},
{
"name": "istanbul-reports",
"direct": false,
"version": "3.1.7",
"ecosystem": "npm"
},
{
"name": "iterator.prototype",
"direct": false,
"version": "1.1.2",
"ecosystem": "npm"
},
{
"name": "jake",
"direct": false,
"version": "10.9.2",
"ecosystem": "npm"
},
{
"name": "jest",
"direct": false,
"version": "29.7.0",
"ecosystem": "npm"
},
{
"name": "jest-changed-files",
"direct": false,
"version": "29.7.0",
"ecosystem": "npm"
},
{
"name": "jest-circus",
"direct": false,
"version": "29.7.0",
"ecosystem": "npm"
},
{
"name": "jest-cli",
"direct": false,
"version": "29.7.0",
"ecosystem": "npm"
},
{
"name": "jest-config",
"direct": false,
"version": "29.7.0",
"ecosystem": "npm"
},
{
"name": "jest-diff",
"direct": false,
"version": "29.7.0",
"ecosystem": "npm"
},
{
"name": "jest-docblock",
"direct": false,
"version": "29.7.0",
"ecosystem": "npm"
},
{
"name": "jest-each",
"direct": false,
"version": "29.7.0",
"ecosystem": "npm"
},
{
"name": "jest-environment-jsdom",
"direct": false,
"version": "30.0.0-beta.3",
"ecosystem": "npm"
},
{
"name": "jest-environment-node",
"direct": false,
"version": "29.7.0",
"ecosystem": "npm"
},
{
"name": "jest-get-type",
"direct": false,
"version": "29.6.3",
"ecosystem": "npm"
},
{
"name": "jest-haste-map",
"direct": false,
"version": "29.7.0",
"ecosystem": "npm"
},
{
"name": "jest-leak-detector",
"direct": false,
"version": "29.7.0",
"ecosystem": "npm"
},
{
"name": "jest-localstorage-mock",
"direct": false,
"version": "2.4.26",
"ecosystem": "npm"
},
{
"name": "jest-matcher-utils",
"direct": false,
"version": "29.7.0",
"ecosystem": "npm"
},
{
"name": "jest-message-util",
"direct": false,
"version": "29.7.0",
"ecosystem": "npm"
},
{
"name": "jest-message-util",
"direct": false,
"version": "30.0.0-beta.3",
"ecosystem": "npm"
},
{
"name": "jest-mock",
"direct": false,
"version": "29.7.0",
"ecosystem": "npm"
},
{
"name": "jest-mock",
"direct": false,
"version": "30.0.0-beta.3",
"ecosystem": "npm"
},
{
"name": "jest-pnp-resolver",
"direct": false,
"version": "1.2.3",
"ecosystem": "npm"
},
{
"name": "jest-regex-util",
"direct": false,
"version": "29.6.3",
"ecosystem": "npm"
},
{
"name": "jest-regex-util",
"direct": false,
"version": "30.0.0-beta.3",
"ecosystem": "npm"
},
{
"name": "jest-resolve",
"direct": false,
"version": "29.7.0",
"ecosystem": "npm"
},
{
"name": "jest-resolve-dependencies",
"direct": false,
"version": "29.7.0",
"ecosystem": "npm"
},
{
"name": "jest-runner",
"direct": false,
"version": "29.7.0",
"ecosystem": "npm"
},
{
"name": "jest-runtime",
"direct": false,
"version": "29.7.0",
"ecosystem": "npm"
},
{
"name": "jest-snapshot",
"direct": false,
"version": "29.7.0",
"ecosystem": "npm"
},
{
"name": "jest-util",
"direct": false,
"version": "29.7.0",
"ecosystem": "npm"
},
{
"name": "jest-util",
"direct": false,
"version": "30.0.0-beta.3",
"ecosystem": "npm"
},
{
"name": "jest-validate",
"direct": false,
"version": "29.7.0",
"ecosystem": "npm"
},
{
"name": "jest-watcher",
"direct": false,
"version": "29.7.0",
"ecosystem": "npm"
},
{
"name": "jest-worker",
"direct": false,
"version": "29.7.0",
"ecosystem": "npm"
},
{
"name": "js-tokens",
"direct": false,
"version": "4.0.0",
"ecosystem": "npm"
},
{
"name": "js-yaml",
"direct": false,
"version": "3.14.2",
"ecosystem": "npm"
},
{
"name": "js-yaml",
"direct": false,
"version": "4.1.1",
"ecosystem": "npm"
},
{
"name": "jsdom",
"direct": false,
"version": "26.1.0",
"ecosystem": "npm"
},
{
"name": "jsesc",
"direct": false,
"version": "3.1.0",
"ecosystem": "npm"
},
{
"name": "json-buffer",
"direct": false,
"version": "3.0.1",
"ecosystem": "npm"
},
{
"name": "json-parse-even-better-errors",
"direct": false,
"version": "2.3.1",
"ecosystem": "npm"
},
{
"name": "json-schema-traverse",
"direct": false,
"version": "0.4.1",
"ecosystem": "npm"
},
{
"name": "json-stable-stringify-without-jsonify",
"direct": false,
"version": "1.0.1",
"ecosystem": "npm"
},
{
"name": "json5",
"direct": false,
"version": "1.0.2",
"ecosystem": "npm"
},
{
"name": "json5",
"direct": false,
"version": "2.2.3",
"ecosystem": "npm"
},
{
"name": "jsx-ast-utils",
"direct": false,
"version": "3.3.5",
"ecosystem": "npm"
},
{
"name": "keyv",
"direct": false,
"version": "4.5.4",
"ecosystem": "npm"
},
{
"name": "kleur",
"direct": false,
"version": "3.0.3",
"ecosystem": "npm"
},
{
"name": "leven",
"direct": false,
"version": "3.1.0",
"ecosystem": "npm"
},
{
"name": "levn",
"direct": false,
"version": "0.4.1",
"ecosystem": "npm"
},
{
"name": "lilconfig",
"direct": false,
"version": "3.1.3",
"ecosystem": "npm"
},
{
"name": "lines-and-columns",
"direct": false,
"version": "1.2.4",
"ecosystem": "npm"
},
{
"name": "lint-staged",
"direct": false,
"version": "16.1.2",
"ecosystem": "npm"
},
{
"name": "listr2",
"direct": false,
"version": "8.3.3",
"ecosystem": "npm"
},
{
"name": "locate-path",
"direct": false,
"version": "5.0.0",
"ecosystem": "npm"
},
{
"name": "locate-path",
"direct": false,
"version": "6.0.0",
"ecosystem": "npm"
},
{
"name": "lodash.memoize",
"direct": false,
"version": "4.1.2",
"ecosystem": "npm"
},
{
"name": "lodash.merge",
"direct": false,
"version": "4.6.2",
"ecosystem": "npm"
},
{
"name": "log-update",
"direct": false,
"version": "6.1.0",
"ecosystem": "npm"
},
{
"name": "loose-envify",
"direct": false,
"version": "1.4.0",
"ecosystem": "npm"
},
{
"name": "lru-cache",
"direct": false,
"version": "10.4.3",
"ecosystem": "npm"
},
{
"name": "lru-cache",
"direct": false,
"version": "5.1.1",
"ecosystem": "npm"
},
{
"name": "lz-string",
"direct": false,
"version": "1.5.0",
"ecosystem": "npm"
},
{
"name": "make-dir",
"direct": false,
"version": "4.0.0",
"ecosystem": "npm"
},
{
"name": "make-error",
"direct": false,
"version": "1.3.6",
"ecosystem": "npm"
},
{
"name": "makeerror",
"direct": false,
"version": "1.0.12",
"ecosystem": "npm"
},
{
"name": "merge-stream",
"direct": false,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "merge2",
"direct": false,
"version": "1.4.1",
"ecosystem": "npm"
},
{
"name": "micromatch",
"direct": false,
"version": "4.0.8",
"ecosystem": "npm"
},
{
"name": "mimic-fn",
"direct": false,
"version": "2.1.0",
"ecosystem": "npm"
},
{
"name": "mimic-function",
"direct": false,
"version": "5.0.1",
"ecosystem": "npm"
},
{
"name": "minimatch",
"direct": false,
"version": "3.1.5",
"ecosystem": "npm"
},
{
"name": "minimatch",
"direct": false,
"version": "5.1.9",
"ecosystem": "npm"
},
{
"name": "minimatch",
"direct": false,
"version": "9.0.9",
"ecosystem": "npm"
},
{
"name": "minimist",
"direct": false,
"version": "1.2.8",
"ecosystem": "npm"
},
{
"name": "ms",
"direct": false,
"version": "2.1.3",
"ecosystem": "npm"
},
{
"name": "nano-spawn",
"direct": false,
"version": "1.0.2",
"ecosystem": "npm"
},
{
"name": "natural-compare",
"direct": false,
"version": "1.4.0",
"ecosystem": "npm"
},
{
"name": "node-int64",
"direct": false,
"version": "0.4.0",
"ecosystem": "npm"
},
{
"name": "node-releases",
"direct": false,
"version": "2.0.19",
"ecosystem": "npm"
},
{
"name": "nofilter",
"direct": false,
"version": "3.1.0",
"ecosystem": "npm"
},
{
"name": "normalize-path",
"direct": false,
"version": "3.0.0",
"ecosystem": "npm"
},
{
"name": "npm-run-path",
"direct": false,
"version": "4.0.1",
"ecosystem": "npm"
},
{
"name": "nwsapi",
"direct": false,
"version": "2.2.20",
"ecosystem": "npm"
},
{
"name": "object-assign",
"direct": false,
"version": "4.1.1",
"ecosystem": "npm"
},
{
"name": "object-inspect",
"direct": false,
"version": "1.13.1",
"ecosystem": "npm"
},
{
"name": "object-keys",
"direct": false,
"version": "1.1.1",
"ecosystem": "npm"
},
{
"name": "object.assign",
"direct": false,
"version": "4.1.5",
"ecosystem": "npm"
},
{
"name": "object.entries",
"direct": false,
"version": "1.1.8",
"ecosystem": "npm"
},
{
"name": "object.fromentries",
"direct": false,
"version": "2.0.8",
"ecosystem": "npm"
},
{
"name": "object.groupby",
"direct": false,
"version": "1.0.3",
"ecosystem": "npm"
},
{
"name": "object.hasown",
"direct": false,
"version": "1.1.4",
"ecosystem": "npm"
},
{
"name": "object.values",
"direct": false,
"version": "1.2.0",
"ecosystem": "npm"
},
{
"name": "once",
"direct": false,
"version": "1.4.0",
"ecosystem": "npm"
},
{
"name": "onetime",
"direct": false,
"version": "5.1.2",
"ecosystem": "npm"
},
{
"name": "onetime",
"direct": false,
"version": "7.0.0",
"ecosystem": "npm"
},
{
"name": "optionator",
"direct": false,
"version": "0.9.4",
"ecosystem": "npm"
},
{
"name": "p-limit",
"direct": false,
"version": "2.3.0",
"ecosystem": "npm"
},
{
"name": "p-limit",
"direct": false,
"version": "3.1.0",
"ecosystem": "npm"
},
{
"name": "p-locate",
"direct": false,
"version": "4.1.0",
"ecosystem": "npm"
},
{
"name": "p-locate",
"direct": false,
"version": "5.0.0",
"ecosystem": "npm"
},
{
"name": "p-try",
"direct": false,
"version": "2.2.0",
"ecosystem": "npm"
},
{
"name": "parent-module",
"direct": false,
"version": "1.0.1",
"ecosystem": "npm"
},
{
"name": "parse-json",
"direct": false,
"version": "5.2.0",
"ecosystem": "npm"
},
{
"name": "parse5",
"direct": false,
"version": "7.3.0",
"ecosystem": "npm"
},
{
"name": "path-exists",
"direct": false,
"version": "4.0.0",
"ecosystem": "npm"
},
{
"name": "path-is-absolute",
"direct": false,
"version": "1.0.1",
"ecosystem": "npm"
},
{
"name": "path-key",
"direct": false,
"version": "3.1.1",
"ecosystem": "npm"
},
{
"name": "path-parse",
"direct": false,
"version": "1.0.7",
"ecosystem": "npm"
},
{
"name": "path-type",
"direct": false,
"version": "4.0.0",
"ecosystem": "npm"
},
{
"name": "picocolors",
"direct": false,
"version": "1.1.1",
"ecosystem": "npm"
},
{
"name": "picomatch",
"direct": false,
"version": "2.3.2",
"ecosystem": "npm"
},
{
"name": "picomatch",
"direct": false,
"version": "4.0.4",
"ecosystem": "npm"
},
{
"name": "pidtree",
"direct": false,
"version": "0.6.0",
"ecosystem": "npm"
},
{
"name": "pirates",
"direct": false,
"version": "4.0.7",
"ecosystem": "npm"
},
{
"name": "pkg-dir",
"direct": false,
"version": "4.2.0",
"ecosystem": "npm"
},
{
"name": "possible-typed-array-names",
"direct": false,
"version": "1.0.0",
"ecosystem": "npm"
},
{
"name": "prelude-ls",
"direct": false,
"version": "1.2.1",
"ecosystem": "npm"
},
{
"name": "prettier",
"direct": false,
"version": "3.3.2",
"ecosystem": "npm"
},
{
"name": "pretty-format",
"direct": false,
"version": "27.5.1",
"ecosystem": "npm"
},
{
"name": "pretty-format",
"direct": false,
"version": "29.7.0",
"ecosystem": "npm"
},
{
"name": "pretty-format",
"direct": false,
"version": "30.0.0-beta.3",
"ecosystem": "npm"
},
{
"name": "prompts",
"direct": false,
"version": "2.4.2",
"ecosystem": "npm"
},
{
"name": "prop-types",
"direct": false,
"version": "15.8.1",
"ecosystem": "npm"
},
{
"name": "punycode",
"direct": false,
"version": "2.3.1",
"ecosystem": "npm"
},
{
"name": "pure-rand",
"direct": false,
"version": "6.1.0",
"ecosystem": "npm"
},
{
"name": "queue-microtask",
"direct": false,
"version": "1.2.3",
"ecosystem": "npm"
},
{
"name": "react",
"direct": false,
"version": "18.3.1",
"ecosystem": "npm"
},
{
"name": "react-dom",
"direct": false,
"version": "18.3.1",
"ecosystem": "npm"
},
{
"name": "react-is",
"direct": false,
"version": "16.13.1",
"ecosystem": "npm"
},
{
"name": "react-is",
"direct": false,
"version": "17.0.2",
"ecosystem": "npm"
},
{
"name": "react-is",
"direct": false,
"version": "18.3.1",
"ecosystem": "npm"
},
{
"name": "reflect.getprototypeof",
"direct": false,
"version": "1.0.6",
"ecosystem": "npm"
},
{
"name": "regexp-tree",
"direct": false,
"version": "0.1.27",
"ecosystem": "npm"
},
{
"name": "regexp.prototype.flags",
"direct": false,
"version": "1.5.2",
"ecosystem": "npm"
},
{
"name": "require-directory",
"direct": false,
"version": "2.1.1",
"ecosystem": "npm"
},
{
"name": "resolve",
"direct": false,
"version": "1.22.8",
"ecosystem": "npm"
},
{
"name": "resolve",
"direct": false,
"version": "2.0.0-next.5",
"ecosystem": "npm"
},
{
"name": "resolve-cwd",
"direct": false,
"version": "3.0.0",
"ecosystem": "npm"
},
{
"name": "resolve-from",
"direct": false,
"version": "4.0.0",
"ecosystem": "npm"
},
{
"name": "resolve-from",
"direct": false,
"version": "5.0.0",
"ecosystem": "npm"
},
{
"name": "resolve.exports",
"direct": false,
"version": "2.0.3",
"ecosystem": "npm"
},
{
"name": "restore-cursor",
"direct": false,
"version": "5.1.0",
"ecosystem": "npm"
},
{
"name": "reusify",
"direct": false,
"version": "1.0.4",
"ecosystem": "npm"
},
{
"name": "rfdc",
"direct": false,
"version": "1.4.1",
"ecosystem": "npm"
},
{
"name": "rimraf",
"direct": false,
"version": "3.0.2",
"ecosystem": "npm"
},
{
"name": "rrweb-cssom",
"direct": false,
"version": "0.8.0",
"ecosystem": "npm"
},
{
"name": "run-parallel",
"direct": false,
"version": "1.2.0",
"ecosystem": "npm"
},
{
"name": "safe-array-concat",
"direct": false,
"version": "1.1.2",
"ecosystem": "npm"
},
{
"name": "safe-regex",
"direct": false,
"version": "2.1.1",
"ecosystem": "npm"
},
{
"name": "safe-regex-test",
"direct": false,
"version": "1.0.3",
"ecosystem": "npm"
},
{
"name": "safer-buffer",
"direct": false,
"version": "2.1.2",
"ecosystem": "npm"
},
{
"name": "saxes",
"direct": false,
"version": "6.0.0",
"ecosystem": "npm"
},
{
"name": "scheduler",
"direct": false,
"version": "0.23.2",
"ecosystem": "npm"
},
{
"name": "semver",
"direct": false,
"version": "6.3.1",
"ecosystem": "npm"
},
{
"name": "semver",
"direct": false,
"version": "7.6.2",
"ecosystem": "npm"
},
{
"name": "semver",
"direct": false,
"version": "7.7.2",
"ecosystem": "npm"
},
{
"name": "set-function-length",
"direct": false,
"version": "1.2.2",
"ecosystem": "npm"
},
{
"name": "set-function-name",
"direct": false,
"version": "2.0.2",
"ecosystem": "npm"
},
{
"name": "shebang-command",
"direct": false,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "shebang-regex",
"direct": false,
"version": "3.0.0",
"ecosystem": "npm"
},
{
"name": "side-channel",
"direct": false,
"version": "1.0.6",
"ecosystem": "npm"
},
{
"name": "signal-exit",
"direct": false,
"version": "3.0.7",
"ecosystem": "npm"
},
{
"name": "signal-exit",
"direct": false,
"version": "4.1.0",
"ecosystem": "npm"
},
{
"name": "sisteransi",
"direct": false,
"version": "1.0.5",
"ecosystem": "npm"
},
{
"name": "slash",
"direct": false,
"version": "3.0.0",
"ecosystem": "npm"
},
{
"name": "slice-ansi",
"direct": false,
"version": "5.0.0",
"ecosystem": "npm"
},
{
"name": "slice-ansi",
"direct": false,
"version": "7.1.0",
"ecosystem": "npm"
},
{
"name": "source-map",
"direct": false,
"version": "0.6.1",
"ecosystem": "npm"
},
{
"name": "source-map-support",
"direct": false,
"version": "0.5.13",
"ecosystem": "npm"
},
{
"name": "sprintf-js",
"direct": false,
"version": "1.0.3",
"ecosystem": "npm"
},
{
"name": "stack-utils",
"direct": false,
"version": "2.0.6",
"ecosystem": "npm"
},
{
"name": "string-argv",
"direct": false,
"version": "0.3.2",
"ecosystem": "npm"
},
{
"name": "string-length",
"direct": false,
"version": "4.0.2",
"ecosystem": "npm"
},
{
"name": "string-width",
"direct": false,
"version": "4.2.3",
"ecosystem": "npm"
},
{
"name": "string-width",
"direct": false,
"version": "7.2.0",
"ecosystem": "npm"
},
{
"name": "string.prototype.matchall",
"direct": false,
"version": "4.0.11",
"ecosystem": "npm"
},
{
"name": "string.prototype.trim",
"direct": false,
"version": "1.2.9",
"ecosystem": "npm"
},
{
"name": "string.prototype.trimend",
"direct": false,
"version": "1.0.8",
"ecosystem": "npm"
},
{
"name": "string.prototype.trimstart",
"direct": false,
"version": "1.0.8",
"ecosystem": "npm"
},
{
"name": "strip-ansi",
"direct": false,
"version": "6.0.1",
"ecosystem": "npm"
},
{
"name": "strip-ansi",
"direct": false,
"version": "7.1.0",
"ecosystem": "npm"
},
{
"name": "strip-bom",
"direct": false,
"version": "3.0.0",
"ecosystem": "npm"
},
{
"name": "strip-bom",
"direct": false,
"version": "4.0.0",
"ecosystem": "npm"
},
{
"name": "strip-final-newline",
"direct": false,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "strip-json-comments",
"direct": false,
"version": "3.1.1",
"ecosystem": "npm"
},
{
"name": "supports-color",
"direct": false,
"version": "7.2.0",
"ecosystem": "npm"
},
{
"name": "supports-color",
"direct": false,
"version": "8.1.1",
"ecosystem": "npm"
},
{
"name": "supports-preserve-symlinks-flag",
"direct": false,
"version": "1.0.0",
"ecosystem": "npm"
},
{
"name": "symbol-tree",
"direct": false,
"version": "3.2.4",
"ecosystem": "npm"
},
{
"name": "test-exclude",
"direct": false,
"version": "6.0.0",
"ecosystem": "npm"
},
{
"name": "text-table",
"direct": false,
"version": "0.2.0",
"ecosystem": "npm"
},
{
"name": "tldts",
"direct": false,
"version": "6.1.86",
"ecosystem": "npm"
},
{
"name": "tldts-core",
"direct": false,
"version": "6.1.86",
"ecosystem": "npm"
},
{
"name": "tmpl",
"direct": false,
"version": "1.0.5",
"ecosystem": "npm"
},
{
"name": "to-regex-range",
"direct": false,
"version": "5.0.1",
"ecosystem": "npm"
},
{
"name": "tough-cookie",
"direct": false,
"version": "5.1.2",
"ecosystem": "npm"
},
{
"name": "tr46",
"direct": false,
"version": "5.1.1",
"ecosystem": "npm"
},
{
"name": "ts-api-utils",
"direct": false,
"version": "1.3.0",
"ecosystem": "npm"
},
{
"name": "ts-jest",
"direct": false,
"version": "29.3.4",
"ecosystem": "npm"
},
{
"name": "ts-node",
"direct": false,
"version": "10.9.2",
"ecosystem": "npm"
},
{
"name": "tsconfig-paths",
"direct": false,
"version": "3.15.0",
"ecosystem": "npm"
},
{
"name": "type-check",
"direct": false,
"version": "0.4.0",
"ecosystem": "npm"
},
{
"name": "type-detect",
"direct": false,
"version": "4.0.8",
"ecosystem": "npm"
},
{
"name": "type-fest",
"direct": false,
"version": "0.20.2",
"ecosystem": "npm"
},
{
"name": "type-fest",
"direct": false,
"version": "0.21.3",
"ecosystem": "npm"
},
{
"name": "type-fest",
"direct": false,
"version": "4.41.0",
"ecosystem": "npm"
},
{
"name": "typed-array-buffer",
"direct": false,
"version": "1.0.2",
"ecosystem": "npm"
},
{
"name": "typed-array-byte-length",
"direct": false,
"version": "1.0.1",
"ecosystem": "npm"
},
{
"name": "typed-array-byte-offset",
"direct": false,
"version": "1.0.2",
"ecosystem": "npm"
},
{
"name": "typed-array-length",
"direct": false,
"version": "1.0.6",
"ecosystem": "npm"
},
{
"name": "typescript",
"direct": false,
"version": "5.4.5",
"ecosystem": "npm"
},
{
"name": "unbox-primitive",
"direct": false,
"version": "1.0.2",
"ecosystem": "npm"
},
{
"name": "undici-types",
"direct": false,
"version": "5.26.5",
"ecosystem": "npm"
},
{
"name": "update-browserslist-db",
"direct": false,
"version": "1.1.3",
"ecosystem": "npm"
},
{
"name": "uri-js",
"direct": false,
"version": "4.4.1",
"ecosystem": "npm"
},
{
"name": "v8-compile-cache-lib",
"direct": false,
"version": "3.0.1",
"ecosystem": "npm"
},
{
"name": "v8-to-istanbul",
"direct": false,
"version": "9.3.0",
"ecosystem": "npm"
},
{
"name": "w3c-xmlserializer",
"direct": false,
"version": "5.0.0",
"ecosystem": "npm"
},
{
"name": "walker",
"direct": false,
"version": "1.0.8",
"ecosystem": "npm"
},
{
"name": "webidl-conversions",
"direct": false,
"version": "7.0.0",
"ecosystem": "npm"
},
{
"name": "whatwg-encoding",
"direct": false,
"version": "3.1.1",
"ecosystem": "npm"
},
{
"name": "whatwg-mimetype",
"direct": false,
"version": "4.0.0",
"ecosystem": "npm"
},
{
"name": "whatwg-url",
"direct": false,
"version": "14.2.0",
"ecosystem": "npm"
},
{
"name": "which",
"direct": false,
"version": "2.0.2",
"ecosystem": "npm"
},
{
"name": "which-boxed-primitive",
"direct": false,
"version": "1.0.2",
"ecosystem": "npm"
},
{
"name": "which-builtin-type",
"direct": false,
"version": "1.1.3",
"ecosystem": "npm"
},
{
"name": "which-collection",
"direct": false,
"version": "1.0.2",
"ecosystem": "npm"
},
{
"name": "which-typed-array",
"direct": false,
"version": "1.1.15",
"ecosystem": "npm"
},
{
"name": "word-wrap",
"direct": false,
"version": "1.2.5",
"ecosystem": "npm"
},
{
"name": "wrap-ansi",
"direct": false,
"version": "7.0.0",
"ecosystem": "npm"
},
{
"name": "wrap-ansi",
"direct": false,
"version": "9.0.0",
"ecosystem": "npm"
},
{
"name": "wrappy",
"direct": false,
"version": "1.0.2",
"ecosystem": "npm"
},
{
"name": "write-file-atomic",
"direct": false,
"version": "4.0.2",
"ecosystem": "npm"
},
{
"name": "ws",
"direct": false,
"version": "8.18.2",
"ecosystem": "npm"
},
{
"name": "xml-name-validator",
"direct": false,
"version": "5.0.0",
"ecosystem": "npm"
},
{
"name": "xmlchars",
"direct": false,
"version": "2.2.0",
"ecosystem": "npm"
},
{
"name": "y18n",
"direct": false,
"version": "5.0.8",
"ecosystem": "npm"
},
{
"name": "yallist",
"direct": false,
"version": "3.1.1",
"ecosystem": "npm"
},
{
"name": "yaml",
"direct": false,
"version": "2.8.0",
"ecosystem": "npm"
},
{
"name": "yargs",
"direct": false,
"version": "17.7.2",
"ecosystem": "npm"
},
{
"name": "yargs-parser",
"direct": false,
"version": "21.1.1",
"ecosystem": "npm"
},
{
"name": "yn",
"direct": false,
"version": "3.1.1",
"ecosystem": "npm"
},
{
"name": "yocto-queue",
"direct": false,
"version": "0.1.0",
"ecosystem": "npm"
}
],
"collected": true,
"truncated": false,
"total_count": 619,
"direct_count": 2,
"indirect_count": 617
}
},
"maintainership": {
"issues": {
"open_prs": 1,
"merged_prs": 105,
"open_issues": 0,
"closed_ratio": null,
"closed_issues": 0,
"closed_unmerged_prs": 5
},
"bus_factor": 2,
"bot_contributors": 1,
"top_contributors": [
{
"type": "User",
"login": "akbisw",
"commits": 188,
"avatar_url": "https://avatars.githubusercontent.com/u/8528636?v=4"
},
{
"type": "User",
"login": "actions-user",
"commits": 102,
"avatar_url": "https://avatars.githubusercontent.com/u/65916846?v=4"
},
{
"type": "User",
"login": "ottokruse",
"commits": 96,
"avatar_url": "https://avatars.githubusercontent.com/u/6275520?v=4"
},
{
"type": "User",
"login": "EricBorland",
"commits": 6,
"avatar_url": "https://avatars.githubusercontent.com/u/6512144?v=4"
},
{
"type": "User",
"login": "RobHarveyDev",
"commits": 6,
"avatar_url": "https://avatars.githubusercontent.com/u/87716995?v=4"
},
{
"type": "User",
"login": "martinpagelaws",
"commits": 4,
"avatar_url": "https://avatars.githubusercontent.com/u/128691727?v=4"
},
{
"type": "User",
"login": "fahadsadiq",
"commits": 3,
"avatar_url": "https://avatars.githubusercontent.com/u/18647350?v=4"
},
{
"type": "User",
"login": "tinti",
"commits": 3,
"avatar_url": "https://avatars.githubusercontent.com/u/31630?v=4"
},
{
"type": "User",
"login": "mikemeerschaert",
"commits": 1,
"avatar_url": "https://avatars.githubusercontent.com/u/2775912?v=4"
},
{
"type": "User",
"login": "Tameyer41",
"commits": 1,
"avatar_url": "https://avatars.githubusercontent.com/u/63265436?v=4"
}
],
"contributors_sampled": 20,
"top_contributor_share": 0.448
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"main.yml",
"publish.yml"
],
"has_docs_dir": false,
"linter_configs": [
".eslintrc.cjs"
],
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [
"package-lock.json"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 3,
"reason": "branch protection is not maximal on development and all release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 9,
"reason": "24 out of 25 merged PRs checked by a CI test -- score normalized to 9",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 0/29 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 10,
"reason": "project has 3 contributing companies or organizations -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 0,
"reason": "no update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": null,
"reason": "packaging workflow not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 3,
"reason": "dependency not pinned by hash detected -- score normalized to 3",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 10,
"reason": "SAST tool is run on all commits",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 0,
"reason": "security policy file not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": null,
"reason": "no releases found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 0,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 0,
"reason": "12 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "2ddce40e8a2b8cce16f32bf03fd4b5051de26594",
"ran_at": "2026-07-27T16:53:56Z",
"aggregate_score": 4.4,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": false,
"has_dependabot_config": false
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-24T06:37:05Z",
"oldest_open_prs": [
{
"number": 109,
"created_at": "2026-07-20T22:38:03Z",
"last_comment_at": null,
"last_comment_author": null
}
],
"last_merged_pr_at": "2026-07-23T16:22:55Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": []
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/joinmeow/amazon-cognito-passwordless-auth",
"host": "github.com",
"name": "amazon-cognito-passwordless-auth",
"owner": "joinmeow"
},
"metrics": {
"overall": {
"key": "overall",
"band": "moderate",
"name": "Overall health",
"note": null,
"notes": [],
"value": 59,
"inputs": {
"security": 55,
"vitality": 83,
"community": 26,
"governance": 68,
"engineering": 53
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "good",
"name": "Vitality",
"value": 83,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "good",
"name": "Development activity",
"note": null,
"notes": [],
"value": 72,
"inputs": {
"commits_last_year": 97,
"human_commit_share": 0.95,
"days_since_last_push": 4,
"active_weeks_last_year": 11
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 4 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 4
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "11/52 weeks with commits",
"points": 7.6,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 11
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "97 commits in the last year",
"points": 17.9,
"status": "partial",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 97
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 100,
"inputs": {
"releases_count": 96,
"latest_release_tag": "v1.0.104",
"releases_from_tags": false,
"days_since_latest_release": 6,
"mean_days_between_releases": 32
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "96 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 96
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 6 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 6
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~32 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 32
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "maintained",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": null,
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": 4,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "last human commit 4 days ago",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_maintained",
"params": {
"days": 4
}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "critical",
"name": "Community & Adoption",
"value": 26,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "critical",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 1,
"inputs": {
"forks": 0,
"stars": 0,
"watchers": 0,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "0 stars",
"points": 0,
"status": "missed",
"details": [
{
"code": "stars",
"params": {
"count": 0
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "0 forks",
"points": 0,
"status": "missed",
"details": [
{
"code": "forks",
"params": {
"count": 0
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "0 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 0
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "critical",
"name": "Community health",
"note": null,
"notes": [],
"value": 25,
"inputs": {
"has_readme": false,
"has_license": false,
"has_contributing": false,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (Apache-2.0)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "Apache-2.0"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
},
{
"key": "ecosystem_adoption",
"band": "moderate",
"name": "Ecosystem adoption (downloads)",
"note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"registry_dependents"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 66,
"inputs": {
"packages": [
"@joinmeow/cognito-passwordless-auth"
],
"dependents": null,
"ecosystems": "npm",
"total_downloads": null,
"monthly_downloads": 8713
},
"components": [
{
"key": "monthly_downloads",
"name": "Monthly downloads",
"detail": "8,713 downloads/month across npm",
"points": 52.5,
"status": "partial",
"details": [
{
"code": "downloads_monthly",
"params": {
"count": 8713,
"ecosystems": "npm"
}
}
],
"max_points": 80
},
{
"key": "registry_dependents",
"name": "Registry dependents",
"detail": "not reported by this ecosystem",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_reported_by_this_ecosystem",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "moderate",
"name": "Sustainability & Governance",
"value": 68,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "moderate",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 61,
"inputs": {
"bus_factor": 2,
"contributors_sampled": 20,
"top_contributor_share": 0.448
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "2 contributor(s) cover half of all commits",
"points": 25.2,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 2
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 45% of commits",
"points": 12.4,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 45
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "20 contributors",
"points": 13.5,
"status": "met",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 20
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 3 contributing companies or organizations -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "moderate",
"name": "Issue & PR responsiveness",
"note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"issue_resolution"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 69,
"inputs": {
"merged_prs": 105,
"open_issues": 0,
"closed_issues": 0,
"issue_closed_ratio": null,
"closed_unmerged_prs": 5
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "no issues or no data",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_issues_or_data",
"params": {}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "105/110 decided PRs merged",
"points": 36.5,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 105,
"decided": 110
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 0/29 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "moderate",
"name": "Ownership & stewardship",
"note": null,
"notes": [],
"value": 51,
"inputs": {
"followers": 4,
"owner_type": "Organization",
"is_verified": null,
"owner_login": "joinmeow",
"public_repos": 4,
"account_age_days": 2000
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "organization-owned",
"points": 30,
"status": "met",
"details": [
{
"code": "owner_organization",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "4 followers of joinmeow",
"points": 5,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 4,
"login": "joinmeow"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "4 public repos, account ~5 yr old",
"points": 16,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 4
}
},
{
"code": "account_age_years",
"params": {
"years": 5
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"@joinmeow/cognito-passwordless-auth"
],
"ecosystems": "npm",
"any_deprecated": false,
"min_days_since_publish": 6
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "1 package(s) on npm",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 1,
"ecosystems": "npm"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 6 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 6
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "100 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 100
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "moderate",
"name": "Engineering Quality",
"value": 53,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "good",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 82,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "2 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 2
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": ".eslintrc.cjs",
"points": 16,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": ".eslintrc.cjs"
}
}
],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "24 out of 25 merged PRs checked by a CI test -- score normalized to 9",
"points": 18,
"status": "partial",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "critical",
"name": "Documentation",
"note": null,
"notes": [],
"value": 10,
"inputs": {
"topics": [],
"has_wiki": true,
"homepage": null,
"has_readme": false,
"has_docs_dir": false,
"has_description": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "moderate",
"name": "Security",
"value": 55,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "at_risk",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): Packaging, Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"packaging",
"signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 44,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 16,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 2,
"scorecard_aggregate": 4.4
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection is not maximal on development and all release branches",
"points": 2.2,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "24 out of 25 merged PRs checked by a CI test -- score normalized to 9",
"points": 2.2,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 0/29 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 3 contributing companies or organizations -- score normalized to 10",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "no update tool detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow not detected",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 3",
"points": 1.5,
"status": "partial",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is run on all commits",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file not detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "12 existing vulnerabilities detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "dependency_advisories",
"band": "excellent",
"name": "Dependency advisories",
"note": "Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the npm:@joinmeow/cognito-passwordless-auth@1.0.104 runtime dependency closure — what installing the published package pulls in — 3 packages. Reachability is not analyzed.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"no_advisories_left_outstanding"
]
}
},
{
"code": "weights_renormalized",
"params": {}
},
{
"code": "advisories_scope_published",
"params": {
"package": "npm:@joinmeow/cognito-passwordless-auth@1.0.104",
"assessed": 3
}
},
{
"code": "advisories_reachability",
"params": {}
}
],
"value": 100,
"inputs": {
"source": "osv",
"advisories": 0,
"affected_packages": 0,
"assessed_packages": 3,
"unassessed_packages": 0,
"affected_by_severity": "none",
"direct_affected_packages": 0
},
"components": [
{
"key": "direct_dependencies_free_of_known_advisories",
"name": "Direct dependencies free of known advisories",
"detail": "no direct dependency carries a known advisory",
"points": 35,
"status": "met",
"details": [
{
"code": "no_direct_advisories",
"params": {}
}
],
"max_points": 35
},
{
"key": "indirect_dependencies_free_of_known_advisories",
"name": "Indirect dependencies free of known advisories",
"detail": "no indirect dependency carries a known advisory",
"points": 25,
"status": "met",
"details": [
{
"code": "no_indirect_advisories",
"params": {}
}
],
"max_points": 25
},
{
"key": "no_advisories_left_outstanding",
"name": "No advisories left outstanding",
"detail": "no advisory carries a publication date",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_no_publication_date",
"params": {}
}
],
"max_points": 40
}
]
},
{
"key": "malicious_dependencies",
"band": "excellent",
"name": "Malicious dependencies",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"source": "osv",
"meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
"packages": [],
"red_flag": false,
"assessed_packages": 3,
"malicious_packages": 0,
"direct_malicious_packages": 0,
"withdrawn_malicious_packages": 0,
"installable_malicious_packages": 0
},
"components": [
{
"key": "no_dependency_reported_as_a_malicious_package",
"name": "No dependency reported as a malicious package",
"detail": "no dependency is reported as a malicious package",
"points": 100,
"status": "met",
"details": [
{
"code": "no_malicious_dependencies",
"params": {}
}
],
"max_points": 100
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "excellent",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"review_only_matches": 0,
"assessed_self_published_locations": 3
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "moderate",
"name": "AI Readiness",
"value": 64,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "at_risk",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 0.8,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "no CLAUDE.md / AGENTS.md / editor rules",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_instructions",
"params": {}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "76 of 95 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 76,
"sampled": 95
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "moderate",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 69,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"package-lock.json"
],
"has_dockerfile": false,
"typed_language": true,
"bootstrap_files": [],
"has_devcontainer": false,
"has_linter_config": true,
"typecheck_configs": [
"client/tsconfig.json"
],
"agent_commit_share": 0.02,
"toolchain_manifests": [],
"dependency_bot_commit_share": 0.05
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": ".eslintrc.cjs",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": ".eslintrc.cjs"
}
}
],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "client/tsconfig.json",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "client/tsconfig.json"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "2 of the last 100 commits agent-authored or agent-credited",
"points": 4,
"status": "partial",
"details": [
{
"code": "agent_authored_commits",
"params": {
"count": 2,
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "5 of the last 100 commits are automated dependency updates",
"points": 8,
"status": "met",
"details": [
{
"code": "dependency_bot_commits",
"params": {
"count": 5,
"sampled": 100
}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 3",
"points": 3,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "excellent",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 98,
"inputs": {
"primary_language": "TypeScript",
"largest_source_bytes": 96149,
"source_files_sampled": 92,
"oversized_source_files": 3
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "TypeScript (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "TypeScript"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "3/92 source files over 60KB",
"points": 53.2,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 92,
"oversized": 3
}
}
],
"max_points": 55
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"Community profile unavailable"
],
"report_type": "repository",
"generated_at": "2026-07-27T16:54:22.870855Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/j/joinmeow/amazon-cognito-passwordless-auth.svg",
"full_name": "joinmeow/amazon-cognito-passwordless-auth",
"license_state": "standard",
"license_spdx": "Apache-2.0"
}