
Security News
Happy Birthday, Shai-Hulud
It has been one year since Shai-Hulud made its first appearance on npm.
@cellar-door/attestation-core
Advanced tools
Shared attestation primitives for EXIT Protocol adapters — marker hashing, salt generation, and core types.
𓉸 Passage Protocol · exit-door · entry-door · mcp · langchain · vercel · eliza · eas · erc-8004 · sign · python
⚠️ Pre-release software — no formal security audit has been conducted. This project is published for transparency, review, and community feedback. It should not be used in production systems where security guarantees are required. Report vulnerabilities to hawthornhollows@gmail.com.
Shared hash, salt, and verification logic for EXIT Protocol attestation adapters. Used internally by @cellar-door/eas, @cellar-door/sign-protocol, and @cellar-door/erc-8004.
npm install @cellar-door/attestation-core
computeMarkerHash(marker, salt?)Compute a keccak256 commitment hash for an EXIT marker.
import { computeMarkerHash } from '@cellar-door/attestation-core';
const { hash, salt } = computeMarkerHash(marker);
// hash: '0x...' (bytes32)
// salt: '0x...' (auto-generated 256-bit random salt)
// With explicit salt:
const { hash } = computeMarkerHash(marker, existingSalt);
verifyMarkerHash(marker, expectedHash, salt)Verify that a marker matches a previously computed hash.
import { verifyMarkerHash } from '@cellar-door/attestation-core';
const valid = verifyMarkerHash(marker, hash, salt);
// true if recomputed hash matches expectedHash
randomSalt()Generate a cryptographically random 256-bit salt.
import { randomSalt } from '@cellar-door/attestation-core';
const salt = randomSalt();
// '0x...' (32 bytes hex)
| Package | Language | Description |
|---|---|---|
| cellar-door-exit | TypeScript | Core protocol (reference impl) |
| cellar-door-exit | Python | Core protocol |
| cellar-door-entry | TypeScript | Arrival/entry markers |
| @cellar-door/langchain | TypeScript | LangChain integration |
| cellar-door-langchain | Python | LangChain integration |
| @cellar-door/vercel-ai-sdk | TypeScript | Vercel AI SDK |
| @cellar-door/mcp-server | TypeScript | MCP server |
| @cellar-door/eliza | TypeScript | ElizaOS plugin |
| @cellar-door/eas | TypeScript | EAS attestation anchoring |
| @cellar-door/erc-8004 | TypeScript | ERC-8004 identity/reputation |
| @cellar-door/sign-protocol | TypeScript | Sign Protocol attestation |
Apache-2.0
FAQs
Shared attestation primitives for EXIT Protocol adapters — marker hashing, salt generation, and core types.
The npm package @cellar-door/attestation-core receives a total of 2 weekly downloads. As such, @cellar-door/attestation-core popularity was classified as not popular.
We found that @cellar-door/attestation-core demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.