New:Microsoft Teams Notifications Are Now Available in Socket.Learn more →
Get Started

@codai/axiom-canon

Package Overview
Dependencies
Maintainers
1
Versions
7
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@codai/axiom-canon

RFC 8785 JSON canonicalization, sha256 digests and in-toto Statement/SLSA provenance builders for AXIOM

latest
Source
npmnpm
Version
2.4.0
Version published
Maintainers
1
Created
Source

@codai/axiom-canon

Zero-dependency canonicalization and attestation primitives for AXIOM v2.

What: RFC 8785 JSON Canonicalization (JCS), sha256 content addressing (sha256:<hex>), an in-toto Statement v1 / SLSA Provenance v1 builder, and DSSE Pre-Authentication Encoding. Only node:crypto at runtime.

Why: every AXIOM artefact (Manifest, Plan, facts, Statement) is identified by the hash of its canonical bytes. Deterministic serialization is what makes manifestDigest reproducible across OSes and lets verify byte-compare instead of trusting a parser. Lifted from codai/packages/rules-core.

API

  • canonicalize(value): string — JCS; throws CanonicalizeError on NaN, bigint, lone surrogates. undefined members are dropped.
  • sha256Hex, sha256Digest, digestRef, parseDigestRef
  • canonicalHash(value), canonicalDigestRef(value), verifyCanonical(text)
  • buildStatement(input): InTotoStatementV1 + constants IN_TOTO_STATEMENT_V1, SLSA_PROVENANCE_V1, AXIOM_BUILD_TYPE, AXIOM_BUILDER_ID
  • pae(payloadType, payload): Uint8Array, DSSE_IN_TOTO_PAYLOAD_TYPE

Keywords

axiom

FAQs

Package last updated on 27 Sep 2026

Related posts