
Security News
Ruby's Bundler 4.0.18 Extends Cooldown to bundle lock and bundle cache
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.
@dotit/sign
Advanced tools
Ed25519 cryptographic signatures for IntentText (.it) documents — provable 'who signed', self-verifying and offline. The opt-in identity layer on top of @dotit/core's integrity seal.
Ed25519 cryptographic signatures for IntentText (.it) documents. The opt-in
identity layer on top of @dotit/core's
integrity seal.
@dotit/core → "has the content changed?" SHA-256, zero-dependency
@dotit/sign → "who signed it?" Ed25519, audited crypto (@noble/curves)
A signature is self-verifying and offline: each sign: line embeds both the
Ed25519 signature and the signer's public key, so a .it file carries
everything needed to verify it — no server, no key lookup, no network.
K signed this exact content.K belongs to a particular real-world person.
Binding a key to a verified identity is UTS certification (a later layer).npm install @dotit/sign # library
# or use the CLI:
npx @dotit/sign keygen
import {
generateSigningKey,
signDocumentCrypto,
verifyDocumentSignatures,
} from "@dotit/sign";
const key = generateSigningKey();
// → { privateKey: "…", publicKey: "…" } (base64url, keep the private key secret)
const signed = signDocumentCrypto(source, {
signer: "Ahmed Al-Rashid",
role: "CEO",
privateKey: key.privateKey,
});
// signed.source now has:
// sign: Ahmed Al-Rashid | role: CEO | at: … | hash: sha256:… | key: ed25519:… | sig: …
const v = verifyDocumentSignatures(signed.source);
// → { hash, signatures: [{ signer, role, valid, cryptographic, publicKey, reason }],
// validCount, allSignaturesValid }
Editing the document after signing flips its signatures to valid: false — exactly
as it should. Signing is idempotent per public key (no duplicate sign: lines),
and signatures survive sealing (the freeze: line is excluded from the hash).
dotit-sign)dotit-sign keygen --out key.json # generate a keypair (0600 file)
dotit-sign sign contract.it --key key.json \
--signer "Ahmed Al-Rashid" --role CEO # add a cryptographic signature
dotit-sign verify contract.it # exit 0 = all valid, 1 = invalid
verify is a clean CI gate: it needs nothing but the file (the public key is
embedded) and returns a non-zero exit code if any signature fails.
.it proves integrity today (@dotit/core). @dotit/sign adds identity.
A UTS timestamp authority will add provable time, and an optional public anchor
adds permanence — each an independent layer, each claim one you can prove. See
the project's SECURITY-MODEL.md.
Crypto is @noble/curves — audited,
constant-time, runs in Node and the browser. We never hand-roll signature math.
MIT · part of the dotit ecosystem.
A signature proves who signed. A certification is issued by a trust authority (UTS) and proves "authority A attests this exact content existed at time T, from account N" — provable time, and (with KYC at onboarding) a vouched identity for the account.
import { certifyDocument, verifyCertifications } from "@dotit/sign";
// Run by the AUTHORITY (UTS) with its private key — never the document author:
const certified = certifyDocument(source, { issuer: "UTS", account: "acme-corp", issuerPrivateKey: UTS_KEY });
// certify: UTS | account: acme-corp | at: … | hash: sha256:… | key: ed25519:<utsPub> | sig: …
// Anyone verifies against UTS's PUBLISHED public key (offline):
const checks = verifyCertifications(certified.source, { UTS: UTS_PUBLIC_KEY });
// → [{ issuer, account, at, valid, signatureValid, trusted, reason }]
A forged certify: UTS … line signed with someone else's key is rejected
(trusted: false) — the embedded key must match the published UTS key. Editing
the document invalidates the certification. CLI: dotit-sign certify <file> --key uts-key.json --account "acme-corp" (authority) and dotit-sign verify <file> --trust UTS=<pubkey>.
FAQs
Ed25519 cryptographic signatures for IntentText (.it) documents — provable 'who signed', self-verifying and offline. The opt-in identity layer on top of @dotit/core's integrity seal.
The npm package @dotit/sign receives a total of 20 weekly downloads. As such, @dotit/sign popularity was classified as not popular.
We found that @dotit/sign demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.

Security News
During a UK cyber test, a Mythos 5 agent used sockpuppets, social engineering, and prompt injection to try to get a maintainer to merge malware.

Company News
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.