
Security News
Happy Birthday, Shai-Hulud
It has been one year since Shai-Hulud made its first appearance on npm.
@peac/adapter-eat
Advanced tools
EAT (Entity Attestation Token, RFC 9711) passport decoder and PEAC claim mapper
EAT (Entity Attestation Token, RFC 9711) passport decoder and PEAC claim mapper with privacy-first defaults.
pnpm add @peac/adapter-eat
@peac/adapter-eat is a Layer 4 adapter that decodes COSE_Sign1 structures (RFC 9052) containing Entity Attestation Token payloads and maps them into Interaction Record format claims. It verifies Ed25519 signatures, enforces a 64 KB size limit before CBOR decode to prevent denial-of-service, and hashes all claim values with SHA-256 by default so that no raw attestation data leaks into PEAC receipts.
import { decodeEatPassport } from '@peac/adapter-eat';
const result = await decodeEatPassport(coseBytes, publicKey);
if (result.verified) {
console.log('Claims:', result.claims);
console.log('Algorithm:', result.headers.alg); // -8 (EdDSA)
}
import { decodeEatPassport, mapEatClaims } from '@peac/adapter-eat';
const result = await decodeEatPassport(coseBytes, publicKey);
if (result.verified) {
// Privacy-first: all values are SHA-256 hashed by default
const mapped = await mapEatClaims(result.claims);
console.log('Type:', mapped.type); // 'org.peacprotocol/attestation'
console.log('Pillars:', mapped.pillars); // ['identity']
console.log('Values:', mapped.values); // Map<number, string> with hashed values
// Opt in to raw values when needed
const raw = await mapEatClaims(result.claims, { includeRawClaims: true });
}
@peac/kernel (Layer 0): Wire constants and types@peac/schema (Layer 1): Interaction Record format claim schemas@peac/crypto (Layer 2): Ed25519 signature verification and SHA-256 hashing@peac/protocol (Layer 3): Receipt issuance with mapped EAT claimsIf you are building an agent that needs to verify device or entity attestations:
decodeEatPassport() to decode and verify COSE_Sign1 tokens from hardware or software attestation sourcesmapEatClaims() to convert verified attestations into PEAC receipt claims with privacy-safe defaultsApache-2.0
PEAC Protocol is an open source project stewarded by Originary and community contributors.
FAQs
EAT (Entity Attestation Token, RFC 9711) passport decoder and PEAC claim mapper
The npm package @peac/adapter-eat receives a total of 13 weekly downloads. As such, @peac/adapter-eat popularity was classified as not popular.
We found that @peac/adapter-eat demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.