New Research: Supply Chain Attack on Axios Pulls Malicious Dependency from npm.Details →
Socket
Book a DemoSign in
Socket

@sigstore/core

Package Overview
Dependencies
Maintainers
1
Versions
8
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@sigstore/core - npm Package Compare versions

Comparing version
3.1.0
to
3.2.0
+10
-1
dist/crypto.js

@@ -28,3 +28,12 @@ "use strict";

if (typeof key === 'string') {
return crypto_1.default.createPublicKey(key);
if (key.startsWith('-----')) {
return crypto_1.default.createPublicKey(key);
}
else {
return crypto_1.default.createPublicKey({
key: Buffer.from(key, 'base64'),
format: 'der',
type: type,
});
}
}

@@ -31,0 +40,0 @@ else {

+1
-1
{
"name": "@sigstore/core",
"version": "3.1.0",
"version": "3.2.0",
"description": "Base library for Sigstore",

@@ -5,0 +5,0 @@ "main": "dist/index.js",