auth0/node-jsonwebtoken
56.7
Adequate · 1 October 2026
577
lines of production code
JavaScript
primary language
2
measurements over time
What this system is
This system is a JSON Web Token (JWT) library for Node.js that handles token signing, verification, and decoding. It enforces strict security practices by validating key types and algorithms to prevent confusion attacks, while providing structured error handling for token expiration and validation failures. The codebase is maintained with modern tooling, including semantic versioning and comprehensive test coverage for standard and private JWT claims.
Behavioural changes
Commit message validation via commitlint
The repository now enforces commit message standards using commitlint. When a commit is created, the commit-msg hook automatically checks the message format against configured rules, ensuring consistent and semantic commit history.
.husky · high confidence
Major v9 release with breaking changes and security fixes
This release upgrades the library to version 9.0.3, updating the underlying \jws\ dependency to 4.0.1. It introduces significant breaking changes: support for Node versions 11 and below is removed, \jwt.verify()\ no longer accepts unsigned tokens by default (requiring explicit configuration), and RSA key sizes must be 2048 bits or greater. The release also addresses multiple security vulnerabilities ([CVE redacted], [CVE redacted], [CVE redacted], [CVE redacted]) related to arbitrary file writes, insecure default algorithms, and unrestricted key types. Additionally, the codebase has been refactored into separate modules (\sign.js\, \verify.js\, \decode.js\) and CI/CD infrastructure has been updated to use semantic-release with conventional commits.
(repo-wide) · high confidence
Structured error types and asymmetric key validation
The library now introduces specific error classes (JsonWebTokenError, NotBeforeError, TokenExpiredError) that provide clearer context for failures, including the expiration date or 'not before' date. Additionally, asymmetric key validation has been enhanced to strictly enforce allowed algorithms per key type (EC, RSA, RSA-PSS) and, on supported Node versions, validates specific key details like EC curves and RSA-PSS parameters to prevent algorithm confusion attacks.
lib · high confidence
Test coverage
Expanded test coverage for JWT claims and signing behavior
Added comprehensive test suites for standard JWT claims (audience, expiration, issued-at, issuer, JWT ID, not-before, subject) and private claims, including validation of option types and payload interactions. Introduced tests for asynchronous signing, buffer payloads, decoding edge cases, and cryptographic key handling (DSA, ECDSA, RSA with insecure key size checks).
test · high confidence
Dependencies
Upgrade to v9.0.3 with modernized dependencies and build tooling
The package has been updated to version 9.0.3, renaming from 'node-jsonwebtoken' to 'jsonwebtoken'. This release upgrades the core 'jws' dependency to ^4.0.1 and introduces several new dependencies including 'lodash' utility packages, 'ms' for time handling, and 'semver' for version management. The build process now enforces stricter code coverage requirements via 'nyc' and integrates 'husky' for git hooks, while the supported runtime environment is explicitly defined as Node.js \>=12 and npm \>=6.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 57 → 57 (-0.0)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 59 → 58 (-1.1)
- Architecture 69 → 69 (+0.0)
- Maturity 49 → 49 (+0.0)
- Readiness 63 → 63 (+0.7)
- Security 88 → 92 (+3.5)
Resolved (1)
- Documentation: no licence statement (README.md)
New (7)
- Documentation: no project overview (README.md)
- Scanner failed to run — not a clean result
- sign.default (cognitive 68) (sign.js)
- sign.default (cyclomatic 55) (sign.js)
- validateAsymmetricKey.default (cognitive 24) (lib/validateAsymmetricKey.js)
- verify.default (cognitive 99) (verify.js)
- verify.default (cyclomatic 78) (verify.js)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
auth0/node-jsonwebtoken was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 1 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit b924272f29192e12926b5414546f7c5bfcc9579d — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.