{"id":44040200,"url":"https://github.com/nuts-foundation/irma-web-frontend","last_synced_at":"2026-02-07T20:34:21.978Z","repository":{"id":34568407,"uuid":"179511331","full_name":"nuts-foundation/irma-web-frontend","owner":"nuts-foundation","description":"Styling to simplify and standardize the IRMA login flow","archived":false,"fork":false,"pushed_at":"2022-12-06T17:15:01.000Z","size":18712,"stargazers_count":0,"open_issues_count":12,"forks_count":0,"subscribers_count":1,"default_branch":"master","last_synced_at":"2025-10-19T10:37:18.686Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"https://nuts-foundation.github.io/irma-web-frontend/","language":"SCSS","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"lgpl-3.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/nuts-foundation.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2019-04-04T14:13:28.000Z","updated_at":"2020-12-09T14:11:37.000Z","dependencies_parsed_at":"2023-01-15T08:01:26.479Z","dependency_job_id":null,"html_url":"https://github.com/nuts-foundation/irma-web-frontend","commit_stats":null,"previous_names":[],"tags_count":6,"template":false,"template_full_name":null,"purl":"pkg:github/nuts-foundation/irma-web-frontend","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nuts-foundation%2Firma-web-frontend","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nuts-foundation%2Firma-web-frontend/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nuts-foundation%2Firma-web-frontend/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nuts-foundation%2Firma-web-frontend/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/nuts-foundation","download_url":"https://codeload.github.com/nuts-foundation/irma-web-frontend/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nuts-foundation%2Firma-web-frontend/sbom","scorecard":{"id":698967,"data":{"date":"2025-08-11","repo":{"name":"github.com/nuts-foundation/irma-web-frontend","commit":"506ef5711df1f49c70163fcd558c9b8e9384bdf9"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":1.7,"checks":[{"name":"Code-Review","score":0,"reason":"Found 0/19 approved changesets -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Dangerous-Workflow","score":-1,"reason":"no workflows found","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Token-Permissions","score":-1,"reason":"No tokens found","details":null,"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Maintained","score":0,"reason":"0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: GNU Lesser General Public License v3.0: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Pinned-Dependencies","score":-1,"reason":"no dependencies found","details":null,"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: branch protection not enabled for branch 'master'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 12 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Vulnerabilities","score":0,"reason":"55 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GHSA-93q8-gq69-wqmw","Warn: Project is vulnerable to: GHSA-v6h2-p8h4-qcjw","Warn: Project is vulnerable to: GHSA-grv7-fg5c-xmjg","Warn: Project is vulnerable to: GHSA-3xgq-45jj-v275","Warn: Project is vulnerable to: GHSA-gxpj-cx7g-858c","Warn: Project is vulnerable to: GHSA-w573-4hg7-7wgq","Warn: Project is vulnerable to: GHSA-jc84-3g44-wf2q","Warn: Project is vulnerable to: GHSA-74fj-2j2h-c42q","Warn: Project is vulnerable to: GHSA-pw2r-vq6v-hr8c","Warn: Project is vulnerable to: GHSA-jchw-25xp-jwwc","Warn: Project is vulnerable to: GHSA-cxjh-pqwp-8mfp","Warn: Project is vulnerable to: GHSA-8r6j-v8pm-fqw3","Warn: Project is vulnerable to: MAL-2023-462","Warn: Project is vulnerable to: GHSA-ww39-953v-wcq6","Warn: Project is vulnerable to: GHSA-62gr-4qp9-h98f","Warn: Project is vulnerable to: GHSA-f52g-6jhx-586p","Warn: Project is vulnerable to: GHSA-2cf5-4w76-r9qv","Warn: Project is vulnerable to: GHSA-3cqr-58rm-57f8","Warn: Project is vulnerable to: GHSA-g9r4-xpmj-mj65","Warn: Project is vulnerable to: GHSA-q2c6-c6pm-g3gh","Warn: Project is vulnerable to: GHSA-765h-qjxv-5f44","Warn: Project is vulnerable to: GHSA-f2jv-r9rf-7988","Warn: Project is vulnerable to: GHSA-vfrc-7r7c-w9mx","Warn: Project is vulnerable to: GHSA-7wwv-vh3v-89cq","Warn: Project is vulnerable to: GHSA-43f8-2h32-f4cj","Warn: Project is vulnerable to: GHSA-6x33-pw7p-hmpq","Warn: Project is vulnerable to: GHSA-qqgx-2p2h-9c37","Warn: Project is vulnerable to: GHSA-6c8f-qphg-qjgp","Warn: Project is vulnerable to: GHSA-f98m-q3hr-p5wq","Warn: Project is vulnerable to: GHSA-39q4-p535-c852","Warn: Project is vulnerable to: GHSA-h86x-mv66-gr5q","Warn: Project is vulnerable to: GHSA-p6mc-m468-83gw","Warn: Project is vulnerable to: GHSA-29mw-wpgm-hmr9","Warn: Project is vulnerable to: GHSA-35jh-r3h4-6jhm","Warn: Project is vulnerable to: GHSA-6vfc-qv3f-vr6c","Warn: Project is vulnerable to: GHSA-952p-6rrq-rcjv","Warn: Project is vulnerable to: GHSA-f8q6-p94x-37v3","Warn: Project is vulnerable to: GHSA-vh95-rmgr-6w4m","Warn: Project is vulnerable to: GHSA-xvch-5gv4-984h","Warn: Project is vulnerable to: GHSA-rp65-9cf3-cjxr","Warn: Project is vulnerable to: GHSA-x77j-w7wf-fjmw","Warn: Project is vulnerable to: GHSA-hj48-42vr-x3v9","Warn: Project is vulnerable to: GHSA-gqgv-6jq5-jjj9","Warn: Project is vulnerable to: GHSA-hrpp-h998-j3pp","Warn: Project is vulnerable to: GHSA-c2qf-rxjj-qqgw","Warn: Project is vulnerable to: GHSA-3jfq-g458-7qm9","Warn: Project is vulnerable to: GHSA-r628-mhmh-qjhw","Warn: Project is vulnerable to: GHSA-9r2w-394v-53qc","Warn: Project is vulnerable to: GHSA-5955-9wpr-37jh","Warn: Project is vulnerable to: GHSA-qq89-hq3f-393p","Warn: Project is vulnerable to: GHSA-f5x3-32g6-xq36","Warn: Project is vulnerable to: GHSA-884p-74jh-xrg2","Warn: Project is vulnerable to: GHSA-j7fq-p9q7-5wfv","Warn: Project is vulnerable to: GHSA-c4w7-xm78-47vh","Warn: Project is vulnerable to: GHSA-p9pc-299p-vxgp"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-22T04:38:21.559Z","repository_id":34568407,"created_at":"2025-08-22T04:38:21.560Z","updated_at":"2025-08-22T04:38:21.560Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":29208161,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-02-07T20:33:12.493Z","status":"ssl_error","status_checked_at":"2026-02-07T20:30:47.381Z","response_time":63,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.5:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2026-02-07T20:34:21.212Z","updated_at":"2026-02-07T20:34:21.972Z","avatar_url":"https://github.com/nuts-foundation.png","language":"SCSS","funding_links":[],"categories":[],"sub_categories":[],"readme":"_Please note that this repository has been handed over to the Privacy by Design foundation. You can find the latest version here: https://github.com/privacybydesign/irma-frontend-packages_\n\n\n# IRMA web front-end\n\n![Screenshot of the IRMA component](screenshot.gif)\n\n_See [the examples in the styleguide](https://nuts-foundation.github.io/irma-web-frontend/section-examples.html)\nfor more visual examples._\n\nImplementing IRMA disclosure flows for verifying credentials or allowing users\nto log in using IRMA can be a bit daunting, from a UX perspective. IRMA has a\nlot of different states that the user has to be guided through and the whole\nthing needs to be interactive.\n\nAlso, from a user's point of view, it will be beneficial to the adoption of IRMA\nfor these kinds of flows if they are easily recognisable and have similar\npredictable behaviour. Seen one, seen them all.\n\nFor these reasons we have released this important part of the\n[Helder application](https://helder.health) as a stand-alone open source package\nthat you can embed in your own (web based) applications.\n\nThis package has been designed and tested to work with the browsers Chrome,\nFirefox, Safari, Opera, Edge and IE11.\n\n## Technical design considerations\n\nWe want to make embedding an IRMA disclosure flow in your website as simple as\nwe can. This package only provides the required design elements that cover the\ndifferent states of the flow. If you want to make these designs actually work\nwith the IRMA app and the IRMA server, take a look at [`irma-web-glue`](https://github.com/nuts-foundation/irma-web-glue).\n\n## UX considerations\n\nEssentially we're guiding the user through a state machine, where for each state\nwe help the user recognise the next step to take. We visually mirror the design\nof the IRMA app to help users make the subconscious connection between the\nwebsite and the app.\n\n### The state machine\n\nThe state machine knows these states:\n\n 1. Uninitialised\n 2. Loading\n 3. Transition to IRMA app\n    * Showing QR code (desktop)\n    * Showing IRMA button (mobile)\n 4. Code scanned, continue on phone (desktop)\n 5. Disclosure cancelled\n 6. Disclosure timed out\n 7. Disclosure errored\n 8. Browser is not supported\n 9. Success\n\nThe happy path for this flow is:\n\n```\n1. Uninitialised →\n  2. Loading →\n    3. Transition to IRMA app →\n      (4. Code scanned, continue on phone) →\n         9. Success\n```\n\nStates 5 - 8 are all basically just catching different edge-cases.\n\n## Embedding in your application\n\nThis project currently only contains CSS. So basically you just include the CSS\nfile(s) and find the right HTML snippets [in the styleguide](https://nuts-foundation.github.io/irma-web-frontend/section-examples.html).\n\n### The old fashioned way\n\nThere is a normal version and a minified version of the styles [available for\ndownload on Github](https://github.com/nuts-foundation/irma-web-frontend/tree/master/dist)\nthat you can include in your own project. If you don't even want to host the CSS\nfiles yourself you can link from your project to the latest version like so:\n\n```html\n\u003clink rel=\"stylesheet\" href=\"//nuts-foundation.github.io/irma-web-frontend/application.css\" /\u003e\n```\n\nPlease be aware though that we can make breaking changes at any time.\n\n### The way the cool kids do it\n\nAlternatively, you can install it as an npm package. This can be useful if you\nwant to use (parts of) the SCSS behind it and override some variables, if you\nneed to package it in some complicated way or if you want to stay up to date.\n\n```bash\n$ npm install irma-web-frontend\n```\n\nYou can then pull from the entire thing or just bits and pieces of it in your\nSCSS/SASS:\n\n```scss\n  # The entire thing:\n  @import \"~irma-web-frontend/stylesheets\";\n\n  # Or just bits and pieces of it:\n  @import \"~irma-web-frontend/stylesheets/components/irma-form\";\n```\n\n## Contributing\n\n### Compiling locally\n\nRequires a working `git` and `npm` on your machine.\n\n```bash\n# Clone the project\n$ git clone git@github.com:nuts-foundation/irma-web-frontend.git\n\n# Install dependencies\n$ cd irma-web-frontend\n$ npm install\n\n# Run the compiler \u0026 dev server\n$ npm run dev\n```\n\nYou should now have the styleguide running on\n[http://localhost:8080](http://localhost:8080).\n\nAny change you make to the stylesheets will trigger a rebuild of the styleguide\nand will be shown after a browser refresh.\n\n### Making PRs\n\nPlease commit your changes in two steps for legibility:\n\n```bash\n# Commit your actual work:\n$ git add stylesheets\n$ git commit --signoff -m \"Update button shadows to reflect new design\"\n\n# And then end with any updates to the living styleguide:\n$ npm run clean # To make sure we're all good\n$ git add docs\n$ git commit --signoff -m \"Rebuild the docs\"\n```\n\nThen, feel free to make pull requests on this repository.\n\nWe sign off commits to indicate that we, as authors, are okay with releasing\nthis software under the license in the `LICENSE` file.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fnuts-foundation%2Firma-web-frontend","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fnuts-foundation%2Firma-web-frontend","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fnuts-foundation%2Firma-web-frontend/lists"}