{"_id":"@bun-win32/wintrust","_rev":"3-f41a7719b6e42597eb8cca3831178077","name":"@bun-win32/wintrust","dist-tags":{"latest":"2.0.1"},"versions":{"1.0.0":{"name":"@bun-win32/wintrust","version":"1.0.0","keywords":["bun","ffi","win32","windows","wintrust","authenticode","signature","verification","bindings","typescript","dll"],"author":"Stev Peifer <stev@bell.net>","license":"MIT","_id":"@bun-win32/wintrust@1.0.0","maintainers":[{"name":"obscuritysrl","email":"stev@bell.net"}],"homepage":"https://github.com/ObscuritySRL/bun-win32#readme","bugs":{"url":"https://github.com/ObscuritySRL/bun-win32/issues"},"dist":{"shasum":"e6ba3f1f8233abd308bcad494d0bb1061542dacb","tarball":"https://registry.npmjs.org/@bun-win32/wintrust/-/wintrust-1.0.0.tgz","fileCount":6,"integrity":"sha512-OChkyvti9a+rANpuNEm4EfRfVWfdRmSRgTDs1LrE3IKp4uAEPvw2lByRaFYfp0q3Zh23PIu6vwALRr/4C4mM6Q==","signatures":[{"sig":"MEUCIQDYVZESuySABKMs+0D9Pj4DfIN3W9ybW8l5b4QgIFdqPAIgPJ+ihVxH893Sd7hqOLHgAY4XI1xCjMkxUgkIaNkpAmw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":28638},"main":"./index.ts","type":"module","module":"index.ts","shasum":"e6ba3f1f8233abd308bcad494d0bb1061542dacb","engines":{"bun":">=1.1.0"},"exports":{".":"./index.ts"},"private":false,"scripts":{"example:trust-radar":"bun ./example/trust-radar.ts","example:authenticode-audit":"bun ./example/authenticode-audit.ts"},"_npmUser":{"name":"obscuritysrl","email":"stev@bell.net"},"_integrity":"sha512-OChkyvti9a+rANpuNEm4EfRfVWfdRmSRgTDs1LrE3IKp4uAEPvw2lByRaFYfp0q3Zh23PIu6vwALRr/4C4mM6Q==","repository":{"url":"git://github.com/ObscuritySRL/bun-win32.git","type":"git","directory":"packages/wintrust"},"_npmVersion":"10.8.3","description":"Zero-dependency, zero-overhead Win32 WINTRUST bindings for Bun (FFI) on Windows.","directories":{},"sideEffects":false,"_nodeVersion":"24.3.0","dependencies":{"@bun-win32/core":"1.1.2"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","@bun-win32/kernel32":"1.0.21"},"peerDependencies":{"typescript":"^5"},"_npmOperationalInternal":{"tmp":"tmp/wintrust_1.0.0_1778847658553_0.10622887682476456","host":"s3://npm-registry-packages-npm-production"}},"2.0.0":{"name":"@bun-win32/wintrust","version":"2.0.0","keywords":["bun","ffi","win32","windows","wintrust","authenticode","signature","verification","bindings","typescript","dll"],"author":"Stev Peifer <stev.p@outlook.com>","license":"MIT","_id":"@bun-win32/wintrust@2.0.0","maintainers":[{"name":"obscuritysrl","email":"stev.p@outlook.com"}],"homepage":"https://github.com/ObscuritySRL/bun-win32#readme","bugs":{"url":"https://github.com/ObscuritySRL/bun-win32/issues"},"dist":{"shasum":"06f1c818d040db2185fa7491b1b27a95a9ae47e0","tarball":"https://registry.npmjs.org/@bun-win32/wintrust/-/wintrust-2.0.0.tgz","fileCount":6,"integrity":"sha512-DWQddjBB1eugY9B7wF1miDUnNfavxQbrq9Z9U5/JyGcVubmXD9jzEK1SbCrKW7PNabtC9M7I8edA/Vw57AdDPA==","signatures":[{"sig":"MEQCIDWKD8Eq/p7867rlx+ZjZEEWJuG1t2myYYbWtl+3TPdZAiB0Jr82B6Vb6OAxhqXOMP+PUVtaoGiCMaD2CDB27/Muag==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":30199},"main":"./index.ts","type":"module","module":"index.ts","shasum":"06f1c818d040db2185fa7491b1b27a95a9ae47e0","engines":{"bun":">=1.1.0"},"exports":{".":"./index.ts"},"private":false,"scripts":{"example:trust-radar":"bun ./example/trust-radar.ts","example:authenticode-audit":"bun ./example/authenticode-audit.ts"},"_npmUser":{"name":"obscuritysrl","email":"stev.p@outlook.com"},"_integrity":"sha512-DWQddjBB1eugY9B7wF1miDUnNfavxQbrq9Z9U5/JyGcVubmXD9jzEK1SbCrKW7PNabtC9M7I8edA/Vw57AdDPA==","repository":{"url":"git://github.com/ObscuritySRL/bun-win32.git","type":"git","directory":"packages/wintrust"},"_npmVersion":"10.8.3","description":"Zero-dependency, zero-overhead Win32 WINTRUST bindings for Bun (FFI) on Windows.","directories":{},"sideEffects":false,"_nodeVersion":"26.3.0","dependencies":{"@bun-win32/core":"2.0.0"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","@bun-win32/kernel32":"2.0.0"},"peerDependencies":{"typescript":"^5"},"_npmOperationalInternal":{"tmp":"tmp/wintrust_2.0.0_1782435999434_0.40374354627746656","host":"s3://npm-registry-packages-npm-production"}},"2.0.1":{"author":"Stev Peifer <stev.p@outlook.com>","bugs":{"url":"https://github.com/ObscuritySRL/bun-win32/issues"},"dependencies":{"@bun-win32/core":"2.0.1"},"description":"Zero-dependency, zero-overhead Win32 WINTRUST bindings for Bun (FFI) on Windows.","devDependencies":{"@bun-win32/kernel32":"2.0.1","@types/bun":"latest"},"exports":{".":"./index.ts"},"license":"MIT","module":"index.ts","name":"@bun-win32/wintrust","peerDependencies":{"typescript":"^5"},"private":false,"homepage":"https://github.com/ObscuritySRL/bun-win32#readme","repository":{"type":"git","url":"git://github.com/ObscuritySRL/bun-win32.git","directory":"packages/wintrust"},"type":"module","version":"2.0.1","main":"./index.ts","keywords":["bun","ffi","win32","windows","wintrust","authenticode","signature","verification","bindings","typescript","dll"],"sideEffects":false,"engines":{"bun":">=1.1.0"},"scripts":{"example:authenticode-audit":"bun ./example/authenticode-audit.ts","example:trust-radar":"bun ./example/trust-radar.ts"},"_id":"@bun-win32/wintrust@2.0.1","_integrity":"sha512-B009QaBSJFRkdR6aADLTuuGbKSvAE7NrWkvSyhfgfr/ZTcshQCEgz5qUtT0y9gZS98Y4W/mQNsP8sYXPkPAkkA==","_nodeVersion":"26.3.0","_npmVersion":"10.8.3","shasum":"60609d609eab2e857082c5983423af9c34c55efa","dist":{"integrity":"sha512-B009QaBSJFRkdR6aADLTuuGbKSvAE7NrWkvSyhfgfr/ZTcshQCEgz5qUtT0y9gZS98Y4W/mQNsP8sYXPkPAkkA==","shasum":"60609d609eab2e857082c5983423af9c34c55efa","tarball":"https://registry.npmjs.org/@bun-win32/wintrust/-/wintrust-2.0.1.tgz","fileCount":6,"unpackedSize":30199,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDIkgsbhII0hGu6gLaU1SyiWvgPDU7JsCdWz8BABtvRVwIhALD23Z0JsujiO33uNQQ+S5Pi4Evn/1UnN4MXY6TP82X+"}]},"_npmUser":{"name":"obscuritysrl","email":"stev.p@outlook.com"},"directories":{},"maintainers":[{"name":"obscuritysrl","email":"stev.p@outlook.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/wintrust_2.0.1_1782438224446_0.7322998478980773"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-15T12:20:58.392Z","modified":"2026-06-26T01:43:44.696Z","1.0.0":"2026-05-15T12:20:58.766Z","2.0.0":"2026-06-26T01:06:39.678Z","2.0.1":"2026-06-26T01:43:44.587Z"},"bugs":{"url":"https://github.com/ObscuritySRL/bun-win32/issues"},"author":"Stev Peifer <stev.p@outlook.com>","license":"MIT","homepage":"https://github.com/ObscuritySRL/bun-win32#readme","keywords":["bun","ffi","win32","windows","wintrust","authenticode","signature","verification","bindings","typescript","dll"],"repository":{"type":"git","url":"git://github.com/ObscuritySRL/bun-win32.git","directory":"packages/wintrust"},"description":"Zero-dependency, zero-overhead Win32 WINTRUST bindings for Bun (FFI) on Windows.","maintainers":[{"name":"obscuritysrl","email":"stev.p@outlook.com"}],"readme":"# @bun-win32/wintrust\n\nZero-dependency, zero-overhead Win32 Wintrust bindings for [Bun](https://bun.sh) on Windows.\n\n## Overview\n\n`@bun-win32/wintrust` exposes the `wintrust.dll` exports using [Bun](https://bun.sh)'s FFI. It provides a single class, `Wintrust`, which lazily binds native symbols on first use. You can optionally preload a subset or all symbols up-front via `Preload()`.\n\nThe bindings are strongly typed for a smooth DX in TypeScript.\n\n## Features\n\n- [Bun](https://bun.sh)-first ergonomics on Windows 10/11.\n- Direct FFI to `wintrust.dll` (Authenticode signature verification, catalog files, trust providers, and subject interface packages).\n- In-source docs in `structs/Wintrust.ts` with links to Microsoft Docs.\n- Lazy binding on first call; optional eager preload (`Wintrust.Preload()`).\n- No wrapper overhead; calls map 1:1 to native APIs.\n- Strongly-typed Win32 aliases (see `types/Wintrust.ts`).\n\n## Requirements\n\n- [Bun](https://bun.sh) runtime\n- Windows 10 or later\n\n## Installation\n\n```sh\nbun add @bun-win32/wintrust\n```\n\n## Quick Start\n\n```ts\nimport Wintrust, { WINTRUST_ACTION_GENERIC_VERIFY_V2 } from '@bun-win32/wintrust';\n\n// Verify the Authenticode signature of a PE file.\nfunction verify(exePath: string): number {\n  // WINTRUST_FILE_INFO (x64): 32 bytes\n  const pathBuf = Buffer.from(exePath + '\\0', 'utf16le');\n  const fileInfo = Buffer.alloc(32);\n  fileInfo.writeUInt32LE(32, 0); // cbStruct\n  fileInfo.writeBigUInt64LE(BigInt(pathBuf.ptr!), 8); // pcwszFilePath\n\n  // WINTRUST_DATA (x64, with pSignatureSettings): 88 bytes\n  const trustData = Buffer.alloc(88);\n  trustData.writeUInt32LE(88, 0); // cbStruct\n  trustData.writeUInt32LE(2, 24); // dwUIChoice = WTD_UI_NONE\n  trustData.writeUInt32LE(0, 28); // fdwRevocationChecks = WTD_REVOKE_NONE\n  trustData.writeUInt32LE(1, 32); // dwUnionChoice = WTD_CHOICE_FILE\n  trustData.writeBigUInt64LE(BigInt(fileInfo.ptr!), 40); // pFile\n\n  return Wintrust.WinVerifyTrust(-1n, WINTRUST_ACTION_GENERIC_VERIFY_V2.ptr!, trustData.ptr!);\n}\n\nconst status = verify(process.execPath);\nconsole.log(status === 0 ? 'Trusted' : `Failed: 0x${(status >>> 0).toString(16)}`);\n```\n\n> [!NOTE]\n> AI agents: see `AI.md` for the package binding contract and source-navigation guidance. It explains how to use the package without scanning the entire implementation.\n\n## Examples\n\nRun the included examples:\n\n```sh\nbun run example:authenticode-audit  # System32 signature audit with status bars and counts\nbun run example:trust-radar         # Animated radar sweep verifying directories in real time\n```\n\n## Notes\n\n- Either rely on lazy binding or call `Wintrust.Preload()`.\n- WinVerifyTrust returns 0 on success; any non-zero value is a status code (do **not** use `SUCCEEDED()`).\n- System files like `notepad.exe` are catalog-signed (no embedded signature); WinVerifyTrust returns `TRUST_E_NOSIGNATURE` (0x800B0100) for them — use `CryptCATAdmin*` to look them up in the system catalog database.\n- Windows only. Bun runtime required.\n- **SAL types & naming:** nullability is in the **type** — `Optional<T>` (formally optional, SAL `_*opt_`) and `Nullable<T>` (plain `[in]`/`[out]` the docs say can be NULL), the null sentinel derived from `T` (`null` for pointers `LP*`/`P*`, `0n` for handles/by-value addresses); direction is in the **parameter name** — `_out` (`_Out_`), `_in_out` (`_Inout_`), `_In_` bare. See `AI.md` and the repo `AGENTS.md`.\n","readmeFilename":"README.md"}