Hi,
In fact peertube doesn't use this library anymore. We switched to https://github.com/misskey-dev/node-http-message-signatures
Ironically, Misskey doesn't still use PeerTube (npub17gp…7p4g)/http-signature.
The former dev of @misskey-dev/node-http-message-signatures expressed concerns about the maintenance status of the library: https://github.com/Chocobozzz/PeerTube/issues/7372
However, upon reviewing it, I found no issues or security considerations with the library. PeerTube (npub17gp…7p4g)/http-signature (based on https://github.com/TritonDataCenter/node-http-signature) isn't really maintained either