@aws-amplify/amplify-category-function
amplify-cli function plugin
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:dynamic-require | AI (semgrep): CLI command-dispatch pattern loading subcommands by category name; stable across versions of this package. | ai | |
| dependencies | unvetted-dep:@aws-amplify/amplify-cli-core | AI (dependencies): Core AWS Amplify CLI package from the same publisher; stable ecosystem dependency. | ai | |
| dependencies | unvetted-dep:@aws-amplify/amplify-prompts | AI (dependencies): AWS Amplify ecosystem package from same publisher; stable. | ai | |
| dependencies | unvetted-dep:@aws-amplify/amplify-environment-parameters | AI (dependencies): AWS Amplify ecosystem package from same publisher; stable. | ai | |
| dependencies | unvetted-dep:@aws-amplify/amplify-function-plugin-interface | AI (dependencies): AWS Amplify ecosystem package from same publisher; stable. | ai | |
| dependencies | unvetted-dep:graphql-transformer-core | AI (dependencies): AWS Amplify GraphQL transformer package; consistent with this package's purpose. | ai | |
| dependencies | unvetted-dep:cloudform-types | AI (dependencies): CloudFormation types library; expected dependency for AWS infrastructure tooling. | ai | |
| dependencies | unvetted-dep:jstreemap | AI (dependencies): Utility data structure library; no malicious indicators. | ai | |
| dependencies | unvetted-dep:promise-sequential | AI (dependencies): Small utility library for sequential promise execution; no malicious indicators. | ai | |
| dependencies | unvetted-dep:inquirer-datepicker | AI (dependencies): CLI datepicker plugin for inquirer; consistent with interactive CLI tooling. | ai |
Versions (showing 15 of 15)
| Version | Deps | Published |
|---|---|---|
| 5.8.3 | 19 / 2 | |
| 5.8.2 | 19 / 2 | |
| 5.8.1 | 19 / 2 | |
| 5.7.18 | 19 / 2 | |
| 5.7.15 | 19 / 2 | |
| 5.7.14 | 19 / 2 | |
| 5.7.13 | 19 / 2 | |
| 5.7.12 | 19 / 2 | |
| 5.7.11 | 19 / 2 | |
| 5.7.10 | 19 / 2 | |
| 5.7.9 | 19 / 2 | |
| 5.7.8 | 19 / 2 | |
| 5.7.7 | 19 / 2 | |
| 5.7.6 | 19 / 2 | |
| 5.7.5 | 19 / 2 |
v5.7.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.7.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.7.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.7.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.7.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.7.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.7.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.7.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.7.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.7.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.