@aws-amplify/amplify-category-function
amplify-cli function plugin
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:dynamic-require | AI (semgrep): CLI command-dispatch pattern loading subcommands by category name; stable across versions of this package. | ai | |
| dependencies | unvetted-dep:@aws-amplify/amplify-cli-core | AI (dependencies): Core AWS Amplify CLI package from the same publisher; stable ecosystem dependency. | ai | |
| dependencies | unvetted-dep:@aws-amplify/amplify-prompts | AI (dependencies): AWS Amplify ecosystem package from same publisher; stable. | ai | |
| dependencies | unvetted-dep:@aws-amplify/amplify-environment-parameters | AI (dependencies): AWS Amplify ecosystem package from same publisher; stable. | ai | |
| dependencies | unvetted-dep:@aws-amplify/amplify-function-plugin-interface | AI (dependencies): AWS Amplify ecosystem package from same publisher; stable. | ai | |
| dependencies | unvetted-dep:graphql-transformer-core | AI (dependencies): AWS Amplify GraphQL transformer package; consistent with this package's purpose. | ai | |
| dependencies | unvetted-dep:cloudform-types | AI (dependencies): CloudFormation types library; expected dependency for AWS infrastructure tooling. | ai | |
| dependencies | unvetted-dep:jstreemap | AI (dependencies): Utility data structure library; no malicious indicators. | ai | |
| dependencies | unvetted-dep:promise-sequential | AI (dependencies): Small utility library for sequential promise execution; no malicious indicators. | ai | |
| dependencies | unvetted-dep:inquirer-datepicker | AI (dependencies): CLI datepicker plugin for inquirer; consistent with interactive CLI tooling. | ai |
Versions (showing 4 of 4)
| Version | Deps | Published |
|---|---|---|
| 5.8.2 | 19 / 2 | |
| 5.8.1 | 19 / 2 | |
| 5.7.18 | 19 / 2 | |
| 5.7.15 | 19 / 2 |
v5.8.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.8.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.7.18
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.7.15
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.