@aws-amplify/analytics
Analytics category of aws-amplify
51
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
amzn-ossaws-amplify-opsamplify-studio-uibuilderamplify-codegenamplify-data-dev-npmaws-amplify-data-runtime
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): aws-amplify-ops is a well-established publisher with 566 approved packages; missing gitHead likely reflects a CI/CD pipeline change in this large monorepo, not a supply chain compromise. | ai | |
| dependencies | unvetted-dep:aws-sdk | AI (dependencies): aws-sdk is a core dependency for AWS service integration; expected and legitimate for this analytics package. | ai | |
| source-diff | source-size-tripled | AI (source-diff): 3.6x size increase corresponds to new AWS SDK integrations and analytics features; no injected payloads detected. | ai | |
| source-diff | large-new-source-files | AI (source-diff): 68 new source files reflect normal development activity for a mature package; no evidence of bundled/injected code. | ai | |
| provenance | publisher-changed | AI (provenance): Publisher transition (mlabieniec → aws-amplify-ops) in 2019 reflects AWS's official adoption of Amplify; stable for this package. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New dependencies are all official AWS SDK packages for analytics integrations; legitimate feature expansion, not attack vector. | ai | |
| dependencies | unvetted-dep:@aws-sdk/client-kinesis-browser | AI (dependencies): AWS SDK browser client; legitimate dependency for analytics package. Stable for this package. | ai | |
| dependencies | unvetted-dep:@aws-amplify/cache | AI (dependencies): Internal AWS Amplify monorepo dependency with pinned constraint; stable for this package. | ai | |
| dependencies | unvetted-dep:@aws-sdk/client-firehose | AI (dependencies): Official AWS SDK; appropriate for analytics service integration. | ai | |
| dependencies | unvetted-dep:@aws-sdk/client-personalize-events | AI (dependencies): Official AWS SDK; appropriate for analytics service integration. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Signals are weak for an established scoped package from a known organization; mass production signal applies to different publisher (elorzafe). | ai | |
| dependencies | unvetted-dep:@aws-sdk/client-kinesis | AI (dependencies): Official AWS SDK; appropriate for analytics service integration. | ai | |
| provenance | no-provenance | AI (provenance): Package predates Sigstore adoption; no provenance is expected for established packages from this era. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): AWS Amplify maintainer transitions are documented organizational changes; stable for this package. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Maintainer removal in context of AWS Amplify's scale is expected; no takeover indicators present. | ai | |
| dependencies | unvetted-dep:@aws-amplify/core | AI (dependencies): Internal Amplify dependency from same trusted publisher; unvetted status is expected for monorepo packages. | ai | |
| dependencies | unvetted-dep:@aws-sdk/client-personalize-events-browser | AI (dependencies): Official AWS SDK preview package from Amazon; unvetted status reflects early preview versioning, not a security concern. | ai | |
| dependencies | unvetted-dep:@aws-sdk/client-pinpoint-browser | AI (dependencies): Official AWS SDK preview package from Amazon; unvetted status reflects early preview versioning, not a security concern. | ai |
Versions (showing 51 of 177)
| Version | Deps | Published |
|---|---|---|
| 7.1.0 | 5 / 3 | |
| 7.0.94 | 5 / 3 | |
| 7.0.93 | 5 / 3 | |
| 7.0.92 | 5 / 3 | |
| 7.0.91 | 5 / 3 | |
| 7.0.90 | 5 / 3 | |
| 7.0.89 | 5 / 3 | |
| 7.0.88 | 5 / 3 | |
| 7.0.87 | 5 / 3 | |
| 7.0.86 | 5 / 3 | |
| 7.0.85 | 5 / 3 | |
| 7.0.84 | 5 / 3 | |
| 7.0.83 | 5 / 3 | |
| 7.0.82 | 5 / 3 | |
| 7.0.81 | 5 / 3 | |
| 7.0.80 | 5 / 4 | |
| 7.0.79 | 5 / 4 | |
| 7.0.78 | 5 / 4 | |
| 7.0.77 | 5 / 4 | |
| 7.0.76 | 5 / 4 | |
| 7.0.75 | 5 / 4 | |
| 7.0.74 | 5 / 4 | |
| 7.0.73 | 5 / 4 | |
| 7.0.72 | 5 / 4 | |
| 7.0.71 | 5 / 4 | |
| 7.0.70 | 5 / 4 | |
| 7.0.69 | 5 / 4 | |
| 7.0.68 | 5 / 4 | |
| 7.0.67 | 5 / 4 | |
| 7.0.66 | 5 / 4 | |
| 7.0.65 | 5 / 4 | |
| 7.0.64 | 5 / 4 | |
| 7.0.63 | 5 / 4 | |
| 7.0.62 | 5 / 4 | |
| 7.0.61 | 5 / 4 | |
| 7.0.60 | 5 / 4 | |
| 7.0.59 | 5 / 4 | |
| 7.0.58 | 5 / 4 | |
| 7.0.57 | 5 / 4 | |
| 7.0.56 | 5 / 4 | |
| 7.0.55 | 5 / 4 | |
| 7.0.54 | 5 / 4 | |
| 7.0.53 | 5 / 4 | |
| 7.0.52 | 5 / 4 | |
| 7.0.51 | 5 / 4 | |
| 7.0.50 | 5 / 4 | |
| 7.0.49 | 5 / 4 | |
| 7.0.48 | 5 / 4 | |
| 7.0.47 | 5 / 4 | |
| 7.0.46 | 5 / 4 | |
| 7.0.45 | 5 / 4 |
v7.1.0
1 finding
INFO
No provenance attestation
provenance
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.