← Home

@aws-amplify/analytics

Analytics category of aws-amplify

100
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

amzn-ossaws-amplify-opsamplify-studio-uibuilderamplify-codegenamplify-data-dev-npmaws-amplify-data-runtime

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): aws-amplify-ops is a well-established publisher with 566 approved packages; missing gitHead likely reflects a CI/CD pipeline change in this large monorepo, not a supply chain compromise. ai
dependencies unvetted-dep:aws-sdk AI (dependencies): aws-sdk is a core dependency for AWS service integration; expected and legitimate for this analytics package. ai
source-diff source-size-tripled AI (source-diff): 3.6x size increase corresponds to new AWS SDK integrations and analytics features; no injected payloads detected. ai
source-diff large-new-source-files AI (source-diff): 68 new source files reflect normal development activity for a mature package; no evidence of bundled/injected code. ai
provenance publisher-changed AI (provenance): Publisher transition (mlabieniec → aws-amplify-ops) in 2019 reflects AWS's official adoption of Amplify; stable for this package. ai
publish-pattern new-deps-added AI (publish-pattern): New dependencies are all official AWS SDK packages for analytics integrations; legitimate feature expansion, not attack vector. ai
dependencies unvetted-dep:@aws-sdk/client-kinesis-browser AI (dependencies): AWS SDK browser client; legitimate dependency for analytics package. Stable for this package. ai
dependencies unvetted-dep:@aws-amplify/cache AI (dependencies): Internal AWS Amplify monorepo dependency with pinned constraint; stable for this package. ai
dependencies unvetted-dep:@aws-sdk/client-firehose AI (dependencies): Official AWS SDK; appropriate for analytics service integration. ai
dependencies unvetted-dep:@aws-sdk/client-personalize-events AI (dependencies): Official AWS SDK; appropriate for analytics service integration. ai
bogus-package bogus-package AI (bogus-package): Signals are weak for an established scoped package from a known organization; mass production signal applies to different publisher (elorzafe). ai
dependencies unvetted-dep:@aws-sdk/client-kinesis AI (dependencies): Official AWS SDK; appropriate for analytics service integration. ai
provenance no-provenance AI (provenance): Package predates Sigstore adoption; no provenance is expected for established packages from this era. ai
maintainer-change maintainer-added AI (maintainer-change): AWS Amplify maintainer transitions are documented organizational changes; stable for this package. ai
maintainer-change maintainer-removed AI (maintainer-change): Maintainer removal in context of AWS Amplify's scale is expected; no takeover indicators present. ai
dependencies unvetted-dep:@aws-amplify/core AI (dependencies): Internal Amplify dependency from same trusted publisher; unvetted status is expected for monorepo packages. ai
dependencies unvetted-dep:@aws-sdk/client-personalize-events-browser AI (dependencies): Official AWS SDK preview package from Amazon; unvetted status reflects early preview versioning, not a security concern. ai
dependencies unvetted-dep:@aws-sdk/client-pinpoint-browser AI (dependencies): Official AWS SDK preview package from Amazon; unvetted status reflects early preview versioning, not a security concern. ai

Versions (showing 100 of 144)

Version Deps Published
7.0.94 5 / 3
7.0.93 5 / 3
7.0.92 5 / 3
7.0.91 5 / 3
7.0.90 5 / 3
7.0.89 5 / 3
7.0.88 5 / 3
7.0.87 5 / 3
7.0.86 5 / 3
7.0.85 5 / 3
7.0.84 5 / 3
7.0.83 5 / 3
7.0.82 5 / 3
7.0.81 5 / 3
7.0.80 5 / 4
7.0.79 5 / 4
7.0.78 5 / 4
7.0.77 5 / 4
7.0.76 5 / 4
7.0.75 5 / 4
7.0.74 5 / 4
7.0.73 5 / 4
7.0.72 5 / 4
7.0.71 5 / 4
7.0.70 5 / 4
7.0.69 5 / 4
7.0.68 5 / 4
7.0.67 5 / 4
7.0.66 5 / 4
7.0.65 5 / 4
7.0.64 5 / 4
7.0.63 5 / 4
7.0.62 5 / 4
7.0.61 5 / 4
7.0.60 5 / 4
7.0.59 5 / 4
7.0.58 5 / 4
7.0.57 5 / 4
7.0.56 5 / 4
7.0.55 5 / 4
7.0.54 5 / 4
7.0.53 5 / 4
7.0.52 5 / 4
7.0.51 5 / 4
7.0.50 5 / 4
7.0.49 5 / 4
7.0.48 5 / 4
7.0.47 5 / 4
7.0.46 5 / 4
7.0.45 5 / 4
7.0.44 5 / 4
7.0.43 5 / 4
7.0.42 5 / 4
7.0.41 5 / 4
7.0.40 5 / 4
7.0.39 5 / 4
7.0.38 5 / 4
7.0.37 5 / 4
7.0.36 5 / 4
7.0.35 5 / 4
7.0.34 5 / 4
7.0.33 5 / 4
7.0.32 5 / 4
7.0.31 5 / 4
7.0.30 5 / 4
7.0.29 5 / 4
6.5.17 9 / 1
6.5.16 9 / 1
3.3.1 9 / 0
3.3.0 9 / 0
3.2.8 9 / 0
3.2.7 8 / 0
3.2.6 8 / 0
3.2.5 8 / 0
3.2.4 8 / 0
3.2.3 8 / 0
3.2.2 8 / 0
3.2.1 8 / 0
3.2.0 8 / 0
3.1.15 8 / 0
3.1.14 8 / 0
3.1.13 8 / 0
3.1.12 8 / 0
3.1.11 8 / 0
3.1.10 8 / 0
3.1.9 8 / 0
3.1.8 7 / 0
3.1.7 7 / 0
3.1.6 7 / 0
3.1.5 7 / 0
3.1.4 7 / 0
3.1.3 7 / 0
3.1.2 7 / 0
3.1.0 7 / 0
2.2.8 3 / 0
2.2.7 3 / 0
2.2.6 3 / 0
2.2.5 3 / 0
2.2.4 3 / 0
2.2.2 3 / 0
Showing 100 of 144 Next page →

v7.0.93

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.92

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.91

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.90

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.89

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.88

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.87

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.86

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.85

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.84

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.83

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.82

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.81

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.80

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.79

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.78

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.77

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.76

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.75

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.74

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.73

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.72

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.71

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.70

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.69

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.68

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.67

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.66

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.65

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.64

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.63

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.62

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.61

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.60

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.59

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.58

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.57

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.56

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.55

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.54

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.53

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.52

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.51

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.50

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.49

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.48

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.47

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.46

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.45

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.44

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.43

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.42

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.41

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.40

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.39

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.38

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.37

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.36

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.35

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.34

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.33

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.32

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.31

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.30

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.29

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.5.17

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.5.16

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.2.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.2.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1.15

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: aws-amplify-ops.

v3.1.13

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1.12

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.