← Home

@aws-amplify/api-graphql

Api-graphql category of aws-amplify

100
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

amzn-ossaws-amplify-opsamplify-studio-uibuilderamplify-codegenamplify-data-dev-npmaws-amplify-data-runtime

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern dormant-publish AI (publish-pattern): Major version gap (v3→v4) explains dormancy; aws-amplify-ops is a well-established publisher with 4000+ approved packages. ai
phantom-deps phantom-dep:@aws-sdk/types AI (phantom-deps): Framework-scoped type package; stable false positive for AWS Amplify packages. ai
source-diff source-size-tripled AI (source-diff): 6x size increase is expected for a major version rewrite adding new providers and ESM/CJS dual builds. ai
source-diff large-new-source-files AI (source-diff): Major version rewrite accounts for 163 new source files; consistent with v3→v4 restructuring of AWS Amplify GraphQL API. ai
provenance missing-githead AI (provenance): AWS Amplify is a large AWS org; missing gitHead is consistent with a CI/CD pipeline change rather than a compromise signal, especially with no other corroborating indicators. ai
phantom-deps phantom-dep:@types/zen-observable AI (phantom-deps): Framework-scoped type definition loaded by TypeScript convention; stable false positive for this package. ai
dependencies unvetted-dep:zen-observable AI (dependencies): zen-observable is a stable, widely-used RxJS dependency; acceptable for AWS Amplify's GraphQL API layer. ai
maintainer-change maintainer-added AI (maintainer-change): mattsb42-aws is an AWS-affiliated maintainer; addition is consistent with normal team transitions. ai
publish-pattern new-deps-added AI (publish-pattern): New dependency is @aws-amplify/pubsub, an internal sibling package, not a third-party addition. ai
dependencies unvetted-dep:@aws-amplify/pubsub AI (dependencies): Internal AWS Amplify monorepo dependency; unvetted status is expected for internal packages. ai
dependencies unvetted-dep:zen-observable-ts AI (dependencies): zen-observable-ts is a standard RxJS observable library; unvetted status is expected for ecosystem packages. ai
phantom-deps phantom-dep:uuid AI (phantom-deps): uuid is referenced in config but not directly imported; benign phantom dependency. ai
dependencies unvetted-dep:@aws-amplify/cache AI (dependencies): Internal AWS Amplify monorepo dependency; unvetted status is expected for internal packages. ai
provenance no-provenance AI (provenance): Provenance attestation is not yet standard practice; absence is not a security concern for this package. ai
maintainer-change maintainer-removed AI (maintainer-change): Removal of prior maintainers is normal team transition; no compromise indicators present. ai
bogus-package bogus-package AI (bogus-package): Mass-production pattern reflects AWS monorepo structure; no malicious intent. Missing keywords is cosmetic. ai
dependencies unvetted-dep:@aws-amplify/api-rest AI (dependencies): Sibling package in the AWS Amplify monorepo, published at the same build hash. Consistently co-released; not an independent third-party dependency. ai
dependencies unvetted-peer-dep:@aws-amplify/pubsub AI (dependencies): Peer dependency on internal AWS Amplify package; acceptable for monorepo architecture. ai
dependencies unvetted-dep:@aws-amplify/core AI (dependencies): Internal AWS Amplify monorepo dependency; unvetted status is expected for internal packages. ai

Versions (showing 100 of 132)

Version Deps Published
4.8.7 7 / 0
4.8.6 8 / 0
4.8.5 8 / 0
4.8.4 8 / 0
4.8.3 8 / 0
4.8.2 8 / 0
4.8.1 8 / 0
4.8.0 8 / 0
4.7.22 8 / 0
4.7.21 8 / 0
4.7.20 8 / 0
4.7.19 8 / 0
4.7.18 8 / 0
4.7.17 8 / 0
4.7.16 8 / 0
4.7.15 8 / 3
4.7.14 8 / 3
4.7.13 8 / 3
4.7.12 8 / 3
4.7.11 8 / 3
4.7.10 8 / 3
4.7.9 8 / 3
4.7.8 8 / 3
4.7.7 8 / 3
4.7.6 8 / 3
4.7.5 8 / 3
4.7.4 8 / 3
4.7.3 8 / 3
4.7.2 8 / 3
4.7.1 8 / 3
4.7.0 8 / 3
4.6.7 8 / 3
4.6.6 8 / 3
4.6.5 8 / 3
4.6.4 8 / 3
4.6.3 8 / 3
4.6.2 8 / 3
4.6.1 8 / 3
4.6.0 8 / 3
4.5.1 8 / 3
4.5.0 8 / 3
4.4.3 8 / 3
4.4.2 8 / 3
4.4.1 8 / 3
4.4.0 8 / 3
4.3.3 8 / 3
4.3.2 8 / 3
4.3.1 8 / 3
4.3.0 8 / 3
4.2.1 8 / 3
4.2.0 8 / 3
4.1.15 8 / 3
4.1.14 8 / 3
4.1.13 8 / 3
4.1.12 8 / 3
4.1.11 8 / 3
4.1.10 8 / 3
4.1.9 8 / 3
4.1.8 8 / 3
4.1.7 8 / 3
4.1.6 8 / 3
4.1.5 8 / 3
4.1.4 8 / 3
4.1.3 8 / 3
4.1.2 8 / 3
4.1.1 8 / 3
4.1.0 8 / 3
3.4.27 9 / 2
3.4.26 9 / 2
3.4.25 9 / 2
3.4.24 9 / 2
2.0.0 8 / 1
1.3.3 8 / 1
1.3.2 8 / 1
1.3.1 8 / 1
1.3.0 8 / 1
1.2.30 8 / 1
1.2.29 8 / 1
1.2.28 8 / 1
1.2.27 8 / 1
1.2.26 8 / 1
1.2.25 8 / 1
1.2.24 8 / 1
1.2.23 8 / 1
1.2.22 8 / 1
1.2.21 8 / 1
1.2.20 8 / 1
1.2.19 8 / 1
1.2.18 8 / 1
1.2.17 8 / 1
1.2.16 8 / 1
1.2.15 8 / 1
1.2.14 8 / 1
1.2.13 8 / 1
1.2.12 8 / 1
1.2.11 8 / 1
1.2.10 8 / 1
1.2.9 8 / 1
1.2.8 8 / 1
1.2.7 8 / 1
Showing 100 of 132 Next page →

v4.8.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.8.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.8.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.8.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.8.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.8.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.8.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.7.22

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.7.21

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.7.20

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.7.19

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.7.18

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.7.17

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.7.16

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.7.15

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.7.14

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.7.13

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.7.12

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.7.11

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.7.10

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.7.9

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.7.8

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.7.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.7.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.7.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.7.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.7.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.7.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.7.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.7.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.6.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.6.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.6.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.6.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.6.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.6.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.6.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.6.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.5.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.5.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.4.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.4.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.4.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.4.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.3.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.3.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.3.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.3.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.1.15

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.1.14

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.1.13

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.1.12

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.1.11

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.1.10

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.1.9

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.1.8

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.1.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.1.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.1.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.1.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.1.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.1.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.1.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.1.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.27

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.26

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.25

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.24

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.