@aws-amplify/auth
Auth category of aws-amplify
51
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
amzn-ossaws-amplify-opsamplify-studio-uibuilderamplify-codegenamplify-data-dev-npmaws-amplify-data-runtime
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@aws-amplify/common | AI (dependencies): @aws-amplify/common is a sibling package in the same AWS Amplify monorepo; expected dependency for all versions of this package. | ai | |
| dependencies | unvetted-dep:aws-sdk | AI (dependencies): aws-sdk is a core AWS dependency expected for @aws-amplify/auth; stable and legitimate for this package across all versions. | ai | |
| source-diff | source-size-dropped | AI (source-diff): Pre-release version of monorepo package; source size variations are expected and benign in this context. | ai | |
| dependencies | unvetted-peer-dep:react-native | AI (dependencies): react-native is a legitimate peer dependency for auth library; expected for this package. | ai | |
| source-diff | encoded-string-file:dist/aws-amplify-auth.min.js | AI (source-diff): Minified bundle for a major AWS library; long encoded strings are standard minification artifacts. Sample confirms safe-buffer/process polyfill code, not malicious payloads. | ai | |
| dependencies | unvetted-dep:@aws-amplify/cache | AI (dependencies): Internal AWS Amplify monorepo dependency; same org scope and legitimate internal coupling. | ai | |
| bogus-package | bogus-package | AI (bogus-package): AWS Amplify publishes many packages with templated names by design; this is a known false positive for the aws-amplify org scope. | ai | |
| semgrep | semgrep:toplevel-fetch | AI (semgrep): Fetch call is part of Cognito auth flow (launchUri handler); legitimate use, not data exfiltration. | ai | |
| phantom-deps | phantom-dep:@aws-amplify/cache | AI (phantom-deps): Expected monorepo internal dependency pattern; same org scope. | ai | |
| provenance | no-provenance | AI (provenance): Provenance not yet enabled; not a security disqualifier for established AWS package. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): New maintainers (amzn-oss, jamesiri, jpeddicord) reflect AWS organizational changes within the official Amplify project, not a takeover. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): crypto-js is established library appropriate for auth package; no supply-chain risk. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Removal of richardzcode is part of legitimate maintainer transition within AWS Amplify; combined with new AWS maintainers, indicates organizational restructuring, not compromise. | ai | |
| provenance | publisher-changed | AI (provenance): Documented AWS organizational transition in 2020; legitimate maintainer handoff. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Base64 decoding is legitimate Cognito auth protocol handling, not obfuscation. | ai | |
| source-diff | large-new-source-files | AI (source-diff): 55 new files reflect normal package evolution; no bundled/injected code indicators. | ai | |
| dependencies | unvetted-dep:@aws-amplify/core | AI (dependencies): Internal AWS Amplify dependency within same organization scope; monorepo pattern. | ai |
Versions (showing 51 of 177)
| Version | Deps | Published |
|---|---|---|
| 6.20.0 | 3 / 3 | |
| 6.19.1 | 3 / 3 | |
| 6.19.0 | 3 / 3 | |
| 6.18.0 | 3 / 3 | |
| 6.17.2 | 3 / 3 | |
| 6.17.1 | 3 / 3 | |
| 6.17.0 | 3 / 3 | |
| 6.16.0 | 3 / 3 | |
| 6.15.1 | 3 / 3 | |
| 6.15.0 | 3 / 3 | |
| 6.14.0 | 3 / 3 | |
| 6.13.3 | 3 / 3 | |
| 6.13.2 | 3 / 3 | |
| 6.13.1 | 3 / 3 | |
| 6.13.0 | 3 / 3 | |
| 6.12.4 | 3 / 4 | |
| 6.12.3 | 3 / 4 | |
| 6.12.2 | 3 / 4 | |
| 6.12.1 | 3 / 4 | |
| 6.12.0 | 3 / 4 | |
| 6.11.6 | 3 / 4 | |
| 6.11.5 | 3 / 4 | |
| 6.11.4 | 3 / 4 | |
| 6.11.3 | 3 / 4 | |
| 6.11.2 | 3 / 4 | |
| 6.11.1 | 3 / 4 | |
| 6.11.0 | 3 / 4 | |
| 6.10.2 | 3 / 4 | |
| 6.10.1 | 3 / 4 | |
| 6.10.0 | 3 / 4 | |
| 6.9.1 | 1 / 4 | |
| 6.9.0 | 1 / 4 | |
| 6.8.3 | 1 / 4 | |
| 6.8.2 | 1 / 4 | |
| 6.8.1 | 1 / 4 | |
| 6.8.0 | 1 / 4 | |
| 6.7.0 | 1 / 4 | |
| 6.6.2 | 1 / 4 | |
| 6.6.1 | 1 / 4 | |
| 6.6.0 | 1 / 4 | |
| 6.5.5 | 1 / 4 | |
| 6.5.4 | 1 / 4 | |
| 6.5.3 | 1 / 4 | |
| 6.5.2 | 1 / 4 | |
| 6.5.1 | 1 / 4 | |
| 6.5.0 | 1 / 4 | |
| 6.4.2 | 1 / 4 | |
| 6.4.1 | 1 / 4 | |
| 6.4.0 | 1 / 4 | |
| 6.3.17 | 1 / 4 | |
| 6.3.16 | 1 / 4 |