← Home

@aws-amplify/auth

Auth category of aws-amplify

100
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

amzn-ossaws-amplify-opsamplify-studio-uibuilderamplify-codegenamplify-data-dev-npmaws-amplify-data-runtime

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@aws-amplify/common AI (dependencies): @aws-amplify/common is a sibling package in the same AWS Amplify monorepo; expected dependency for all versions of this package. ai
dependencies unvetted-dep:aws-sdk AI (dependencies): aws-sdk is a core AWS dependency expected for @aws-amplify/auth; stable and legitimate for this package across all versions. ai
source-diff source-size-dropped AI (source-diff): Pre-release version of monorepo package; source size variations are expected and benign in this context. ai
dependencies unvetted-peer-dep:react-native AI (dependencies): react-native is a legitimate peer dependency for auth library; expected for this package. ai
source-diff encoded-string-file:dist/aws-amplify-auth.min.js AI (source-diff): Minified bundle for a major AWS library; long encoded strings are standard minification artifacts. Sample confirms safe-buffer/process polyfill code, not malicious payloads. ai
dependencies unvetted-dep:@aws-amplify/cache AI (dependencies): Internal AWS Amplify monorepo dependency; same org scope and legitimate internal coupling. ai
bogus-package bogus-package AI (bogus-package): AWS Amplify publishes many packages with templated names by design; this is a known false positive for the aws-amplify org scope. ai
semgrep semgrep:toplevel-fetch AI (semgrep): Fetch call is part of Cognito auth flow (launchUri handler); legitimate use, not data exfiltration. ai
phantom-deps phantom-dep:@aws-amplify/cache AI (phantom-deps): Expected monorepo internal dependency pattern; same org scope. ai
provenance no-provenance AI (provenance): Provenance not yet enabled; not a security disqualifier for established AWS package. ai
maintainer-change maintainer-added AI (maintainer-change): New maintainers (amzn-oss, jamesiri, jpeddicord) reflect AWS organizational changes within the official Amplify project, not a takeover. ai
publish-pattern new-deps-added AI (publish-pattern): crypto-js is established library appropriate for auth package; no supply-chain risk. ai
maintainer-change maintainer-removed AI (maintainer-change): Removal of richardzcode is part of legitimate maintainer transition within AWS Amplify; combined with new AWS maintainers, indicates organizational restructuring, not compromise. ai
provenance publisher-changed AI (provenance): Documented AWS organizational transition in 2020; legitimate maintainer handoff. ai
semgrep semgrep:base64-decode AI (semgrep): Base64 decoding is legitimate Cognito auth protocol handling, not obfuscation. ai
source-diff large-new-source-files AI (source-diff): 55 new files reflect normal package evolution; no bundled/injected code indicators. ai
dependencies unvetted-dep:@aws-amplify/core AI (dependencies): Internal AWS Amplify dependency within same organization scope; monorepo pattern. ai

Versions (showing 100 of 143)

Version Deps Published
6.20.0 3 / 3
6.19.1 3 / 3
6.19.0 3 / 3
6.18.0 3 / 3
6.17.2 3 / 3
6.17.1 3 / 3
6.17.0 3 / 3
6.16.0 3 / 3
6.15.1 3 / 3
6.15.0 3 / 3
6.14.0 3 / 3
6.13.3 3 / 3
6.13.2 3 / 3
6.13.1 3 / 3
6.13.0 3 / 3
6.12.4 3 / 4
6.12.3 3 / 4
6.12.2 3 / 4
6.12.1 3 / 4
6.12.0 3 / 4
6.11.6 3 / 4
6.11.5 3 / 4
6.11.4 3 / 4
6.11.3 3 / 4
6.11.2 3 / 4
6.11.1 3 / 4
6.11.0 3 / 4
6.10.2 3 / 4
6.10.1 3 / 4
6.10.0 3 / 4
6.9.1 1 / 4
6.9.0 1 / 4
6.8.3 1 / 4
6.8.2 1 / 4
6.8.1 1 / 4
6.8.0 1 / 4
6.7.0 1 / 4
6.6.2 1 / 4
6.6.1 1 / 4
6.6.0 1 / 4
6.5.5 1 / 4
6.5.4 1 / 4
6.5.3 1 / 4
6.5.2 1 / 4
6.5.1 1 / 4
6.5.0 1 / 4
6.4.2 1 / 4
6.4.1 1 / 4
6.4.0 1 / 4
6.3.17 1 / 4
6.3.16 1 / 4
6.3.15 1 / 4
6.3.14 1 / 4
6.3.13 1 / 4
6.3.12 1 / 4
6.3.11 1 / 4
6.3.10 1 / 4
6.3.9 1 / 4
6.3.8 1 / 4
6.3.7 1 / 4
6.3.6 1 / 4
6.3.5 1 / 4
6.3.4 1 / 4
6.3.3 1 / 4
6.3.2 1 / 4
6.3.1 1 / 4
6.3.0 1 / 4
6.2.2 1 / 4
5.6.19 5 / 1
5.6.18 5 / 1
5.6.17 5 / 1
5.3.6 3 / 1
4.0.0 4 / 1
3.4.34 4 / 1
3.4.33 4 / 1
3.4.32 4 / 1
3.4.31 4 / 1
3.4.30 4 / 1
3.4.29 4 / 1
3.4.28 4 / 1
3.4.27 4 / 1
3.4.26 4 / 1
3.4.25 4 / 1
3.4.24 4 / 1
3.4.23 4 / 1
3.4.22 4 / 1
3.4.21 4 / 1
3.4.20 4 / 1
3.4.19 4 / 1
3.4.18 4 / 1
3.4.17 4 / 1
3.4.16 4 / 1
3.4.15 4 / 1
3.4.14 4 / 1
3.4.13 4 / 1
3.4.12 4 / 1
3.4.11 4 / 1
3.2.5 4 / 0
3.2.4 4 / 0
3.2.3 4 / 0
Showing 100 of 143 Next page →

v6.20.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.19.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.18.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.17.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.17.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.17.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.16.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.15.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.15.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.14.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.13.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.13.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.13.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.13.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.12.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.12.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.12.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.12.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.12.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.11.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.11.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.11.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.11.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.11.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.11.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.11.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.10.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.10.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.10.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.9.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.9.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.8.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.8.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.8.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.8.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.7.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.6.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.6.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.6.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.5.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.5.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.5.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.5.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.5.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.5.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.4.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.4.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.4.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.3.17

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.3.16

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.3.15

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.3.14

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.3.13

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.3.12

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.3.11

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.3.10

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.3.9

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.3.8

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.3.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.3.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.3.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.3.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.3.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.3.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.3.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.3.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.2.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.6.19

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.6.18

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.6.17

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.0

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: aws-amplify-ops.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.34

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: aws-amplify-ops.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.33

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.31

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: mlabieniec → aws-amplify-ops (on 2021-05-06) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-05-06. This could indicate a legitimate maintainer transition or an account compromise.

v3.4.30

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: mlabieniec → aws-amplify-ops (on 2021-04-15) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-04-15. This could indicate a legitimate maintainer transition or an account compromise.

v3.4.29

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: mlabieniec → aws-amplify-ops (on 2021-03-25) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-03-25. This could indicate a legitimate maintainer transition or an account compromise.

v3.4.28

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: mlabieniec → aws-amplify-ops (on 2021-03-18) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-03-18. This could indicate a legitimate maintainer transition or an account compromise.

v3.4.27

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: mlabieniec → aws-amplify-ops (on 2021-03-12) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-03-12. This could indicate a legitimate maintainer transition or an account compromise.

v3.4.26

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: mlabieniec → aws-amplify-ops (on 2021-03-08) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-03-08. This could indicate a legitimate maintainer transition or an account compromise.

v3.4.25

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: mlabieniec → aws-amplify-ops (on 2021-03-03) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-03-03. This could indicate a legitimate maintainer transition or an account compromise.

v3.4.24

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: mlabieniec → aws-amplify-ops (on 2021-02-25) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-02-25. This could indicate a legitimate maintainer transition or an account compromise.

v3.4.23

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: mlabieniec → aws-amplify-ops (on 2021-02-18) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-02-18. This could indicate a legitimate maintainer transition or an account compromise.

v3.4.22

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: mlabieniec → aws-amplify-ops (on 2021-02-15) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-02-15. This could indicate a legitimate maintainer transition or an account compromise.

v3.4.21

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: mlabieniec → aws-amplify-ops (on 2021-02-09) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-02-09. This could indicate a legitimate maintainer transition or an account compromise.

v3.4.20

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: mlabieniec → aws-amplify-ops (on 2021-02-03) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-02-03. This could indicate a legitimate maintainer transition or an account compromise.

v3.4.19

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: mlabieniec → aws-amplify-ops (on 2021-02-01) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-02-01. This could indicate a legitimate maintainer transition or an account compromise.

v3.4.18

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: mlabieniec → aws-amplify-ops (on 2021-01-29) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-01-29. This could indicate a legitimate maintainer transition or an account compromise.

v3.4.17

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: mlabieniec → aws-amplify-ops (on 2021-01-07) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-01-07. This could indicate a legitimate maintainer transition or an account compromise.

v3.4.16

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.15

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: mlabieniec → aws-amplify-ops (on 2020-12-10) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2020-12-10. This could indicate a legitimate maintainer transition or an account compromise.

v3.4.14

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: mlabieniec → aws-amplify-ops (on 2020-11-30) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2020-11-30. This could indicate a legitimate maintainer transition or an account compromise.

v3.4.13

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: mlabieniec → aws-amplify-ops (on 2020-11-23) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2020-11-23. This could indicate a legitimate maintainer transition or an account compromise.

v3.4.12

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: mlabieniec → aws-amplify-ops (on 2020-11-20) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2020-11-20. This could indicate a legitimate maintainer transition or an account compromise.

v3.4.11

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: mlabieniec → aws-amplify-ops (on 2020-11-13) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2020-11-13. This could indicate a legitimate maintainer transition or an account compromise.

v3.2.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.2.3

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: mlabieniec → aws-amplify-ops (on 2020-04-08) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2020-04-08. This could indicate a legitimate maintainer transition or an account compromise.