@aws-amplify/datastore
AppSyncLocal support for aws-amplify
51
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
amzn-ossaws-amplify-opsamplify-studio-uibuilderamplify-codegenamplify-data-dev-npmaws-amplify-data-runtime
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:hex-decode | AI (semgrep): PRNG/random bytes utility using hex encoding — cryptographic utility, not obfuscation. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): JWT token payload parsing — standard auth pattern in Amplify DataStore sync processor, not malicious. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New deps (rxjs, ulid, buffer, @aws-amplify/api-graphql) are all legitimate, well-known packages appropriate for a major version update of an AWS Amplify library. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Diff is against v1.0.1; this is a major version jump (1.x→5.x) for an established AWS library. Large file count increase is expected and files are standard build artifacts (source maps, CJS/ESM bundles). | ai | |
| dependencies | unvetted-dep:@aws-amplify/core | AI (dependencies): @aws-amplify/core is a first-party AWS Amplify dependency; its presence in this package is expected and stable across all versions. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Removal of individual maintainers corresponds to AWS Amplify's shift to team-based publishing. Publisher aws-amplify-ops is unchanged and has strong track record. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): AWS Amplify migrated from individual maintainer accounts to team/bot accounts (amplify-*). This is a documented organizational change, not a takeover signal. | ai | |
| dependencies | unvetted-dep:ulid | AI (dependencies): ulid is a legitimate, widely-used ULID generation library with no known malicious history. Its use in an AWS SDK package is appropriate. | ai | |
| phantom-deps | phantom-dep:buffer | AI (phantom-deps): buffer is a Node.js core polyfill commonly declared as a runtime dep for browser bundling without direct imports in source. Standard pattern for SDK packages. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Dormancy is an artifact of comparing against v1.0.1 (the only prior approved version). The package has been actively maintained; this is a major version jump, not a revival of an abandoned package. | ai | |
| source-diff | encoded-string-file:dist/aws-amplify-datastore.min.js | AI (source-diff): Encoded strings in minified dist are cryptographic constants and license headers, not malicious payloads. Standard for compiled AWS libraries. | ai | |
| phantom-deps | phantom-dep:@aws-amplify/pubsub | AI (phantom-deps): Same-org phantom dependency is expected; likely used transitively through other @aws-amplify modules. | ai | |
| dependencies | unvetted-dep:@aws-amplify/pubsub | AI (dependencies): Internal AWS Amplify dependency; acceptable within the ecosystem. | ai | |
| dependencies | unvetted-dep:zen-observable-ts | AI (dependencies): Pinned to 0.8.19; zen-observable-ts is a stable RxJS dependency, acceptable for this package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): AWS Amplify is a large monorepo; mass-produced scoped packages and missing keywords are normal, not spam indicators. | ai | |
| dependencies | unvetted-dep:zen-push | AI (dependencies): zen-push is a legitimate observable utility used in the Apollo/GraphQL ecosystem; appropriate for Amplify DataStore. | ai | |
| dependencies | unvetted-dep:idb | AI (dependencies): Dependency already accepted in prior versions; stable for this package. | ai |
Versions (showing 51 of 112)
| Version | Deps | Published |
|---|---|---|
| 5.1.9 | 7 / 7 | |
| 5.1.8 | 7 / 7 | |
| 5.1.7 | 7 / 7 | |
| 5.1.6 | 7 / 7 | |
| 5.1.5 | 7 / 7 | |
| 5.1.4 | 7 / 7 | |
| 5.1.3 | 7 / 7 | |
| 5.1.2 | 7 / 7 | |
| 5.1.1 | 7 / 7 | |
| 5.1.0 | 7 / 7 | |
| 5.0.89 | 7 / 7 | |
| 5.0.88 | 7 / 7 | |
| 5.0.87 | 7 / 7 | |
| 5.0.86 | 7 / 7 | |
| 5.0.85 | 7 / 7 | |
| 5.0.84 | 7 / 7 | |
| 5.0.83 | 7 / 7 | |
| 5.0.82 | 7 / 8 | |
| 5.0.81 | 7 / 8 | |
| 5.0.80 | 7 / 8 | |
| 5.0.79 | 7 / 8 | |
| 5.0.78 | 7 / 8 | |
| 5.0.77 | 7 / 8 | |
| 5.0.76 | 7 / 8 | |
| 5.0.75 | 7 / 8 | |
| 5.0.74 | 7 / 8 | |
| 5.0.73 | 7 / 8 | |
| 5.0.72 | 7 / 8 | |
| 5.0.71 | 7 / 8 | |
| 5.0.70 | 7 / 8 | |
| 5.0.69 | 6 / 8 | |
| 5.0.68 | 6 / 8 | |
| 5.0.67 | 6 / 8 | |
| 5.0.66 | 6 / 8 | |
| 5.0.65 | 6 / 8 | |
| 5.0.64 | 6 / 8 | |
| 5.0.63 | 6 / 8 | |
| 5.0.62 | 6 / 8 | |
| 5.0.61 | 6 / 8 | |
| 5.0.60 | 6 / 8 | |
| 5.0.59 | 6 / 8 | |
| 5.0.58 | 6 / 8 | |
| 5.0.57 | 6 / 8 | |
| 5.0.56 | 6 / 8 | |
| 5.0.55 | 6 / 8 | |
| 5.0.54 | 6 / 8 | |
| 5.0.53 | 6 / 8 | |
| 5.0.52 | 6 / 8 | |
| 5.0.51 | 6 / 8 | |
| 5.0.50 | 6 / 8 | |
| 5.0.49 | 6 / 8 |
v5.1.9
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.