@aws-amplify/notifications
Notifications category of aws-amplify
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | dormant-publish | AI (publish-pattern): AWS Amplify monorepo restructuring explains dormancy; trusted publisher with long track record. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): aws-amplify-data-runtime is an AWS org account; consistent with internal team restructuring. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): tslib and @aws-sdk/types are well-established AWS/TS ecosystem packages, not suspicious additions. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Large file count consistent with Amplify monorepo reorganization; no obfuscation or malware indicators. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): aws-amplify-ops is the org-level publisher; individual maintainer changes are routine for this large AWS-managed package and do not indicate a takeover. | ai | |
| provenance | no-provenance | AI (provenance): AWS Amplify packages consistently lack Sigstore provenance; this is a known gap for the org, not a per-version risk signal. | ai | |
| bogus-package | bogus-package | AI (bogus-package): AWS Amplify monorepo packages consistently publish at high semver versions in lockstep, have minimal READMEs, no keywords, and stub entry points. These are structural patterns of the Amplify release pipeline, not spam indicators. | ai |
Versions (showing 51 of 114)
| Version | Deps | Published |
|---|---|---|
| 2.0.94 | 3 / 2 | |
| 2.0.93 | 3 / 2 | |
| 2.0.92 | 3 / 2 | |
| 2.0.91 | 3 / 2 | |
| 2.0.90 | 3 / 2 | |
| 2.0.89 | 3 / 2 | |
| 2.0.88 | 3 / 2 | |
| 2.0.87 | 3 / 2 | |
| 2.0.86 | 3 / 2 | |
| 2.0.85 | 3 / 2 | |
| 2.0.84 | 3 / 2 | |
| 2.0.83 | 3 / 2 | |
| 2.0.82 | 3 / 2 | |
| 2.0.81 | 3 / 2 | |
| 2.0.80 | 3 / 3 | |
| 2.0.79 | 3 / 3 | |
| 2.0.78 | 3 / 3 | |
| 2.0.77 | 3 / 3 | |
| 2.0.76 | 3 / 3 | |
| 2.0.75 | 3 / 3 | |
| 2.0.74 | 3 / 3 | |
| 2.0.73 | 3 / 3 | |
| 2.0.72 | 3 / 3 | |
| 2.0.71 | 3 / 3 | |
| 2.0.70 | 3 / 3 | |
| 2.0.69 | 3 / 3 | |
| 2.0.68 | 3 / 3 | |
| 2.0.67 | 2 / 3 | |
| 2.0.66 | 2 / 3 | |
| 2.0.65 | 2 / 3 | |
| 2.0.64 | 2 / 3 | |
| 2.0.63 | 2 / 3 | |
| 2.0.62 | 2 / 3 | |
| 2.0.61 | 2 / 3 | |
| 2.0.60 | 2 / 3 | |
| 2.0.59 | 2 / 3 | |
| 2.0.58 | 2 / 3 | |
| 2.0.57 | 2 / 3 | |
| 2.0.56 | 2 / 3 | |
| 2.0.55 | 2 / 3 | |
| 2.0.54 | 2 / 3 | |
| 2.0.53 | 2 / 3 | |
| 2.0.52 | 2 / 3 | |
| 2.0.51 | 2 / 3 | |
| 2.0.50 | 2 / 3 | |
| 2.0.49 | 2 / 3 | |
| 2.0.48 | 2 / 3 | |
| 2.0.47 | 2 / 3 | |
| 2.0.46 | 2 / 3 | |
| 2.0.45 | 2 / 3 | |
| 2.0.44 | 2 / 3 |
v2.0.93
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.92
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.91
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.90
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.89
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.88
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.87
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.86
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.85
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.84
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.83
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.82
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.81
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.80
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.79
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.78
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.77
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.76
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.75
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.74
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.73
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.72
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.71
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.70
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.69
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.68
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.67
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.66
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.65
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.64
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.63
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.62
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.61
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.60
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.59
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.58
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.57
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.56
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.55
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.54
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.53
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.52
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.51
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.50
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.49
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.48
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.47
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.46
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.45
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.44
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.