← Home

@aws-amplify/ui

`@aws-amplify/ui` contains low-level logic & styles for stand-alone usage or re-use in framework-specific implementations.

51
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

amzn-ossaws-amplify-opsamplify-studio-uibuilderamplify-codegenamplify-data-dev-npmaws-amplify-data-runtime

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/esm/machines/authenticator/actors/resetPassword.mjs AI (source-diff): Rollup+terser minified output of xstate state machines for auth flows. Legitimate build artifact, not obfuscation. ai
source-diff obfuscated-file:dist/esm/machines/authenticator/signUp.mjs AI (source-diff): Rollup+terser minified output of xstate state machines for auth flows. Legitimate build artifact, not obfuscation. ai
source-diff large-new-source-files AI (source-diff): Large official AWS Amplify UI package with many modules; new files are expected across versions. ai
maintainer-change maintainer-added AI (maintainer-change): aws-amplify-docs-eng-ops is an AWS organizational account; addition is consistent with AWS team restructuring during major version release. ai
maintainer-change maintainer-removed AI (maintainer-change): mlabieniec removal alongside aws-amplify-ops as publisher reflects normal AWS team rotation, not a hostile takeover. ai
publish-pattern new-deps-added AI (publish-pattern): csstype is a well-known, widely-used CSS type definitions package; legitimate addition for a UI library major version. ai
phantom-deps phantom-dep:tslib AI (phantom-deps): tslib is declared as a runtime dependency in package.json and is a standard TypeScript helper; phantom-dep flag is a false positive here. ai
bogus-package bogus-package AI (bogus-package): Signals reflect AWS Amplify monorepo publishing patterns (many templated packages, minimal README for sub-packages). Not spam. ai
typosquat typosquat.levenshtein:uuid AI (typosquat): @aws-amplify/ui is an official AWS scoped package, not a typosquat of uuid. Levenshtein distance match is a false positive for scoped packages. ai
typosquat typosquat.levenshtein:pg AI (typosquat): @aws-amplify/ui is an official AWS scoped package, not a typosquat of pg. False positive. ai
typosquat typosquat.levenshtein:qs AI (typosquat): @aws-amplify/ui is an official AWS scoped package, not a typosquat of qs. False positive. ai
typosquat typosquat.levenshtein:joi AI (typosquat): @aws-amplify/ui is an official AWS scoped package, not a typosquat of joi. False positive. ai
typosquat typosquat.levenshtein:yup AI (typosquat): @aws-amplify/ui is an official AWS scoped package, not a typosquat of yup. False positive. ai

Versions (showing 51 of 190)

Show 172 prereleases View all versions
Version Deps Published
6.15.4 3 / 8
6.15.3 3 / 8
6.15.2 3 / 8
6.15.1 3 / 8
6.15.0 3 / 8
6.14.0 3 / 8
6.13.0 3 / 7
6.12.1 3 / 7
6.12.0 3 / 7
6.11.0 3 / 7
6.10.3 3 / 7
6.10.2 3 / 7
6.10.1 3 / 7
6.10.0 3 / 7
6.9.1 3 / 7
6.9.0 3 / 7
6.8.2 3 / 7
6.8.1 3 / 7
6.8.0 3 / 7
6.7.2 3 / 7
6.7.1 3 / 7
6.7.0 3 / 7
6.6.6 3 / 7
6.6.5 3 / 7
6.6.4 3 / 7
6.6.3 3 / 7
6.6.2 3 / 7
6.6.1 3 / 7
6.6.0 3 / 7
6.5.0 3 / 7
6.4.1 3 / 7
6.4.0 3 / 7
6.3.0 3 / 7
6.2.0 3 / 7
6.1.0 3 / 7
6.0.17 4 / 6
6.0.16 4 / 6
6.0.15 4 / 6
6.0.14 4 / 6
6.0.13 4 / 6
6.0.12 4 / 6
6.0.11 4 / 6
6.0.10 4 / 6
6.0.9 4 / 6
6.0.8 4 / 6
6.0.7 4 / 6
6.0.6 4 / 6
6.0.5 4 / 6
6.0.4 4 / 6
6.0.3 4 / 5
6.0.2 4 / 5

v6.15.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.15.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.15.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.15.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.14.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.13.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.12.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.12.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.11.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.10.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.10.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.10.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.10.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.9.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.9.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.8.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.8.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.8.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.7.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.7.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.6.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.6.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.6.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.6.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.6.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.6.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.4.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.0.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.0.16

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.0.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.0.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.0.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.0.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.0.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.0.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.0.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.0.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.0.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.0.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.0.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.0.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.