@aws-amplify/ui
`@aws-amplify/ui` contains low-level logic & styles for stand-alone usage or re-use in framework-specific implementations.
100
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
amzn-ossaws-amplify-opsamplify-studio-uibuilderamplify-codegenamplify-data-dev-npmaws-amplify-data-runtime
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/esm/machines/authenticator/actors/resetPassword.mjs | AI (source-diff): Rollup+terser minified output of xstate state machines for auth flows. Legitimate build artifact, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/esm/machines/authenticator/signUp.mjs | AI (source-diff): Rollup+terser minified output of xstate state machines for auth flows. Legitimate build artifact, not obfuscation. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Large official AWS Amplify UI package with many modules; new files are expected across versions. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): aws-amplify-docs-eng-ops is an AWS organizational account; addition is consistent with AWS team restructuring during major version release. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): mlabieniec removal alongside aws-amplify-ops as publisher reflects normal AWS team rotation, not a hostile takeover. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): csstype is a well-known, widely-used CSS type definitions package; legitimate addition for a UI library major version. | ai | |
| phantom-deps | phantom-dep:tslib | AI (phantom-deps): tslib is declared as a runtime dependency in package.json and is a standard TypeScript helper; phantom-dep flag is a false positive here. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Signals reflect AWS Amplify monorepo publishing patterns (many templated packages, minimal README for sub-packages). Not spam. | ai | |
| typosquat | typosquat.levenshtein:uuid | AI (typosquat): @aws-amplify/ui is an official AWS scoped package, not a typosquat of uuid. Levenshtein distance match is a false positive for scoped packages. | ai | |
| typosquat | typosquat.levenshtein:pg | AI (typosquat): @aws-amplify/ui is an official AWS scoped package, not a typosquat of pg. False positive. | ai | |
| typosquat | typosquat.levenshtein:qs | AI (typosquat): @aws-amplify/ui is an official AWS scoped package, not a typosquat of qs. False positive. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): @aws-amplify/ui is an official AWS scoped package, not a typosquat of joi. False positive. | ai | |
| typosquat | typosquat.levenshtein:yup | AI (typosquat): @aws-amplify/ui is an official AWS scoped package, not a typosquat of yup. False positive. | ai |
Versions (showing 100 of 363)
| Version | Deps | Published |
|---|---|---|
| 6.15.5 | 3 / 8 | |
| 6.15.4 | 3 / 8 | |
| 6.15.3 | 3 / 8 | |
| 6.15.2 | 3 / 8 | |
| 6.15.1 | 3 / 8 | |
| 6.15.0 | 3 / 8 | |
| 6.14.0 | 3 / 8 | |
| 6.13.0 | 3 / 7 | |
| 6.12.1 | 3 / 7 | |
| 6.12.0 | 3 / 7 | |
| 6.11.0 | 3 / 7 | |
| 6.10.3 | 3 / 7 | |
| 6.10.2 | 3 / 7 | |
| 6.10.1 | 3 / 7 | |
| 6.10.0 | 3 / 7 | |
| 6.9.1 | 3 / 7 | |
| 6.9.0 | 3 / 7 | |
| 6.8.2 | 3 / 7 | |
| 6.8.1 | 3 / 7 | |
| 6.8.0 | 3 / 7 | |
| 6.7.2 | 3 / 7 | |
| 6.7.1 | 3 / 7 | |
| 6.7.0 | 3 / 7 | |
| 6.6.6 | 3 / 7 | |
| 6.6.5 | 3 / 7 | |
| 6.6.4 | 3 / 7 | |
| 6.6.3 | 3 / 7 | |
| 6.6.2 | 3 / 7 | |
| 6.6.1 | 3 / 7 | |
| 6.6.0 | 3 / 7 | |
| 6.5.0 | 3 / 7 | |
| 6.4.1 | 3 / 7 | |
| 6.4.0 | 3 / 7 | |
| 6.3.0 | 3 / 7 | |
| 6.2.0 | 3 / 7 | |
| 6.1.0 | 3 / 7 | |
| 6.0.17 | 4 / 6 | |
| 6.0.16 | 4 / 6 | |
| 6.0.15 | 4 / 6 | |
| 6.0.14 | 4 / 6 | |
| 6.0.13 | 4 / 6 | |
| 6.0.12 | 4 / 6 | |
| 6.0.11 | 4 / 6 | |
| 6.0.10 | 4 / 6 | |
| 6.0.9 | 4 / 6 | |
| 6.0.8 | 4 / 6 | |
| 6.0.7 | 4 / 6 | |
| 6.0.6 | 4 / 6 | |
| 6.0.5 | 4 / 6 | |
| 6.0.4 | 4 / 6 | |
| 6.0.3 | 4 / 5 | |
| 6.0.2 | 4 / 5 | |
| 6.0.1 | 4 / 5 | |
| 6.0.0 | 4 / 5 | |
| 5.9.0 | 4 / 18 | |
| 5.8.1 | 4 / 18 | |
| 5.8.0 | 4 / 18 | |
| 5.7.2 | 4 / 18 | |
| 5.7.1 | 4 / 18 | |
| 5.7.0 | 4 / 18 | |
| 5.6.9 | 4 / 18 | |
| 5.6.8 | 4 / 18 | |
| 5.6.7 | 4 / 18 | |
| 5.6.6 | 4 / 18 | |
| 5.6.5 | 4 / 18 | |
| 5.6.4 | 4 / 18 | |
| 5.6.3 | 4 / 18 | |
| 5.6.2 | 4 / 18 | |
| 5.6.1 | 4 / 18 | |
| 5.6.0 | 4 / 18 | |
| 5.5.10 | 4 / 18 | |
| 5.5.9 | 4 / 18 | |
| 5.5.8 | 4 / 18 | |
| 5.5.7 | 4 / 18 | |
| 5.5.6 | 4 / 19 | |
| 5.5.5 | 4 / 20 | |
| 5.5.4 | 4 / 20 | |
| 5.5.3 | 4 / 20 | |
| 5.5.2 | 4 / 19 | |
| 5.5.1 | 4 / 19 | |
| 5.5.0 | 4 / 19 | |
| 5.4.2 | 4 / 19 | |
| 5.4.1 | 4 / 19 | |
| 5.4.0 | 4 / 19 | |
| 5.3.1 | 4 / 19 | |
| 5.3.0 | 4 / 19 | |
| 5.2.0 | 4 / 19 | |
| 5.1.1 | 4 / 19 | |
| 5.1.0 | 4 / 19 | |
| 5.0.0 | 3 / 18 | |
| 4.1.1 | 3 / 18 | |
| 4.1.0 | 3 / 18 | |
| 4.0.1 | 3 / 18 | |
| 4.0.0 | 3 / 18 | |
| 3.14.0 | 4 / 18 | |
| 3.13.4 | 4 / 18 | |
| 3.13.3 | 4 / 18 | |
| 3.13.2 | 4 / 18 | |
| 3.13.1 | 4 / 18 | |
| 3.13.0 | 4 / 18 |
Showing 100 of 363
Next page →
v6.15.5
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.