← Home

@aws-cdk/integ-runner

CDK Integration Testing Tool

51
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

amzn-ossaws-cdk-team

Keywords

awscdk

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:lib/engines/proxy-agent.js AI (source-diff): Readable compiled TS with inline sourcemap; implements a proxy agent cache, no malicious content. ai
source-diff obfuscated-file:lib/engines/cdk-interface.js AI (source-diff): File contains TypeScript-compiled JS with base64 inline sourcemap — not malicious obfuscation, standard TS build output. ai
source-diff obfuscated-file:lib/engines/toolkit-lib.js AI (source-diff): Legitimate bundled toolkit-lib engine code; long lines from bundler output, not obfuscation. ai
source-diff obfuscated-file:lib/unstable-features.js AI (source-diff): Readable feature-flag registry code; long-line flag from inline sourcemap, not obfuscation. ai
provenance publisher-changed AI (provenance): AWS CDK migrated to GitHub Actions CI publishing with SLSA provenance; consistent with org-wide pipeline change. ai
phantom-deps phantom-dep:aws-cdk AI (phantom-deps): aws-cdk is a peer/runtime dep referenced in config; phantom-dep heuristic false positive. ai
semgrep semgrep:env-spread AI (semgrep): Standard subprocess env forwarding in CDK CLI runner; not exfiltration. ai
phantom-deps phantom-dep:@aws-cdk/aws-service-spec AI (phantom-deps): Same-org dep used indirectly; phantom-dep heuristic false positive. ai
semgrep semgrep:eval-usage AI (semgrep): Bundled workerpool requireFoolWebpack pattern; well-known library internals. ai
semgrep semgrep:new-function-constructor AI (semgrep): workerpool worker.run() pattern for dynamic function dispatch; stable library behavior. ai
semgrep semgrep:dynamic-require AI (semgrep): Dynamic require in bundled workerpool/CDK plugin loader; expected for this tool. ai
semgrep semgrep:child-process-import AI (semgrep): CLI integration runner inherently uses child_process to spawn CDK commands. ai

Versions (showing 51 of 60)

View all versions
Version Deps Published
2.200.1 2 / 45
2.200.0 2 / 45
2.199.0 2 / 45
2.198.0 2 / 45
2.197.24 2 / 45
2.197.23 2 / 45
2.197.22 2 / 45
2.197.21 2 / 45
2.197.20 2 / 45
2.197.19 2 / 45
2.197.18 2 / 45
2.197.17 2 / 45
2.197.16 2 / 45
2.197.15 2 / 45
2.197.14 2 / 45
2.197.13 2 / 44
2.197.12 2 / 44
2.197.11 2 / 43
2.197.10 2 / 43
2.197.9 2 / 43
2.197.8 2 / 43
2.197.7 2 / 43
2.197.6 2 / 43
2.197.5 2 / 43
2.197.4 2 / 43
2.197.3 2 / 43
2.197.2 2 / 43
2.197.1 2 / 43
2.197.0 2 / 43
2.196.1 2 / 43
2.196.0 2 / 43
2.195.0 2 / 43
2.194.2 2 / 44
2.194.1 2 / 44
2.194.0 2 / 44
2.193.5 2 / 43
2.193.4 2 / 43
2.193.3 2 / 43
2.193.2 2 / 43
2.193.1 2 / 43
2.193.0 2 / 43
2.192.2 2 / 43
2.192.1 2 / 43
2.192.0 2 / 43
2.187.3 2 / 42
2.187.2 2 / 42
2.187.1 2 / 41
2.187.0 2 / 41
2.186.11 2 / 41
2.186.10 2 / 41
2.186.9 2 / 41

v2.197.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.197.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.197.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.197.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.197.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.197.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.197.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.197.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.197.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.197.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.197.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.196.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.196.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.195.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.194.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.194.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.194.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.193.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.193.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.193.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.193.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.193.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.193.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.192.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.192.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.192.0

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: aws-cdk-team → GitHub Actions (on 2025-11-06, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (aws-cdk-team) on 2025-11-06, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.