@aws-cdk/integ-runner
CDK Integration Testing Tool
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:lib/engines/proxy-agent.js | AI (source-diff): Readable compiled TS with inline sourcemap; implements a proxy agent cache, no malicious content. | ai | |
| source-diff | obfuscated-file:lib/engines/cdk-interface.js | AI (source-diff): File contains TypeScript-compiled JS with base64 inline sourcemap — not malicious obfuscation, standard TS build output. | ai | |
| source-diff | obfuscated-file:lib/engines/toolkit-lib.js | AI (source-diff): Legitimate bundled toolkit-lib engine code; long lines from bundler output, not obfuscation. | ai | |
| source-diff | obfuscated-file:lib/unstable-features.js | AI (source-diff): Readable feature-flag registry code; long-line flag from inline sourcemap, not obfuscation. | ai | |
| provenance | publisher-changed | AI (provenance): AWS CDK migrated to GitHub Actions CI publishing with SLSA provenance; consistent with org-wide pipeline change. | ai | |
| phantom-deps | phantom-dep:aws-cdk | AI (phantom-deps): aws-cdk is a peer/runtime dep referenced in config; phantom-dep heuristic false positive. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): Standard subprocess env forwarding in CDK CLI runner; not exfiltration. | ai | |
| phantom-deps | phantom-dep:@aws-cdk/aws-service-spec | AI (phantom-deps): Same-org dep used indirectly; phantom-dep heuristic false positive. | ai | |
| semgrep | semgrep:eval-usage | AI (semgrep): Bundled workerpool requireFoolWebpack pattern; well-known library internals. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): workerpool worker.run() pattern for dynamic function dispatch; stable library behavior. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require in bundled workerpool/CDK plugin loader; expected for this tool. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): CLI integration runner inherently uses child_process to spawn CDK commands. | ai |
Versions (showing 51 of 60)
| Version | Deps | Published |
|---|---|---|
| 2.200.1 | 2 / 45 | |
| 2.200.0 | 2 / 45 | |
| 2.199.0 | 2 / 45 | |
| 2.198.0 | 2 / 45 | |
| 2.197.24 | 2 / 45 | |
| 2.197.23 | 2 / 45 | |
| 2.197.22 | 2 / 45 | |
| 2.197.21 | 2 / 45 | |
| 2.197.20 | 2 / 45 | |
| 2.197.19 | 2 / 45 | |
| 2.197.18 | 2 / 45 | |
| 2.197.17 | 2 / 45 | |
| 2.197.16 | 2 / 45 | |
| 2.197.15 | 2 / 45 | |
| 2.197.14 | 2 / 45 | |
| 2.197.13 | 2 / 44 | |
| 2.197.12 | 2 / 44 | |
| 2.197.11 | 2 / 43 | |
| 2.197.10 | 2 / 43 | |
| 2.197.9 | 2 / 43 | |
| 2.197.8 | 2 / 43 | |
| 2.197.7 | 2 / 43 | |
| 2.197.6 | 2 / 43 | |
| 2.197.5 | 2 / 43 | |
| 2.197.4 | 2 / 43 | |
| 2.197.3 | 2 / 43 | |
| 2.197.2 | 2 / 43 | |
| 2.197.1 | 2 / 43 | |
| 2.197.0 | 2 / 43 | |
| 2.196.1 | 2 / 43 | |
| 2.196.0 | 2 / 43 | |
| 2.195.0 | 2 / 43 | |
| 2.194.2 | 2 / 44 | |
| 2.194.1 | 2 / 44 | |
| 2.194.0 | 2 / 44 | |
| 2.193.5 | 2 / 43 | |
| 2.193.4 | 2 / 43 | |
| 2.193.3 | 2 / 43 | |
| 2.193.2 | 2 / 43 | |
| 2.193.1 | 2 / 43 | |
| 2.193.0 | 2 / 43 | |
| 2.192.2 | 2 / 43 | |
| 2.192.1 | 2 / 43 | |
| 2.192.0 | 2 / 43 | |
| 2.187.3 | 2 / 42 | |
| 2.187.2 | 2 / 42 | |
| 2.187.1 | 2 / 41 | |
| 2.187.0 | 2 / 41 | |
| 2.186.11 | 2 / 41 | |
| 2.186.10 | 2 / 41 | |
| 2.186.9 | 2 / 41 |
v2.197.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.197.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.197.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.197.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.197.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.197.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.197.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.197.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.197.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.197.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.197.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.196.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.196.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.195.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.194.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.194.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.194.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.193.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.193.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.193.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.193.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.193.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.193.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.192.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.192.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.192.0
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (aws-cdk-team) on 2025-11-06, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.