← Home

@cdklabs/cdk-cicd-wrapper

This repository contains the infrastructure as code to wrap your AWS CDK project with CI/CD around it.

7
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

cdklabs-automationaws-cdk-teamamzn-oss

Keywords

awsaws-cdkawscdkci-cdci-cd-bootclivanilla-pipeline

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:api-obfuscation-reflect AI (semgrep): Standard Proxy trap pattern in CDK pipeline code; not obfuscation. ai
dependencies unvetted-dep:@cloudcomponents/cdk-pull-request-check AI (dependencies): Bundled CDK construct dependency; no advisory signals, stable usage in this package. ai
dependencies unvetted-dep:@cloudcomponents/cdk-pull-request-approval-rule AI (dependencies): Bundled CDK construct dependency; no advisory signals, stable usage in this package. ai

Versions (showing 7 of 7)

Version Deps Published
0.3.7 3 / 27
0.3.6 3 / 27
0.3.5 3 / 27
0.3.4 3 / 27
0.3.3 3 / 27
0.3.2 3 / 27
0.3.1 3 / 27

v0.3.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.