@cdklabs/cdk-ecs-codedeploy
CDK Constructs for performing ECS Deployments with CodeDeploy
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:child-process-import | AI (semgrep): child_process used in code-bundling helper; expected for CDK construct tooling. | ai | |
| dependencies | unvetted-dep:@aws-sdk/client-codedeploy | AI (dependencies): AWS SDK dependency is core to this ECS CodeDeploy construct's functionality. | ai |
Versions (showing 5 of 5)
| Version | Deps | Published |
|---|---|---|
| 0.0.439 | 2 / 33 | |
| 0.0.438 | 2 / 33 | |
| 0.0.437 | 2 / 33 | |
| 0.0.436 | 2 / 33 | |
| 0.0.435 | 2 / 33 |
v0.0.438
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.437
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.436
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.435
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.