@cdklabs/cdk-ssm-documents
This library provides a code-based utility for implementing SSM Documents. The SSM Document objects can be used to print YAML/JSON documents and to mimic document processing locally.
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:node_modules/@aws-sdk/xml-builder/node_modules/fast-xml-parser/lib/fxp.cjs | AI (source-diff): Minified bundled dependency output, not obfuscated malicious code. | ai | |
| vendored-integrity | unresolved-vendored-tree:node_modules/synchronized-promise | AI (vendored-integrity): Declared bundled dependency; unindexed version, not implant. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/client-iam | AI (phantom-deps): Framework-scoped AWS SDK client, bundled by design. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/client-sns | AI (phantom-deps): Framework-scoped AWS SDK client, bundled by design. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/client-sqs | AI (phantom-deps): Framework-scoped AWS SDK client, bundled by design. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/client-ssm | AI (phantom-deps): Framework-scoped AWS SDK client, bundled by design. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/client-lambda | AI (phantom-deps): Framework-scoped AWS SDK client, bundled by design. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/client-cloudwatch | AI (phantom-deps): Framework-scoped AWS SDK client, bundled by design. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/client-cloudformation | AI (phantom-deps): Framework-scoped AWS SDK client, bundled by design. | ai | |
| vendored-integrity | unresolved-vendored-tree:node_modules/node-addon-api | AI (vendored-integrity): Transitive dep of deasync; version mismatch not evidence of tampering. | ai | |
| vendored-integrity | unresolved-vendored-tree:node_modules/deasync | AI (vendored-integrity): Declared bundled dependency; unindexed version, not implant. | ai | |
| vendored-integrity | unresolved-vendored-tree:node_modules/fflate | AI (vendored-integrity): Transitive dep; matches claimed manifest identity. | ai | |
| vendored-integrity | unresolved-vendored-tree:node_modules/jsep | AI (vendored-integrity): Transitive dep of jsonpath-plus; matches claimed identity. | ai | |
| vendored-integrity | unresolved-vendored-tree:node_modules/python-shell | AI (vendored-integrity): Declared bundled dependency; unindexed version, not implant. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/client-s3 | AI (phantom-deps): Framework-scoped AWS SDK client, bundled by design. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/client-ec2 | AI (phantom-deps): Framework-scoped AWS SDK client, bundled by design. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Package bundles multiple @aws-sdk clients; large file counts are expected when SDK deps are added or updated. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Standard base64 decode utility; no obfuscation or exfiltration context. | ai | |
| dependencies | unvetted-dep:python-shell | AI (dependencies): python-shell is a legitimate dependency for running Python scripts; consistent with SSM document simulation needs. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamically loads @aws-sdk/client-* by service name; benign plugin-loader pattern for AWS SDK clients. | ai | |
| npm-metadata | bundled-binaries | AI (npm-metadata): Binaries are deasync prebuilt native modules for multiple platforms; well-known package, consistent with bundled deps list. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): Used in environment.js for SSM document simulation; expected for this package's purpose. | ai | |
| dependencies | unvetted-dep:synchronized-promise | AI (dependencies): synchronized-promise is a utility for sync execution; consistent with deasync usage pattern in this package. | ai |
Versions (showing 10 of 10)
| Version | Deps | Published |
|---|---|---|
| 0.0.71 | 14 / 26 | |
| 0.0.69 | 14 / 26 | |
| 0.0.68 | 14 / 26 | |
| 0.0.67 | 14 / 26 | |
| 0.0.66 | 14 / 26 | |
| 0.0.65 | 14 / 26 | |
| 0.0.64 | 14 / 26 | |
| 0.0.63 | 14 / 26 | |
| 0.0.61 | 14 / 26 | |
| 0.0.58 | 14 / 26 |
v0.0.71
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.69
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.68
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.67
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.