← Home

@cdktn/provider-aws

4
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

cdktn-teamjsteinichso0k

Keywords

awscdkcdk-terraincdktfcdktnopentofuproviderterraform

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
maintainer-change maintainer-added AI (maintainer-change): jsteinich added alongside existing maintainers; consistent with project team expansion. ai
source-diff obfuscated-file:lib/bedrockagentcore-resource-policy/index.js AI (source-diff): JSII-compiled TypeScript CDK construct; long lines are export lists, not obfuscation. ai
source-diff obfuscated-file:lib/data-aws-ec2-hosts/index.js AI (source-diff): JSII-compiled TypeScript CDK construct; long lines are export lists, not obfuscation. ai
source-diff obfuscated-file:lib/ec2-local-gateway-route-table-virtual-interface-group-association/index.js AI (source-diff): JSII-compiled TypeScript CDK construct; long lines are export lists, not obfuscation. ai
source-diff obfuscated-file:lib/ec2-local-gateway-route-table/index.js AI (source-diff): JSII-compiled TypeScript CDK construct; long lines are export lists, not obfuscation. ai
source-diff obfuscated-file:lib/kinesis-account-settings/index.js AI (source-diff): JSII-compiled TypeScript CDK construct; long lines are export lists, not obfuscation. ai
source-diff obfuscated-file:lib/observabilityadmin-telemetry-rule-for-organization/index.js AI (source-diff): JSII-compiled TypeScript CDK construct; long lines are export lists, not obfuscation. ai
source-diff obfuscated-file:lib/pinpointsmsvoicev2-event-destination/index.js AI (source-diff): JSII-compiled TypeScript CDK construct; long lines are export lists, not obfuscation. ai
source-diff obfuscated-file:lib/s3control-multi-region-access-point-routes/index.js AI (source-diff): JSII-compiled TypeScript CDK construct; long lines are export lists, not obfuscation. ai
source-diff obfuscated-file:lib/securityhub-automation-rule-v2/index.js AI (source-diff): JSII-compiled TypeScript CDK construct; long lines are export lists, not obfuscation. ai
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI/CD with SLSA provenance and OIDC trusted publisher; legitimate automation change. ai
source-diff obfuscated-file:lib/bedrockagentcore-harness/index.js AI (source-diff): JSII-compiled TypeScript CDK construct; long lines are export lists, not obfuscation. ai
source-diff obfuscated-file:lib/bedrockagentcore-online-evaluation-config/index.js AI (source-diff): JSII-compiled TypeScript CDK construct; long lines are export lists, not obfuscation. ai
source-diff obfuscated-file:lib/bedrockagentcore-policy-engine/index.js AI (source-diff): JSII-compiled TypeScript CDK construct; long lines are export lists, not obfuscation. ai
source-diff obfuscated-file:lib/data-aws-glue-catalog/index.js AI (source-diff): JSII-compiled TypeScript output; long lines are export declarations, not obfuscation. Stable pattern for this package. ai
source-diff obfuscated-file:lib/glue-catalog/index.js AI (source-diff): JSII-compiled TypeScript output; long lines are export declarations, not obfuscation. Stable pattern for this package. ai
source-diff obfuscated-file:lib/observabilityadmin-telemetry-evaluation-for-organization/index.js AI (source-diff): JSII-compiled TypeScript output; long lines are export declarations, not obfuscation. Stable pattern for this package. ai
source-diff obfuscated-file:lib/observabilityadmin-telemetry-evaluation/index.js AI (source-diff): JSII-compiled TypeScript output; long lines are export declarations, not obfuscation. Stable pattern for this package. ai
source-diff obfuscated-file:lib/observabilityadmin-telemetry-rule/index.js AI (source-diff): JSII-compiled TypeScript output; long lines are export declarations, not obfuscation. Stable pattern for this package. ai
source-diff obfuscated-file:lib/outposts-capacity-task/index.js AI (source-diff): JSII-compiled TypeScript output; long lines are export declarations, not obfuscation. Stable pattern for this package. ai
source-diff obfuscated-file:lib/redshift-namespace-registration/index.js AI (source-diff): JSII-compiled TypeScript output; long lines are export declarations, not obfuscation. Stable pattern for this package. ai
source-diff obfuscated-file:lib/securityhub-aggregator-v2/index.js AI (source-diff): JSII-compiled TypeScript output; long lines are export declarations, not obfuscation. Stable pattern for this package. ai
source-diff obfuscated-file:lib/securityhub-connector-v2/index.js AI (source-diff): JSII-compiled TypeScript output; long lines are export declarations, not obfuscation. Stable pattern for this package. ai
source-diff obfuscated-file:lib/arczonalshift-zonal-autoshift-configuration/index.js AI (source-diff): JSII-compiled TypeScript output; long lines are export declarations, not obfuscation. Stable pattern for this package. ai

Versions (showing 4 of 4)

Version Deps Published
24.5.0 0 / 18
24.4.0 0 / 18
24.1.0 0 / 18
23.10.0 0 / 18

v24.5.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v24.4.0

14 findings
HIGH Publisher changed: cdktn-team → GitHub Actions (on 2026-06-04) provenance

This version was published by a different npm account than previous versions on 2026-06-04. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: lib/bedrockagentcore-harness/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/bedrockagentcore-online-evaluation-config/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/bedrockagentcore-policy-engine/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/bedrockagentcore-resource-policy/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/data-aws-ec2-hosts/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/ec2-local-gateway-route-table-virtual-interface-group-association/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/ec2-local-gateway-route-table/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/kinesis-account-settings/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/observabilityadmin-telemetry-rule-for-organization/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/pinpointsmsvoicev2-event-destination/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/s3control-multi-region-access-point-routes/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/securityhub-automation-rule-v2/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v24.1.0

11 findings
HIGH New obfuscated file: lib/arczonalshift-zonal-autoshift-configuration/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/data-aws-glue-catalog/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/glue-catalog/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/observabilityadmin-telemetry-evaluation-for-organization/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/observabilityadmin-telemetry-evaluation/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/observabilityadmin-telemetry-rule/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/outposts-capacity-task/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/redshift-namespace-registration/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/securityhub-aggregator-v2/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/securityhub-connector-v2/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v23.10.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.