← Home

@cdktn/provider-databricks

Prebuilt databricks Provider for CDK Terrain (cdktn)

4
Versions
MPL-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

cdktn-teamjsteinichso0k

Keywords

cdkcdk-terraincdktfcdktndatabricksopentofuproviderterraform

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:lib/account-network-policy/index-structs/structs0.js AI (source-diff): Long lines are TypeScript compiler output (var _a, _b, _c...) for large jsii struct files, not obfuscation. ai
source-diff obfuscated-file:lib/data-databricks-account-network-policies/index-structs/structs0.js AI (source-diff): Same pattern: TypeScript compiler output for large jsii struct files. ai
source-diff obfuscated-file:lib/data-databricks-account-network-policy/index-structs/structs0.js AI (source-diff): Same pattern: TypeScript compiler output for large jsii struct files. ai
source-diff obfuscated-file:lib/account-network-policy/index-structs/structs400.js AI (source-diff): Readable legitimate CDK construct code; long lines from TypeScript compiler variable declarations. ai
source-diff obfuscated-file:lib/data-databricks-account-network-policies/index-structs/structs400.js AI (source-diff): Readable legitimate CDK construct code; long lines from TypeScript compiler variable declarations. ai
source-diff obfuscated-file:lib/data-databricks-account-network-policy/index-structs/structs400.js AI (source-diff): Readable legitimate CDK construct code; long lines from TypeScript compiler variable declarations. ai
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI/CD with SLSA provenance attestation is a legitimate and improved supply chain practice. ai
source-diff obfuscated-file:lib/data-databricks-supervisor-agent-tools/index.js AI (source-diff): jsii-compiled TypeScript output; readable CDK provider code. ai
source-diff obfuscated-file:lib/data-databricks-supervisor-agent/index.js AI (source-diff): jsii-compiled TypeScript output; readable CDK provider code. ai
source-diff obfuscated-file:lib/data-databricks-supervisor-agents/index.js AI (source-diff): jsii-compiled TypeScript output; readable CDK provider code. ai
source-diff obfuscated-file:lib/disaster-recovery-failover-group/index.js AI (source-diff): jsii-compiled TypeScript output; readable CDK provider code. ai
source-diff obfuscated-file:lib/data-databricks-disaster-recovery-failover-group/index.js AI (source-diff): jsii-compiled TypeScript output; long lines are export declarations, not obfuscation. Stable pattern for this package. ai
source-diff obfuscated-file:lib/secret-uc/index.js AI (source-diff): jsii-compiled TypeScript output; readable CDK provider code. ai
source-diff obfuscated-file:lib/supervisor-agent-tool/index.js AI (source-diff): jsii-compiled TypeScript output; readable CDK provider code. ai
source-diff obfuscated-file:lib/supervisor-agent/index.js AI (source-diff): jsii-compiled TypeScript output; readable CDK provider code. ai
source-diff obfuscated-file:lib/disaster-recovery-stable-url/index.js AI (source-diff): jsii-compiled TypeScript output; readable CDK provider code. ai
source-diff obfuscated-file:lib/data-databricks-disaster-recovery-failover-groups/index.js AI (source-diff): jsii-compiled TypeScript output; same pattern as other provider resource files. ai
source-diff obfuscated-file:lib/data-databricks-disaster-recovery-stable-url/index.js AI (source-diff): jsii-compiled TypeScript output; readable CDK provider code. ai
source-diff obfuscated-file:lib/data-databricks-disaster-recovery-stable-urls/index.js AI (source-diff): jsii-compiled TypeScript output; readable CDK provider code. ai
source-diff obfuscated-file:lib/data-databricks-secret-uc/index.js AI (source-diff): jsii-compiled TypeScript output; readable CDK provider code. ai
source-diff obfuscated-file:lib/data-databricks-secret-ucs/index.js AI (source-diff): jsii-compiled TypeScript output; readable CDK provider code. ai
source-diff obfuscated-file:lib/data-databricks-supervisor-agent-tool/index.js AI (source-diff): jsii-compiled TypeScript output; readable CDK provider code. ai

Versions (showing 4 of 4)

Version Deps Published
17.3.0 0 / 18
17.2.0 0 / 18
17.1.0 0 / 18
16.4.1 0 / 18

v17.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v17.2.0

8 findings
HIGH Publisher changed: cdktn-team → GitHub Actions (on 2026-05-29) provenance

This version was published by a different npm account than previous versions on 2026-05-29. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: lib/account-network-policy/index-structs/structs0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/data-databricks-account-network-policies/index-structs/structs0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/data-databricks-account-network-policy/index-structs/structs0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/account-network-policy/index-structs/structs400.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/data-databricks-account-network-policies/index-structs/structs400.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/data-databricks-account-network-policy/index-structs/structs400.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v17.1.0

16 findings
HIGH New obfuscated file: lib/data-databricks-disaster-recovery-failover-group/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/data-databricks-disaster-recovery-failover-groups/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/data-databricks-disaster-recovery-stable-url/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/data-databricks-disaster-recovery-stable-urls/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/data-databricks-secret-uc/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/data-databricks-secret-ucs/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/data-databricks-supervisor-agent-tool/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/data-databricks-supervisor-agent-tools/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/data-databricks-supervisor-agent/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/data-databricks-supervisor-agents/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/disaster-recovery-failover-group/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/disaster-recovery-stable-url/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/secret-uc/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/supervisor-agent-tool/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/supervisor-agent/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v16.4.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.