@goldstack/template-static-website-aws
Utilities for deploying a website to CloudFront and S3
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@goldstack/utils-aws-cli | AI (dependencies): Same goldstack org scope as all other accepted deps; consistent with package's established dependency pattern. | ai | |
| dependencies | unvetted-dep:@goldstack/utils-log | AI (dependencies): Internal goldstack monorepo dependency; stable pattern across all versions. | ai | |
| dependencies | unvetted-dep:@goldstack/utils-template | AI (dependencies): Internal goldstack monorepo dependency; stable pattern across all versions. | ai | |
| dependencies | unvetted-dep:@goldstack/utils-s3-deployment | AI (dependencies): Internal goldstack monorepo dependency; stable pattern across all versions. | ai | |
| dependencies | unvetted-dep:@goldstack/utils-package-config | AI (dependencies): Internal goldstack monorepo dependency; stable pattern across all versions. | ai | |
| phantom-deps | phantom-dep:@goldstack/utils-docs-cli | AI (phantom-deps): Same-org dependency used indirectly via monorepo tooling; stable false positive. | ai | |
| dependencies | unvetted-dep:@goldstack/infra | AI (dependencies): Internal goldstack monorepo dependency; stable pattern across all versions. | ai | |
| dependencies | unvetted-dep:@goldstack/utils-sh | AI (dependencies): Internal goldstack monorepo dependency; stable pattern across all versions. | ai | |
| dependencies | unvetted-dep:@goldstack/infra-aws | AI (dependencies): Internal goldstack monorepo dependency; stable pattern across all versions. | ai | |
| dependencies | unvetted-dep:@goldstack/utils-cli | AI (dependencies): Internal goldstack monorepo dependency; stable pattern across all versions. | ai | |
| dependencies | unvetted-dep:@goldstack/utils-config | AI (dependencies): Internal goldstack monorepo dependency; stable pattern across all versions. | ai | |
| dependencies | unvetted-dep:@goldstack/utils-package | AI (dependencies): Internal goldstack monorepo dependency; stable pattern across all versions. | ai | |
| dependencies | unvetted-dep:@goldstack/utils-docs-cli | AI (dependencies): Internal goldstack monorepo dependency; stable pattern across all versions. | ai | |
| provenance | no-provenance | AI (provenance): Long-established goldstack monorepo package; provenance absence is consistent across all versions. | ai | |
| phantom-deps | phantom-dep:@goldstack/utils-config | AI (phantom-deps): Same-org dep; phantom-dep heuristic fires on indirect usage within monorepo packages. | ai | |
| phantom-deps | phantom-dep:@goldstack/utils-template | AI (phantom-deps): Same-org dep; phantom-dep heuristic fires on indirect usage within monorepo packages. | ai | |
| phantom-deps | phantom-dep:source-map-support | AI (phantom-deps): source-map-support is a common runtime dep declared in package.json; phantom-dep heuristic false positive for this package. | ai |
Versions (showing 47 of 47)
| Version | Deps | Published |
|---|---|---|
| 0.5.100 | 15 / 10 | |
| 0.5.99 | 15 / 10 | |
| 0.5.98 | 15 / 10 | |
| 0.5.97 | 15 / 10 | |
| 0.5.96 | 15 / 10 | |
| 0.5.95 | 15 / 10 | |
| 0.5.94 | 15 / 10 | |
| 0.5.93 | 15 / 10 | |
| 0.5.92 | 14 / 10 | |
| 0.5.90 | 14 / 10 | |
| 0.5.88 | 14 / 10 | |
| 0.5.83 | 14 / 10 | |
| 0.5.80 | 14 / 10 | |
| 0.5.79 | 14 / 10 | |
| 0.5.77 | 14 / 10 | |
| 0.5.62 | 15 / 11 | |
| 0.5.61 | 15 / 11 | |
| 0.5.60 | 15 / 11 | |
| 0.5.51 | 15 / 11 | |
| 0.5.50 | 15 / 11 | |
| 0.5.49 | 15 / 11 | |
| 0.5.48 | 15 / 11 | |
| 0.5.47 | 15 / 11 | |
| 0.5.46 | 15 / 11 | |
| 0.5.45 | 15 / 11 | |
| 0.5.44 | 15 / 11 | |
| 0.5.43 | 15 / 11 | |
| 0.5.42 | 15 / 11 | |
| 0.5.41 | 15 / 11 | |
| 0.5.40 | 15 / 11 | |
| 0.5.39 | 15 / 11 | |
| 0.5.38 | 15 / 11 | |
| 0.5.37 | 15 / 11 | |
| 0.5.36 | 15 / 11 | |
| 0.5.35 | 15 / 11 | |
| 0.5.34 | 15 / 11 | |
| 0.5.33 | 15 / 11 | |
| 0.5.32 | 15 / 11 | |
| 0.5.31 | 15 / 11 | |
| 0.5.30 | 15 / 11 | |
| 0.5.29 | 15 / 11 | |
| 0.5.28 | 15 / 11 | |
| 0.5.27 | 15 / 11 | |
| 0.5.26 | 15 / 11 | |
| 0.5.25 | 15 / 11 | |
| 0.5.24 | 15 / 11 | |
| 0.5.23 | 15 / 11 |
v0.5.100
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.51
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.50
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.49
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.48
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.47
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.46
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.45
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.44
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.43
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.42
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.41
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.40
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.39
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.38
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.37
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.36
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.35
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.34
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.33
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.32
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.31
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.30
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.29
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.28
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.27
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.26
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.25
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.24
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.5.23
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.