← Home

@gradientedge/cdk-utils

Utilities for AWS CDK, Azure and Cloudflare Pulumi provisioning

51
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

jameswiltshirejimmythomsonspockedhemalshahgradient_edge

Keywords

gradientedgeawsazurecloudflarecdkaws-cdkpulumiiactypescript

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@pulumi/cloudflare AI (dependencies): Official Pulumi provider package from the Pulumi org; legitimate dependency for this CDK/Pulumi utility library. ai
dependencies unvetted-dep:cdktf AI (dependencies): cdktf is the official HashiCorp CDK for Terraform; legitimate core dependency for this package. ai
dependencies unvetted-dep:@cdktf/provider-azurerm AI (dependencies): Official HashiCorp CDKTF Azure provider; expected dependency for this package. ai
dependencies unvetted-dep:@cdktf/provider-cloudflare AI (dependencies): Official HashiCorp CDKTF Cloudflare provider; expected dependency for this package. ai
dependencies unvetted-dep:cdktf-local-exec AI (dependencies): Known CDKTF utility; consistent with this package's CDKTF usage. ai
dependencies unvetted-dep:@cdktf/provider-aws AI (dependencies): Official HashiCorp CDKTF AWS provider; expected dependency for this package. ai
phantom-deps phantom-dep:@types/uuid AI (phantom-deps): Type-only package; framework-scoped, not directly imported by convention. ai
phantom-deps phantom-dep:@types/lodash AI (phantom-deps): Type-only package for lodash; expected pattern for this package. ai
semgrep semgrep:new-function-constructor AI (semgrep): Fires on AWS CDK CloudFront Function construct instantiation, not JS eval-like new Function(); stable false positive for this package. ai
phantom-deps phantom-dep:json5 AI (phantom-deps): Used in config files; stable phantom-dep false positive for this package. ai
phantom-deps phantom-dep:nconf AI (phantom-deps): Used in config files; stable phantom-dep false positive for this package. ai
phantom-deps phantom-dep:ts-node AI (phantom-deps): Used in config/tooling; stable phantom-dep false positive for this package. ai
phantom-deps phantom-dep:pluralize AI (phantom-deps): Utility dep used indirectly; stable false positive for this package. ai
phantom-deps phantom-dep:@types/node AI (phantom-deps): Framework-scoped type package; expected pattern for this package. ai
provenance no-provenance AI (provenance): Established org package with 451 versions; no provenance is consistent across all prior releases. ai

Versions (showing 51 of 65)

View all versions
Version Deps Published
11.48.0 4 / 0
11.47.1 4 / 0
11.47.0 4 / 0
11.46.0 4 / 0
11.45.0 4 / 0
11.44.0 4 / 0
11.43.0 4 / 0
11.42.0 4 / 0
11.41.0 4 / 0
11.40.0 4 / 0
11.39.3 4 / 0
11.39.2 4 / 0
11.39.1 4 / 0
11.39.0 4 / 0
11.38.0 4 / 0
11.37.0 4 / 0
11.36.0 4 / 0
11.35.0 4 / 0
11.34.0 4 / 0
11.33.0 4 / 0
11.32.0 4 / 0
11.31.1 4 / 0
11.31.0 4 / 0
11.30.0 4 / 0
11.29.0 4 / 0
11.28.0 4 / 0
11.27.0 4 / 0
11.26.0 4 / 0
11.25.0 4 / 0
11.24.0 4 / 0
11.23.0 4 / 0
11.22.0 4 / 0
11.21.0 4 / 0
11.20.0 4 / 0
11.19.0 4 / 0
11.18.0 4 / 0
11.17.0 4 / 0
11.16.0 4 / 0
11.15.0 4 / 0
11.14.0 4 / 0
11.13.1 4 / 0
11.13.0 4 / 0
11.12.1 4 / 0
11.12.0 4 / 0
11.11.0 4 / 0
11.10.0 4 / 0
11.9.0 4 / 0
11.8.0 4 / 0
11.7.0 4 / 0
11.6.0 4 / 0
11.5.0 4 / 0

v11.48.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.47.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.47.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.46.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.45.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.44.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.43.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.42.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.41.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.40.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.39.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.39.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.39.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.39.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.38.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.37.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.36.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.35.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.34.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.33.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.32.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.31.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.31.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.29.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.28.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.27.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.26.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.25.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.23.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.22.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.21.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.20.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.19.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.18.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.17.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.16.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.15.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.13.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.13.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.12.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.12.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.11.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.9.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.8.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.7.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.6.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.5.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.