← Home

@liflig/cdk

CDK library for Liflig

51
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

capra-cijol-capraconsultingevan-boonesondrehavsba.capraconsulting

Keywords

cdk

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:lib/rds/windows.js AI (source-diff): Readable compiled TypeScript utility; long lines from string concatenation in error messages, not obfuscation. ai
source-diff obfuscated-file:lib/alarms/queue-alarms.js AI (source-diff): File is readable TypeScript-compiled JS; long lines are from inline JSDoc/type annotations, not obfuscation. ai
semgrep semgrep:base64-decode AI (semgrep): Used in Basic Auth authorizer to decode HTTP Authorization header credentials — standard, expected pattern for this package. ai

Versions (showing 51 of 237)

View all versions
Version Deps Published
3.27.33 2 / 31
3.27.32 2 / 31
3.27.31 2 / 31
3.27.30 2 / 31
3.27.29 2 / 31
3.27.28 2 / 31
3.27.27 2 / 31
3.27.26 2 / 31
3.27.25 2 / 31
3.27.24 2 / 31
3.27.23 2 / 31
3.27.22 2 / 31
3.27.21 2 / 31
3.27.20 2 / 31
3.27.19 2 / 31
3.27.18 2 / 31
3.27.17 2 / 31
3.27.16 2 / 31
3.27.15 2 / 31
3.27.14 2 / 31
3.27.13 2 / 31
3.27.12 2 / 31
3.27.11 2 / 31
3.27.10 2 / 31
3.27.9 2 / 31
3.27.8 2 / 31
3.27.7 2 / 31
3.27.6 2 / 31
3.27.5 2 / 31
3.27.4 2 / 31
3.27.3 2 / 31
3.27.2 2 / 31
3.27.1 2 / 31
3.27.0 2 / 31
3.26.23 2 / 31
3.26.22 2 / 31
3.26.21 2 / 31
3.26.20 2 / 31
3.26.19 2 / 31
3.26.18 2 / 31
3.26.17 2 / 31
3.26.16 2 / 31
3.26.15 2 / 31
3.26.14 2 / 31
3.26.13 2 / 31
3.26.12 2 / 31
3.26.11 2 / 31
3.26.10 2 / 31
3.26.9 2 / 31
3.26.8 2 / 31
3.26.7 2 / 31

v3.27.33

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.27.32

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.27.31

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.27.30

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.27.29

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.27.28

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.27.27

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.27.26

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.27.25

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.27.24

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.27.23

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.27.22

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.27.21

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.