@middy/core
🛵 The stylish Node.js middleware engine for AWS Lambda (core package)
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): Package has SLSA provenance attestation via Sigstore, which supersedes gitHead as a supply chain integrity signal. Published by GitHub Actions from the official middyjs/middy monorepo. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): @middy/util is a first-party dependency from the same monorepo at the same version (7.1.5), representing a routine internal refactor, not a third-party injection. | ai | |
| provenance | publisher-changed | AI (provenance): willfarrell is the documented primary maintainer of middy (referenced in funding URL); transition from lmammino is a legitimate handoff. SLSA provenance attestation confirms CI/CD-produced release. | ai | |
| dependencies | unvetted-dep:@middy/util | AI (dependencies): Internal monorepo dependency published with same SLSA provenance; stable for this package. | ai | |
| phantom-deps | phantom-dep:@datastream/core | AI (phantom-deps): @datastream/core is a declared dependency in package.json; the phantom-dep finding reflects indirect/config-level usage rather than a true phantom dependency for this package. | ai | |
| typosquat | typosquat.levenshtein:cors | AI (typosquat): Scoped package @middy/core is clearly distinct from cors; Levenshtein match is a false positive for scoped namespaces. | ai |
Versions (showing 66 of 168)
| Version | Deps | Published |
|---|---|---|
| 4.2.5 | 0 / 2 | |
| 4.2.4 | 0 / 2 | |
| 4.2.3 | 0 / 2 | |
| 4.2.2 | 0 / 2 | |
| 4.2.1 | 0 / 2 | |
| 4.2.0 | 0 / 2 | |
| 4.1.0 | 0 / 2 | |
| 4.0.10 | 0 / 2 | |
| 4.0.9 | 0 / 2 | |
| 4.0.8 | 0 / 2 | |
| 4.0.7 | 0 / 2 | |
| 4.0.6 | 0 / 2 | |
| 4.0.5 | 0 / 2 | |
| 4.0.4 | 0 / 2 | |
| 4.0.3 | 0 / 2 | |
| 4.0.2 | 0 / 2 | |
| 4.0.1 | 0 / 2 | |
| 4.0.0 | 0 / 2 | |
| 3.6.2 | 0 / 2 | |
| 3.6.1 | 0 / 2 | |
| 3.6.0 | 0 / 2 | |
| 3.5.0 | 0 / 2 | |
| 3.4.0 | 0 / 2 | |
| 3.3.4 | 0 / 2 | |
| 3.3.3 | 0 / 2 | |
| 3.3.2 | 0 / 2 | |
| 3.3.1 | 0 / 2 | |
| 3.3.0 | 0 / 2 | |
| 3.2.2 | 0 / 2 | |
| 3.2.1 | 0 / 2 | |
| 3.2.0 | 0 / 2 | |
| 3.1.1 | 0 / 2 | |
| 3.1.0 | 0 / 2 | |
| 3.0.4 | 0 / 2 | |
| 3.0.3 | 0 / 2 | |
| 3.0.2 | 0 / 2 | |
| 3.0.1 | 0 / 2 | |
| 3.0.0 | 0 / 2 | |
| 2.5.7 | 0 / 2 | |
| 2.5.6 | 0 / 2 | |
| 2.5.5 | 0 / 2 | |
| 2.5.4 | 0 / 2 | |
| 2.5.3 | 0 / 2 | |
| 2.5.2 | 0 / 2 | |
| 2.5.1 | 0 / 2 | |
| 2.5.0 | 0 / 2 | |
| 2.4.3 | 0 / 2 | |
| 2.4.2 | 0 / 2 | |
| 2.4.1 | 0 / 2 | |
| 2.4.0 | 0 / 2 | |
| 2.3.0 | 0 / 2 | |
| 2.2.0 | 0 / 2 | |
| 2.1.1 | 0 / 2 | |
| 2.1.0 | 0 / 2 | |
| 2.0.1 | 0 / 2 | |
| 2.0.0 | 0 / 2 | |
| 1.5.2 | 1 / 2 | |
| 1.5.1 | 1 / 2 | |
| 1.5.0 | 1 / 2 | |
| 1.4.0 | 1 / 2 | |
| 1.3.2 | 1 / 2 | |
| 1.3.1 | 1 / 2 | |
| 1.3.0 | 1 / 2 | |
| 1.2.0 | 1 / 2 | |
| 1.1.0 | 1 / 2 | |
| 1.0.0 | 1 / 2 |
v4.2.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.2.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.2.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.2.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.2.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.2.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.1.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.0.10
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.0.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.0.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.0.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.0.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.0.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.0.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.0.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.0.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.0.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.6.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.6.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.6.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.5.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.4.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.3.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.3.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.3.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.3.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.3.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.2.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.2.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.2.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.1.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.1.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.0.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.0.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.0.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.0.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.5.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.5.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.5.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.5.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.5.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.5.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.5.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.5.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.4.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.4.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.4.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.4.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.3.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.5.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.5.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.5.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.