@pulumi/azure
A Pulumi package for creating and managing Microsoft Azure cloud resources, based on the Terraform azurerm provider. We recommend using the [Azure Native provider](https://github.com/pulumi/pulumi-azure-native) to provision Azure infrastructure. Azure Nat
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:moment | AI (phantom-deps): moment is a declared runtime dep used by the provider; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:@azure/eventgrid | AI (phantom-deps): Framework-scoped Azure SDK dep; loaded by convention in Pulumi provider, not a direct import. | ai | |
| phantom-deps | phantom-dep:@azure/functions | AI (phantom-deps): Framework-scoped Azure SDK dep; loaded by convention in Pulumi provider. | ai | |
| phantom-deps | phantom-dep:azure-functions-ts-essentials | AI (phantom-deps): Referenced in config files as documented; stable false positive for this package. | ai | |
| semgrep | semgrep:ssh-key-access | AI (semgrep): Fires on JSDoc example code in documentation comments, not runtime credential access. Stable false positive for this package. | ai | |
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): Fires on localhost example URL (127.0.0.1) in documentation comments, not actual network code. | ai |
Versions (showing 7 of 7)
| Version | Deps | Published |
|---|---|---|
| 6.38.0 | 8 / 3 | |
| 6.37.0 | 8 / 3 | |
| 6.36.0 | 8 / 3 | |
| 6.35.0 | 8 / 3 | |
| 6.34.0 | 8 / 3 | |
| 5.89.3 | 8 / 3 | |
| 5.89.2 | 8 / 3 |
v6.38.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.37.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.36.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.34.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.89.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.89.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.