All amazon-cognito-identity-js versions

amazon-cognito-identity-js @1.8.0

rejected
This version was rejected. It did not pass GreenFlagged's security review and is not served by the registry. The findings and risk dispositions below explain why.
10
Risk Score
Apache-2.0
License
No
Install Scripts
3
Dependencies
9
Dev Dependencies
343.0 KB
Package Size
Published

Amazon Cognito Identity Provider JavaScript SDK

Maintainers

itrestian

Keywords

amazonawscognitoidentity

Dependencies (3)

PackageConstraintRegistry Status
jsbn ^0.1.0 auto_approved
sjcl ^1.0.3 auto_approved
aws-sdk ^2.6.0 auto_approved

Dev Dependencies (9)

PackageConstraintRegistry Status
jsdoc ^3.4.0 auto_approved
eslint ^3.3.1 auto_approved
webpack ^1.13.1 auto_approved
babel-core ^6.13.2 auto_approved
babel-loader ^6.2.4 pending
babel-preset-es2015 ^6.13.2 auto_approved
eslint-plugin-import ^1.13.0 auto_approved
eslint-config-airbnb-base ^5.0.2 auto_approved
eslint-import-resolver-webpack ^0.5.1 pending

Transitive Dependency Tree

49 transitive deps max depth 9
  ├─ aws-sdk ^2.6.0 → 2.1692.0
  ├─ jsbn ^0.1.0 → 0.1.1
├─ sjcl ^1.0.3 → 1.0.9
  ├─ buffer 4.9.2 → 4.9.2
  ├─ events 1.1.1 → 1.1.1
  ├─ ieee754 1.1.13 → 1.1.13
  ├─ jmespath 0.16.0 → 0.16.0
  ├─ querystring 0.2.0 → 0.2.0
  ├─ sax 1.2.1 → 1.2.1
  ├─ url 0.10.3 → 0.10.3
  ├─ util ^0.12.4 → 0.12.5
  ├─ uuid 8.0.0 → 8.0.0
├─ xml2js 0.6.2 → 0.6.2
  ├─ base64-js ^1.0.2 → 1.5.1
  ├─ ieee754 ^1.1.4 → 1.2.1
  ├─ inherits ^2.0.3 → 2.0.4
  ├─ is-arguments ^1.0.4
  ├─ is-generator-function ^1.0.7 → 1.1.2
  ├─ is-typed-array ^1.1.3
  ├─ isarray ^1.0.0 → 1.0.0
  ├─ punycode 1.3.2 → 1.3.2
  ├─ querystring 0.2.0 → 0.2.0
  ├─ sax >=0.6.0 → 1.6.0
  ├─ which-typed-array ^1.1.2 → 1.1.20
├─ xmlbuilder ~11.0.0 → 11.0.1
  ├─ available-typed-arrays ^1.0.7 → 1.0.7
  ├─ call-bind ^1.0.8 → 1.0.9
  ├─ call-bound ^1.0.4 → 1.0.4
  ├─ for-each ^0.3.5 → 0.3.5
  ├─ generator-function ^2.0.0 → 2.0.1
  ├─ get-proto ^1.0.1 → 1.0.1
  ├─ gopd ^1.2.0
  ├─ has-tostringtag ^1.0.2 → 1.0.2
├─ safe-regex-test ^1.1.0 → 1.1.0
  ├─ call-bind-apply-helpers ^1.0.2 → 1.0.2
  ├─ call-bound ^1.0.2 → 1.0.4
  ├─ dunder-proto ^1.0.1 → 1.0.1
  ├─ es-define-property ^1.0.1 → 1.0.1
  ├─ es-errors ^1.3.0 → 1.3.0
  ├─ es-object-atoms ^1.0.0 → 1.1.1
  ├─ get-intrinsic ^1.3.0 → 1.3.1
  ├─ has-symbols ^1.0.3 → 1.1.0
  ├─ is-callable ^1.2.7 → 1.2.7
  ├─ is-regex ^1.2.1 → 1.2.1
  ├─ possible-typed-array-names ^1.0.0 → 1.1.0
├─ set-function-length ^1.2.2 → 1.2.2
  ├─ async-function ^1.0.0
  ├─ async-generator-function ^1.0.0 → 1.0.0
  ├─ call-bind-apply-helpers ^1.0.2 → 1.0.2
  ├─ call-bind-apply-helpers ^1.0.1 → 1.0.2
  ├─ call-bound ^1.0.2 → 1.0.4
  ├─ define-data-property ^1.1.4
  ├─ es-define-property ^1.0.1 → 1.0.1
  ├─ es-errors ^1.3.0 → 1.3.0
  ├─ es-object-atoms ^1.1.1 → 1.1.1
  ├─ function-bind ^1.1.2 → 1.1.2
  ├─ generator-function ^2.0.0 → 2.0.1
  ├─ get-intrinsic ^1.3.0 → 1.3.1
  ├─ get-intrinsic ^1.2.4 → 1.3.1
  ├─ get-proto ^1.0.1
  ├─ gopd ^1.2.0
  ├─ gopd ^1.0.1
  ├─ has-property-descriptors ^1.0.2 → 1.0.2
  ├─ has-symbols ^1.1.0 → 1.1.0
  ├─ has-tostringtag ^1.0.2 → 1.0.2
  ├─ hasown ^2.0.2 → 2.0.3
├─ math-intrinsics ^1.1.0 → 1.1.0
  ├─ async-function ^1.0.0
  ├─ async-generator-function ^1.0.0 → 1.0.0
  ├─ call-bind-apply-helpers ^1.0.2 → 1.0.2
  ├─ es-define-property ^1.0.0 → 1.0.1
  ├─ es-define-property ^1.0.1 → 1.0.1
  ├─ es-errors ^1.3.0 → 1.3.0
  ├─ es-object-atoms ^1.1.1 → 1.1.1
  ├─ function-bind ^1.1.2 → 1.1.2
  ├─ generator-function ^2.0.0 → 2.0.1
  ├─ get-intrinsic ^1.3.0 → 1.3.1
  ├─ get-proto ^1.0.1
  ├─ gopd ^1.2.0
  ├─ has-symbols ^1.0.3 → 1.1.0
  ├─ has-symbols ^1.1.0 → 1.1.0
  ├─ hasown ^2.0.2 → 2.0.3
├─ math-intrinsics ^1.1.0 → 1.1.0
  ├─ async-function ^1.0.0
  ├─ async-generator-function ^1.0.0 → 1.0.0
  ├─ call-bind-apply-helpers ^1.0.2 → 1.0.2
  ├─ es-define-property ^1.0.1 → 1.0.1
  ├─ es-errors ^1.3.0 → 1.3.0
  ├─ es-object-atoms ^1.1.1 → 1.1.1
  ├─ function-bind ^1.1.2 → 1.1.2
  ├─ generator-function ^2.0.0 → 2.0.1
  ├─ get-proto ^1.0.1
  ├─ gopd ^1.2.0
  ├─ has-symbols ^1.1.0 → 1.1.0
  ├─ hasown ^2.0.2 → 2.0.3
├─ math-intrinsics ^1.1.0 → 1.1.0
  ├─ es-errors ^1.3.0 → 1.3.0
  ├─ function-bind ^1.1.2 → 1.1.2

Risk Dispositions (1 applicable to this version, 1 other)

Accepted rules are downgraded to INFO on future analyses; rejected rules escalate to CRITICAL.

Rule Source Disposition Author Reason
unvetted-dep:sjcl dependencies reject AI AI (dependencies): Package identity mismatch makes this entire package suspect; unvetted crypto dep compounds the risk.
Show 1 disposition(s) that do not match any finding on this version
Rule Source Disposition Author Reason
large-new-source-files source-diff reject AI AI (source-diff): 42 new source files combined with a mismatched package.json identity (babel-webpack vs amazon-cognito-identity-js) is a strong indicator of injected/malicious content.

SAST Findings (1)

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

Review Summary

Risk score: 10. Findings: 1 medium (+10), 4 info (+0).

Commit: 7026fc7c6fff Browse source

Published to npm: