aws-cdk
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:glob | AI (phantom-deps): Used in bundled CLI; false positive on scan. | ai | |
| semgrep | semgrep:child-process-exec | AI (semgrep): Opens browser for docs command; standard CLI behavior. | ai | |
| phantom-deps | phantom-dep:table | AI (phantom-deps): Used for CLI table rendering. | ai | |
| phantom-deps | phantom-dep:json-diff | AI (phantom-deps): Used for diff command output. | ai | |
| phantom-deps | phantom-dep:archiver | AI (phantom-deps): Used for asset zipping in CDK CLI. | ai | |
| source-diff | obfuscated-file:lib/index.js | AI (source-diff): esbuild bundle banner, not obfuscation; official CDK CLI ships single bundled entrypoint. | ai | |
| source-diff | net-exec-file:lib/index.js | AI (source-diff): Bundled CLI legitimately makes AWS API calls and spawns subprocesses; no hostile destination. | ai | |
| npm-metadata | bundled-binaries | AI (npm-metadata): index_bg.wasm is cdk-from-cfn wasm dependency; expected in this package. | ai | |
| source-diff | obfuscated-file:lib/cli/telemetry/telemetry-state.js | AI (source-diff): Readable compiled TS, not obfuscated; long-line heuristic false positive for this package. | ai | |
| source-diff | obfuscated-file:lib/cli/util/check-unknown-options.js | AI (source-diff): Readable compiled TS, not obfuscated; long lines from normal codegen. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): CLI tool passing env to child processes is expected behavior for CDK app execution. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require of package.json to read version number is a standard, safe pattern. | ai | |
| typosquat | typosquat.levenshtein:aws-sdk | AI (typosquat): aws-cdk is the official AWS CDK CLI by Amazon; not a typosquat of aws-sdk — distinct, well-known packages. | ai | |
| semgrep | semgrep:child-process-spawn | AI (semgrep): Expected for a CLI tool that runs user commands and initializes CDK projects. | ai | |
| semgrep | semgrep:env-bulk-read | AI (semgrep): Reading env keys to detect sandbox environments (CODEX_*) is benign config detection. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): CDK CLI legitimately spawns child processes to execute CDK apps and run init commands. | ai |
Versions (showing 51 of 54)
| Version | Deps | Published |
|---|---|---|
| 2.1133.0 | 0 / 101 | |
| 2.1132.1 | 0 / 101 | |
| 2.1132.0 | 0 / 101 | |
| 2.1131.0 | 0 / 100 | |
| 2.1130.0 | 0 / 100 | |
| 2.1129.0 | 0 / 100 | |
| 2.1128.1 | 0 / 100 | |
| 2.1128.0 | 0 / 100 | |
| 2.1127.0 | 0 / 100 | |
| 2.1126.0 | 0 / 99 | |
| 2.1125.0 | 0 / 99 | |
| 2.1124.1 | 0 / 99 | |
| 2.1124.0 | 0 / 99 | |
| 2.1123.0 | 0 / 99 | |
| 2.1122.0 | 0 / 99 | |
| 2.1121.0 | 0 / 100 | |
| 2.1120.0 | 0 / 100 | |
| 2.1119.0 | 0 / 99 | |
| 2.1118.4 | 0 / 99 | |
| 2.1118.3 | 0 / 99 | |
| 2.1118.2 | 0 / 99 | |
| 2.1118.1 | 0 / 99 | |
| 2.1118.0 | 0 / 96 | |
| 2.1117.0 | 0 / 96 | |
| 2.1116.0 | 0 / 96 | |
| 2.1115.1 | 0 / 99 | |
| 2.1115.0 | 0 / 99 | |
| 2.1114.1 | 0 / 99 | |
| 2.1114.0 | 0 / 99 | |
| 2.1113.0 | 0 / 98 | |
| 2.1112.0 | 0 / 98 | |
| 2.1111.0 | 0 / 98 | |
| 2.1110.0 | 0 / 98 | |
| 2.1109.0 | 0 / 98 | |
| 2.1108.0 | 0 / 98 | |
| 2.1107.0 | 0 / 98 | |
| 2.1106.1 | 0 / 97 | |
| 2.1106.0 | 0 / 97 | |
| 2.1105.0 | 0 / 97 | |
| 2.1104.0 | 0 / 97 | |
| 2.1103.0 | 0 / 97 | |
| 2.1102.0 | 0 / 97 | |
| 2.1101.0 | 0 / 95 | |
| 2.1100.3 | 0 / 95 | |
| 2.1100.2 | 0 / 95 | |
| 2.1100.1 | 0 / 95 | |
| 2.1100.0 | 0 / 95 | |
| 2.1034.0 | 0 / 95 | |
| 2.1033.0 | 0 / 95 | |
| 2.1032.0 | 0 / 95 | |
| 2.1031.2 | 0 / 95 |
v2.1133.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1132.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1132.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1131.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1130.0
4 findingsPackage contains compiled binaries that could be backdoors: • lib/index_bg.wasm
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1129.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1114.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1114.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1113.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1112.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1111.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1110.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1109.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1108.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1107.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1106.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1106.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1105.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1104.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1103.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1102.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1101.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1100.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1100.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1100.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1100.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1034.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1033.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1032.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1031.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.