← Home

aws-cdk

66
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

amzn-ossaws-cdk-teameladb

Keywords

awscdk

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:glob AI (phantom-deps): Used in bundled CLI; false positive on scan. ai
semgrep semgrep:child-process-exec AI (semgrep): Opens browser for docs command; standard CLI behavior. ai
phantom-deps phantom-dep:table AI (phantom-deps): Used for CLI table rendering. ai
phantom-deps phantom-dep:json-diff AI (phantom-deps): Used for diff command output. ai
phantom-deps phantom-dep:archiver AI (phantom-deps): Used for asset zipping in CDK CLI. ai
source-diff obfuscated-file:lib/index.js AI (source-diff): esbuild bundle banner, not obfuscation; official CDK CLI ships single bundled entrypoint. ai
source-diff net-exec-file:lib/index.js AI (source-diff): Bundled CLI legitimately makes AWS API calls and spawns subprocesses; no hostile destination. ai
npm-metadata bundled-binaries AI (npm-metadata): index_bg.wasm is cdk-from-cfn wasm dependency; expected in this package. ai
source-diff obfuscated-file:lib/cli/telemetry/telemetry-state.js AI (source-diff): Readable compiled TS, not obfuscated; long-line heuristic false positive for this package. ai
source-diff obfuscated-file:lib/cli/util/check-unknown-options.js AI (source-diff): Readable compiled TS, not obfuscated; long lines from normal codegen. ai
semgrep semgrep:env-spread AI (semgrep): CLI tool passing env to child processes is expected behavior for CDK app execution. ai
semgrep semgrep:dynamic-require AI (semgrep): Dynamic require of package.json to read version number is a standard, safe pattern. ai
typosquat typosquat.levenshtein:aws-sdk AI (typosquat): aws-cdk is the official AWS CDK CLI by Amazon; not a typosquat of aws-sdk — distinct, well-known packages. ai
semgrep semgrep:child-process-spawn AI (semgrep): Expected for a CLI tool that runs user commands and initializes CDK projects. ai
semgrep semgrep:env-bulk-read AI (semgrep): Reading env keys to detect sandbox environments (CODEX_*) is benign config detection. ai
semgrep semgrep:child-process-import AI (semgrep): CDK CLI legitimately spawns child processes to execute CDK apps and run init commands. ai

Versions (showing 66 of 66)

Version Deps Published
2.1133.0 0 / 101
2.1132.1 0 / 101
2.1132.0 0 / 101
2.1131.0 0 / 100
2.1130.0 0 / 100
2.1129.0 0 / 100
2.1128.1 0 / 100
2.1128.0 0 / 100
2.1127.0 0 / 100
2.1126.0 0 / 99
2.1125.0 0 / 99
2.1124.1 0 / 99
2.1124.0 0 / 99
2.1123.0 0 / 99
2.1122.0 0 / 99
2.1121.0 0 / 100
2.1120.0 0 / 100
2.1119.0 0 / 99
2.1118.4 0 / 99
2.1118.3 0 / 99
2.1118.2 0 / 99
2.1118.1 0 / 99
2.1118.0 0 / 96
2.1117.0 0 / 96
2.1116.0 0 / 96
2.1115.1 0 / 99
2.1115.0 0 / 99
2.1114.1 0 / 99
2.1114.0 0 / 99
2.1113.0 0 / 98
2.1112.0 0 / 98
2.1111.0 0 / 98
2.1110.0 0 / 98
2.1109.0 0 / 98
2.1108.0 0 / 98
2.1107.0 0 / 98
2.1106.1 0 / 97
2.1106.0 0 / 97
2.1105.0 0 / 97
2.1104.0 0 / 97
2.1103.0 0 / 97
2.1102.0 0 / 97
2.1101.0 0 / 95
2.1100.3 0 / 95
2.1100.2 0 / 95
2.1100.1 0 / 95
2.1100.0 0 / 95
2.1034.0 0 / 95
2.1033.0 0 / 95
2.1032.0 0 / 95
2.1031.2 0 / 95
2.1031.1 0 / 95
2.13.0 26 / 29
2.12.0 26 / 29
2.11.0 26 / 28
2.10.0 26 / 28
2.9.0 26 / 28
2.8.0 26 / 28
2.7.0 26 / 28
2.6.0 25 / 28
2.5.0 25 / 28
2.4.0 25 / 28
2.3.0 25 / 28
2.2.0 25 / 28
2.1.0 25 / 28
2.0.0 25 / 28

v2.1133.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1132.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1132.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1131.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1130.0

4 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • lib/index_bg.wasm

HIGH New obfuscated file: lib/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: lib/index.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1129.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1114.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1114.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1113.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1112.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1111.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1110.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1109.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1108.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1107.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1106.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1106.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1105.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1104.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1103.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1102.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1101.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1100.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1100.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1100.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1100.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1034.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1033.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1032.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1031.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1031.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.13.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.12.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.11.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.10.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.9.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.8.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.