← Home

cdk-from-cfn

Turn AWS CloudFormation templates into AWS CDK applications

51
Versions
MIT OR Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

cdklabs-automation

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
npm-metadata bundled-binaries AI (npm-metadata): index_bg.wasm is the package's core wasm-bindgen output; expected every version. ai

Versions (showing 51 of 303)

View all versions
Version Deps Published
0.319.0 0 / 0
0.318.0 0 / 0
0.317.0 0 / 0
0.316.0 0 / 0
0.315.0 0 / 0
0.314.0 0 / 0
0.313.0 0 / 0
0.312.0 0 / 0
0.311.0 0 / 0
0.310.0 0 / 0
0.309.0 0 / 0
0.308.0 0 / 0
0.307.0 0 / 0
0.306.0 0 / 0
0.305.0 0 / 0
0.304.0 0 / 0
0.303.0 0 / 0
0.302.0 0 / 0
0.301.0 0 / 0
0.300.0 0 / 0
0.299.0 0 / 0
0.298.0 0 / 0
0.297.0 0 / 0
0.296.0 0 / 0
0.295.0 0 / 0
0.294.0 0 / 0
0.293.0 0 / 0
0.292.0 0 / 0
0.291.0 0 / 0
0.290.0 0 / 0
0.289.0 0 / 0
0.288.0 0 / 0
0.287.0 0 / 0
0.286.0 0 / 0
0.285.0 0 / 0
0.284.0 0 / 0
0.283.0 0 / 0
0.282.0 0 / 0
0.281.0 0 / 0
0.280.0 0 / 0
0.279.0 0 / 0
0.278.0 0 / 0
0.277.0 0 / 0
0.276.0 0 / 0
0.275.0 0 / 0
0.274.0 0 / 0
0.273.0 0 / 0
0.272.0 0 / 0
0.271.0 0 / 0
0.270.0 0 / 0
0.269.0 0 / 0

v0.319.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.318.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.317.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.316.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.315.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.314.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.313.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • index_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.312.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.311.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.