cdk8s
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| vendored-integrity | tampered-vendored-dep:. | AI (vendored-integrity): Flagged files are cdk8s's own package metadata/lib files, not altered projen payload; unchanged across versions. | ai | |
| vendored-integrity | unresolved-vendored-tree:node_modules/follow-redirects | AI (vendored-integrity): Declared bundledDependency; likely version-hash mismatch not implant, from trusted publisher. | ai | |
| vendored-integrity | unresolved-vendored-tree:node_modules/yaml | AI (vendored-integrity): Declared bundledDependency at pinned prerelease version 2.0.0-7; expected hash mismatch. | ai | |
| provenance | publisher-changed | AI (provenance): cdk8s-team migrated publishing to GitHub Actions CI/CD with SLSA attestation; stable pattern going forward. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): cdk8s-core legitimately wraps spawnSync for helm/kubectl invocations; stable pattern across versions. | ai |
Versions (showing 51 of 879)
| Version | Deps | Published |
|---|---|---|
| 2.70.85 | 3 / 24 | |
| 2.70.84 | 3 / 24 | |
| 2.70.83 | 3 / 24 | |
| 2.70.82 | 3 / 24 | |
| 2.70.81 | 3 / 24 | |
| 2.70.80 | 3 / 24 | |
| 2.70.79 | 3 / 24 | |
| 2.70.78 | 3 / 24 | |
| 2.70.77 | 3 / 24 | |
| 2.70.76 | 3 / 24 | |
| 2.70.75 | 3 / 24 | |
| 2.70.74 | 3 / 24 | |
| 2.70.73 | 3 / 24 | |
| 2.70.72 | 3 / 24 | |
| 2.70.71 | 3 / 24 | |
| 2.70.70 | 3 / 24 | |
| 2.70.69 | 3 / 24 | |
| 2.70.68 | 3 / 24 | |
| 2.70.67 | 3 / 24 | |
| 2.70.66 | 3 / 24 | |
| 2.70.65 | 3 / 24 | |
| 2.70.64 | 3 / 24 | |
| 2.70.63 | 3 / 24 | |
| 2.70.62 | 3 / 24 | |
| 2.70.61 | 3 / 24 | |
| 2.70.60 | 3 / 24 | |
| 2.70.59 | 3 / 24 | |
| 2.70.58 | 3 / 24 | |
| 2.70.57 | 3 / 24 | |
| 2.70.56 | 3 / 24 | |
| 2.70.55 | 3 / 24 | |
| 2.70.54 | 3 / 24 | |
| 2.70.53 | 3 / 24 | |
| 2.70.52 | 3 / 24 | |
| 2.70.51 | 3 / 24 | |
| 2.70.50 | 3 / 24 | |
| 2.70.49 | 3 / 24 | |
| 2.70.48 | 3 / 24 | |
| 2.70.47 | 3 / 24 | |
| 2.70.46 | 3 / 24 | |
| 2.70.45 | 3 / 24 | |
| 2.70.44 | 3 / 24 | |
| 2.70.43 | 3 / 24 | |
| 2.70.42 | 3 / 24 | |
| 2.70.41 | 3 / 24 | |
| 2.70.40 | 3 / 24 | |
| 2.70.39 | 3 / 24 | |
| 2.70.38 | 3 / 24 | |
| 2.70.37 | 3 / 24 | |
| 2.70.36 | 3 / 24 | |
| 2.70.35 | 3 / 24 |
v2.70.85
2 findingsThe directory `.` byte-matched 258 of 318 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 11 file(s) inside it differ from that package's bytes at the same path: .jsii, README.md, lib/index.d.ts, lib/index.js, lib/json-patch.d.ts, lib/json-patch.js, lib/testing.d.ts, lib/testing.js, lib/yaml.d.ts, lib/yaml.js, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.70.84
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.70.83
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.70.82
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.70.81
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.