← Home

cdk8s

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

cdk8s-team

Keywords

cdkconfigurationconstructscontainersk8skubernetesmicroservices

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
vendored-integrity tampered-vendored-dep:. AI (vendored-integrity): Flagged files are cdk8s's own package metadata/lib files, not altered projen payload; unchanged across versions. ai
vendored-integrity unresolved-vendored-tree:node_modules/follow-redirects AI (vendored-integrity): Declared bundledDependency; likely version-hash mismatch not implant, from trusted publisher. ai
vendored-integrity unresolved-vendored-tree:node_modules/yaml AI (vendored-integrity): Declared bundledDependency at pinned prerelease version 2.0.0-7; expected hash mismatch. ai
provenance publisher-changed AI (provenance): cdk8s-team migrated publishing to GitHub Actions CI/CD with SLSA attestation; stable pattern going forward. ai
semgrep semgrep:child-process-import AI (semgrep): cdk8s-core legitimately wraps spawnSync for helm/kubectl invocations; stable pattern across versions. ai

Versions (showing 51 of 879)

View all versions
Version Deps Published
2.70.85 3 / 24
2.70.84 3 / 24
2.70.83 3 / 24
2.70.82 3 / 24
2.70.81 3 / 24
2.70.80 3 / 24
2.70.79 3 / 24
2.70.78 3 / 24
2.70.77 3 / 24
2.70.76 3 / 24
2.70.75 3 / 24
2.70.74 3 / 24
2.70.73 3 / 24
2.70.72 3 / 24
2.70.71 3 / 24
2.70.70 3 / 24
2.70.69 3 / 24
2.70.68 3 / 24
2.70.67 3 / 24
2.70.66 3 / 24
2.70.65 3 / 24
2.70.64 3 / 24
2.70.63 3 / 24
2.70.62 3 / 24
2.70.61 3 / 24
2.70.60 3 / 24
2.70.59 3 / 24
2.70.58 3 / 24
2.70.57 3 / 24
2.70.56 3 / 24
2.70.55 3 / 24
2.70.54 3 / 24
2.70.53 3 / 24
2.70.52 3 / 24
2.70.51 3 / 24
2.70.50 3 / 24
2.70.49 3 / 24
2.70.48 3 / 24
2.70.47 3 / 24
2.70.46 3 / 24
2.70.45 3 / 24
2.70.44 3 / 24
2.70.43 3 / 24
2.70.42 3 / 24
2.70.41 3 / 24
2.70.40 3 / 24
2.70.39 3 / 24
2.70.38 3 / 24
2.70.37 3 / 24
2.70.36 3 / 24
2.70.35 3 / 24

v2.70.85

2 findings
HIGH Modified vendored dependency: . (11 file(s)) vendored-integrity

The directory `.` byte-matched 258 of 318 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 11 file(s) inside it differ from that package's bytes at the same path: .jsii, README.md, lib/index.d.ts, lib/index.js, lib/json-patch.d.ts, lib/json-patch.js, lib/testing.d.ts, lib/testing.js, lib/yaml.d.ts, lib/yaml.js, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.70.84

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.70.83

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.70.82

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.70.81

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.