← Home

jsii-release

Release jsii modules to multiple package managers

51
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

aws-cdk-teamcdklabs-automation

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:lib/bin/publib-maven.js AI (source-diff): Standard TypeScript compiler output (bundled bin); not obfuscated malicious code. ai
semgrep semgrep:env-spread AI (semgrep): Release tool intentionally passes env vars (GPG keys, credentials) to subprocesses; pattern is expected and stable. ai
semgrep semgrep:child-process-import AI (semgrep): Publishing tool invokes CLI tools (gpg, maven, npm, etc.) via child_process by design; stable for this package. ai
bogus-package bogus-package AI (bogus-package): Known cdklabs/AWS tool; README link-dump and missing keywords are cosmetic issues, not spam indicators. ai
phantom-deps phantom-dep:@types/fs-extra AI (phantom-deps): @types/fs-extra is a type declaration package; not directly imported at runtime by convention. ai

Versions (showing 51 of 230)

View all versions
Version Deps Published
0.2.1057 10 / 20
0.2.1056 10 / 20
0.2.1055 10 / 20
0.2.1054 10 / 20
0.2.1053 10 / 20
0.2.1052 10 / 20
0.2.1051 10 / 20
0.2.1050 10 / 20
0.2.1049 10 / 20
0.2.1048 10 / 20
0.2.1047 10 / 20
0.2.1046 10 / 20
0.2.1045 10 / 20
0.2.1044 10 / 20
0.2.1043 10 / 20
0.2.1042 10 / 20
0.2.1041 10 / 20
0.2.1040 10 / 20
0.2.1039 10 / 20
0.2.1038 10 / 20
0.2.1037 10 / 20
0.2.1036 10 / 20
0.2.1035 10 / 20
0.2.1034 10 / 20
0.2.1033 10 / 20
0.2.1032 10 / 20
0.2.1031 10 / 20
0.2.1030 10 / 20
0.2.1029 10 / 20
0.2.1028 10 / 20
0.2.1027 10 / 20
0.2.1026 10 / 20
0.2.1025 10 / 20
0.2.1024 10 / 20
0.2.1023 10 / 20
0.2.1022 10 / 20
0.2.1021 10 / 20
0.2.1020 10 / 20
0.2.1019 10 / 20
0.2.1018 10 / 20
0.2.1017 10 / 20
0.2.1016 10 / 20
0.2.1015 10 / 20
0.2.1014 10 / 20
0.2.1013 10 / 20
0.2.1012 10 / 20
0.2.1011 10 / 20
0.2.1010 10 / 20
0.2.1009 10 / 20
0.2.1008 10 / 20
0.2.1007 10 / 20

v0.2.1057

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.1056

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.1055

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.1054

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.1053

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.1052

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.