jsii-release
Release jsii modules to multiple package managers
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:lib/bin/publib-maven.js | AI (source-diff): Standard TypeScript compiler output (bundled bin); not obfuscated malicious code. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): Release tool intentionally passes env vars (GPG keys, credentials) to subprocesses; pattern is expected and stable. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): Publishing tool invokes CLI tools (gpg, maven, npm, etc.) via child_process by design; stable for this package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Known cdklabs/AWS tool; README link-dump and missing keywords are cosmetic issues, not spam indicators. | ai | |
| phantom-deps | phantom-dep:@types/fs-extra | AI (phantom-deps): @types/fs-extra is a type declaration package; not directly imported at runtime by convention. | ai |
Versions (showing 30 of 230)
| Version | Deps | Published |
|---|---|---|
| 0.2.857 | 9 / 19 | |
| 0.2.856 | 9 / 19 | |
| 0.2.855 | 9 / 19 | |
| 0.2.854 | 9 / 19 | |
| 0.2.853 | 9 / 19 | |
| 0.2.852 | 9 / 19 | |
| 0.2.851 | 9 / 19 | |
| 0.2.850 | 9 / 19 | |
| 0.2.849 | 9 / 19 | |
| 0.2.848 | 9 / 19 | |
| 0.2.847 | 9 / 19 | |
| 0.2.846 | 9 / 19 | |
| 0.2.845 | 9 / 19 | |
| 0.2.844 | 9 / 19 | |
| 0.2.843 | 9 / 19 | |
| 0.2.842 | 9 / 19 | |
| 0.2.841 | 9 / 19 | |
| 0.2.840 | 9 / 19 | |
| 0.2.839 | 9 / 19 | |
| 0.2.838 | 9 / 19 | |
| 0.2.837 | 9 / 19 | |
| 0.2.836 | 9 / 19 | |
| 0.2.835 | 9 / 19 | |
| 0.2.834 | 9 / 19 | |
| 0.2.833 | 9 / 19 | |
| 0.2.832 | 9 / 19 | |
| 0.2.831 | 9 / 19 | |
| 0.2.830 | 9 / 19 | |
| 0.2.829 | 9 / 19 | |
| 0.2.828 | 9 / 19 |
v0.2.857
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.856
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.855
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.854
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.853
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.852
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.851
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.850
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.849
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.848
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.847
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.846
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.845
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.844
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.843
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.842
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.841
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.840
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.839
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.838
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.837
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.836
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.835
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.834
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.833
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.832
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.831
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.830
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.829
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.828
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.