@bifravst/aws-ssm-settings-helpers
Helper functions written in TypeScript for storing and retrieving application settings in AWS SSM Parameter Store.
29
Versions
BSD-3-Clause
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
coderbyheartbifravst-ci
Keywords
awsssmtypescript
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Publisher changed from bifravst-ci bot to GitHub Actions OIDC publishing — a common legitimate migration. SLSA provenance attestation confirms CI/CD integrity. Stable pattern for this Nordic Semiconductor package. | ai |
Versions (showing 29 of 229)
| Version | Deps | Published |
|---|---|---|
| 1.2.160 | 0 / 9 | |
| 1.2.159 | 0 / 9 | |
| 1.2.158 | 0 / 9 | |
| 1.2.157 | 0 / 9 | |
| 1.2.156 | 0 / 9 | |
| 1.2.155 | 0 / 9 | |
| 1.2.154 | 0 / 9 | |
| 1.2.153 | 0 / 9 | |
| 1.2.152 | 0 / 9 | |
| 1.2.151 | 0 / 9 | |
| 1.2.150 | 0 / 9 | |
| 1.2.149 | 0 / 9 | |
| 1.2.148 | 0 / 9 | |
| 1.2.147 | 0 / 9 | |
| 1.2.146 | 0 / 9 | |
| 1.2.145 | 0 / 9 | |
| 1.2.144 | 0 / 9 | |
| 1.2.143 | 0 / 9 | |
| 1.2.142 | 0 / 9 | |
| 1.2.141 | 0 / 9 | |
| 1.2.140 | 0 / 9 | |
| 1.2.139 | 0 / 9 | |
| 1.2.138 | 0 / 9 | |
| 1.2.137 | 0 / 9 | |
| 1.2.136 | 0 / 9 | |
| 1.2.135 | 0 / 9 | |
| 1.2.134 | 0 / 9 | |
| 1.2.133 | 0 / 9 | |
| 1.2.132 | 0 / 9 |
v1.2.159
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.153
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.147
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.139
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.