
Security News
/Research
Wallet-Draining npm Package Impersonates Nodemailer to Hijack Crypto Transactions
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
@release-gateway/aws-cdk-constructs
Advanced tools
Enterprise ready CDK constructs that are CIS 1.4 and NIST800-53 Rev.5 standards compliant
Library of Enterprise ready CDK constructs that are standards compliant with the CIS 1.4, NIST 800-53 Rev5 and adopting the best practices set out in AWS Well Architected Reliability and Security Pillars.
This library follows the AWS CDK L1, L2 paradigms and where possible applies the minimum configuration needed to satisfy the cloud standards.
Use the package manager npm to install this package:
npm install @release-gateway/aws-cdk-constructs
import { RGApp, RGStack, RGStackProps } from "@release-gateway/aws-cdk-constructs"
class MyStackStack extends RGStack {
constructor(scope: RGApp, id: string, props: RGStackProps) {
super(scope, id, props);
// Define your stack...
}
}
// Build and synthesize
const app = new RGApp();
new MyStack(app, "my-stack", {
serviceName: "My Service Name",
version: "1.0.0"
})
app.synth()
Construct name | Base class | Description of changes |
---|---|---|
RGApp | App | Includes RGGuardValidator as policy validator |
RGStack | Stack | Adds standard tags and creates shared KMS key for use by child resources |
RGGuardValidator | CfnGuardValidator | Policy validator configured to enforce CIS 1.4, NIST800-Rev53, Well Architecte Reliabilty Pillar and Well Architected Security Pillar best practices |
RGLogGroup | LogGroup | Applies kms log encryption, removal policy and sets retention to 1 week |
RGNodejsFunction | NodejsFunction | Makes VPC mandatory, creates lambda log group with encryption, configures DLQ and sets removal policy |
RGQueue | Queue | Sets KMS encryption, removal policy and configures DLQ |
RGTable | TableV2 | Sets KMS encryption,, removal policy |
RGHttpApi | HttpApi | Sets encrypted access logging and throttling defaults |
RGRestApi | RestApi | Sets encrypted access and execution logging, throttling defaults, regional endpoint type |
Pull requests are welcome. For major changes, please open an issue first to discuss what you would like to change.
Please make sure to update tests as appropriate.
Logo Icons
FAQs
Enterprise ready CDK constructs that are CIS 1.4 and NIST800-53 Rev.5 standards compliant
The npm package @release-gateway/aws-cdk-constructs receives a total of 6 weekly downloads. As such, @release-gateway/aws-cdk-constructs popularity was classified as not popular.
We found that @release-gateway/aws-cdk-constructs demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
/Research
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
Security News
This episode explores the hard problem of reachability analysis, from static analysis limits to handling dynamic languages and massive dependency trees.
Security News
/Research
Malicious Nx npm versions stole secrets and wallet info using AI CLI tools; Socket’s AI scanner detected the supply chain attack and flagged the malware.