If you discover a potential security issue in this project, we ask that you notify AWS Security via our vulnerability reporting page. Please do not create a public GitHub issue for security vulnerabilities.
This repository contains a static JSON dataset with no executable code. Security concerns for this project include:
- Data integrity: Incorrect lifecycle dates or statuses that could cause consumers to make flawed operational decisions
- Source authenticity: Broken or manipulated
sourceUrlreferences that undermine the verification model - Supply-chain trust: Unauthorized modifications to the dataset that bypass the review process
- All data changes require CODEOWNERS approval before merge
- CI validates JSON schema, date consistency, and sourceUrl patterns on every PR
- Every entry includes a
sourceUrlpointing to official AWS documentation for independent verification - The
lastUpdatedfield signals dataset freshness
- For critical business decisions (upgrade deadlines, cost forecasting, compliance), always verify dates against the
sourceUrlprovided in each entry - Pin to tagged releases rather than tracking the main branch for production integrations
- Treat the
statusfield as advisory; validate against date fields programmatically for automated decisions