@aws-sdk/client-cloudformation
AWS SDK for JavaScript Cloudformation Client for Node.js, Browser and React Native
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | large-new-source-files | AI (source-diff): AWS SDK client packages regularly add new source files as AWS services expand their APIs. This is expected growth, not injected code. | ai | |
| provenance | no-provenance | AI (provenance): AWS SDK bot publishing pipeline does not use Sigstore provenance; this is a known, stable characteristic of all AWS SDK packages. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/middleware-stack | AI (phantom-deps): AWS SDK v3 framework-scoped package loaded by convention; declared and used as intended in the SDK architecture. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/util-base64-node | AI (phantom-deps): AWS SDK v3 utility package conditionally loaded for Node.js runtime; declared and used as intended. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/util-base64-browser | AI (phantom-deps): AWS SDK v3 utility package conditionally loaded for browser runtime; declared and used as intended. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): AWS SDK v3 consolidates maintainers under aws-sdk-bot automation; removal of individual maintainers is a known, recurring pattern across all AWS SDK packages and not a takeover signal. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): @smithy/uuid is a first-party Smithy/AWS package from the same trusted ecosystem; its addition is benign and consistent with AWS SDK v3 dependency patterns. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/client-sts | AI (phantom-deps): AWS SDK v3 uses framework-scoped packages loaded by convention; these are intentional and legitimate. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/client-sso-oidc | AI (phantom-deps): AWS SDK v3 uses framework-scoped packages loaded by convention; these are intentional and legitimate. | ai | |
| phantom-deps | phantom-dep:@smithy/middleware-stack | AI (phantom-deps): AWS SDK v3 uses framework-scoped packages loaded by convention; these are intentional and legitimate. | ai |
Versions (showing 100 of 592)
| Version | Deps | Published |
|---|---|---|
| 3.1057.0 | 10 / 6 | |
| 3.1056.0 | 10 / 6 | |
| 3.1055.0 | 10 / 6 | |
| 3.1054.0 | 10 / 6 | |
| 3.1053.0 | 10 / 6 | |
| 3.1052.0 | 10 / 6 | |
| 3.1051.0 | 10 / 6 | |
| 3.1050.0 | 10 / 6 | |
| 3.1049.0 | 10 / 6 | |
| 3.1048.0 | 10 / 6 | |
| 3.1047.0 | 18 / 6 | |
| 3.1046.0 | 18 / 6 | |
| 3.1045.0 | 40 / 6 | |
| 3.1044.0 | 40 / 6 | |
| 3.1043.0 | 40 / 6 | |
| 3.1042.0 | 40 / 6 | |
| 3.1041.0 | 40 / 6 | |
| 3.1040.0 | 40 / 6 | |
| 3.1039.0 | 40 / 6 | |
| 3.1038.0 | 40 / 6 | |
| 3.1037.0 | 40 / 6 | |
| 3.1036.0 | 40 / 6 | |
| 3.1035.0 | 40 / 6 | |
| 3.1034.0 | 40 / 6 | |
| 3.1033.0 | 40 / 6 | |
| 3.1032.0 | 40 / 6 | |
| 3.1031.0 | 40 / 6 | |
| 3.1030.0 | 40 / 6 | |
| 3.1029.0 | 40 / 6 | |
| 3.1028.0 | 40 / 6 | |
| 3.1027.0 | 40 / 6 | |
| 3.1026.0 | 40 / 6 | |
| 3.1025.0 | 40 / 6 | |
| 3.1024.0 | 40 / 6 | |
| 3.1023.0 | 40 / 6 | |
| 3.1022.0 | 40 / 6 | |
| 3.1021.0 | 40 / 6 | |
| 3.1020.0 | 40 / 6 | |
| 3.1019.0 | 40 / 6 | |
| 3.1018.0 | 40 / 6 | |
| 3.1017.0 | 40 / 6 | |
| 3.1016.0 | 40 / 6 | |
| 3.1015.0 | 40 / 6 | |
| 3.1014.0 | 40 / 6 | |
| 3.1013.0 | 40 / 6 | |
| 3.1012.0 | 40 / 6 | |
| 3.1011.0 | 40 / 6 | |
| 3.1010.0 | 40 / 6 | |
| 3.1009.0 | 40 / 6 | |
| 3.1008.0 | 40 / 6 | |
| 3.1007.0 | 40 / 6 | |
| 3.1006.0 | 40 / 6 | |
| 3.1005.0 | 40 / 6 | |
| 3.1004.0 | 40 / 6 | |
| 3.1003.0 | 40 / 6 | |
| 3.1002.0 | 40 / 6 | |
| 3.1001.0 | 40 / 6 | |
| 3.1000.0 | 40 / 6 | |
| 3.999.0 | 40 / 6 | |
| 3.998.0 | 40 / 6 | |
| 3.997.0 | 40 / 6 | |
| 3.996.0 | 40 / 6 | |
| 3.995.0 | 40 / 6 | |
| 3.994.0 | 40 / 6 | |
| 3.993.0 | 40 / 6 | |
| 3.992.0 | 40 / 6 | |
| 3.991.0 | 40 / 6 | |
| 3.990.0 | 40 / 6 | |
| 3.989.0 | 40 / 6 | |
| 3.988.0 | 40 / 6 | |
| 3.987.0 | 40 / 6 | |
| 3.986.0 | 40 / 6 | |
| 3.985.0 | 40 / 6 | |
| 3.984.0 | 40 / 6 | |
| 3.983.0 | 40 / 6 | |
| 3.982.0 | 40 / 6 | |
| 3.981.0 | 40 / 6 | |
| 3.980.0 | 40 / 6 | |
| 3.978.0 | 40 / 6 | |
| 3.975.0 | 40 / 6 | |
| 3.974.0 | 40 / 6 | |
| 3.972.0 | 40 / 6 | |
| 3.971.0 | 40 / 6 | |
| 3.970.0 | 40 / 6 | |
| 3.969.0 | 40 / 6 | |
| 3.968.0 | 40 / 6 | |
| 3.967.0 | 40 / 6 | |
| 3.966.0 | 40 / 6 | |
| 3.965.0 | 40 / 6 | |
| 3.964.0 | 40 / 6 | |
| 3.962.0 | 40 / 6 | |
| 3.958.0 | 40 / 6 | |
| 3.957.0 | 40 / 6 | |
| 3.956.0 | 40 / 6 | |
| 3.955.0 | 40 / 6 | |
| 3.954.0 | 40 / 6 | |
| 3.953.0 | 40 / 6 | |
| 3.952.0 | 40 / 6 | |
| 3.948.0 | 40 / 6 | |
| 3.947.0 | 40 / 6 |
v3.1057.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1056.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1055.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1054.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1053.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1052.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1051.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1050.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1049.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1048.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1047.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1046.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1045.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1044.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1043.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1042.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1041.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1040.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1039.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1038.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1037.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1036.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1035.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.