@aws-sdk/client-iam
AWS SDK for JavaScript Iam Client for Node.js, Browser and React Native
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | large-new-source-files | AI (source-diff): AWS SDK client packages regularly add new source files as the IAM API surface grows. This is expected behavior for this package and not indicative of injected code. | ai | |
| phantom-deps | phantom-dep:@smithy/middleware-serde | AI (phantom-deps): @smithy/middleware-serde is a legitimate framework-scoped dependency loaded by convention in AWS SDK v3 architecture, not via direct import. | ai | |
| provenance | no-provenance | AI (provenance): Established AWS SDK package published via aws-sdk-bot; lack of Sigstore provenance is a known gap for this ecosystem, not a security risk indicator. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): AWS SDK team routinely rotates individual maintainers; aws-sdk-bot remains the consistent automated publisher. Maintainer removals here reflect team changes, not a takeover. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/util-base64-browser | AI (phantom-deps): AWS SDK framework-scoped package loaded by convention; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/middleware-stack | AI (phantom-deps): AWS SDK framework-scoped package loaded by convention; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/util-base64-node | AI (phantom-deps): AWS SDK framework-scoped package loaded by convention; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/client-sts | AI (phantom-deps): AWS SDK client packages conventionally load related service clients; this pattern is stable across versions. | ai | |
| phantom-deps | phantom-dep:@smithy/middleware-stack | AI (phantom-deps): Smithy middleware is dynamically loaded by convention in AWS SDK; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/client-sso-oidc | AI (phantom-deps): AWS SDK client packages conventionally load related service clients; this pattern is stable across versions. | ai |
Versions (showing 51 of 577)
| Version | Deps | Published |
|---|---|---|
| 3.1057.0 | 10 / 8 | |
| 3.1056.0 | 10 / 8 | |
| 3.1055.0 | 10 / 8 | |
| 3.1054.0 | 10 / 8 | |
| 3.1053.0 | 10 / 8 | |
| 3.1052.0 | 10 / 8 | |
| 3.1051.0 | 10 / 8 | |
| 3.1050.0 | 10 / 8 | |
| 3.1049.0 | 10 / 8 | |
| 3.1048.0 | 10 / 8 | |
| 3.1047.0 | 18 / 8 | |
| 3.1046.0 | 18 / 8 | |
| 3.1045.0 | 40 / 8 | |
| 3.1044.0 | 40 / 8 | |
| 3.1043.0 | 40 / 8 | |
| 3.1042.0 | 40 / 8 | |
| 3.1041.0 | 40 / 8 | |
| 3.1040.0 | 40 / 8 | |
| 3.1039.0 | 40 / 8 | |
| 3.1038.0 | 40 / 8 | |
| 3.1037.0 | 40 / 8 | |
| 3.1036.0 | 40 / 8 | |
| 3.1035.0 | 40 / 8 | |
| 3.1034.0 | 40 / 8 | |
| 3.1033.0 | 40 / 8 | |
| 3.1032.0 | 40 / 8 | |
| 3.1031.0 | 40 / 8 | |
| 3.1030.0 | 40 / 8 | |
| 3.1029.0 | 40 / 8 | |
| 3.1028.0 | 40 / 8 | |
| 3.1027.0 | 40 / 8 | |
| 3.1026.0 | 40 / 8 | |
| 3.1025.0 | 40 / 8 | |
| 3.1024.0 | 40 / 8 | |
| 3.1023.0 | 40 / 8 | |
| 3.1022.0 | 40 / 8 | |
| 3.1021.0 | 40 / 8 | |
| 3.1020.0 | 40 / 8 | |
| 3.1019.0 | 40 / 8 | |
| 3.1018.0 | 40 / 8 | |
| 3.1017.0 | 40 / 8 | |
| 3.1016.0 | 40 / 8 | |
| 3.1015.0 | 40 / 8 | |
| 3.1014.0 | 40 / 8 | |
| 3.1013.0 | 40 / 8 | |
| 3.1012.0 | 40 / 8 | |
| 3.1011.0 | 40 / 8 | |
| 3.1010.0 | 40 / 8 | |
| 3.1009.0 | 40 / 8 | |
| 3.1008.0 | 40 / 8 | |
| 3.1007.0 | 40 / 8 |
v3.1057.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1056.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1055.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1054.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1053.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1052.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1051.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1050.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1049.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1048.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1047.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1046.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1045.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1044.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1043.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1042.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1041.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1040.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1039.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1038.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1037.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1036.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1035.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.