@aws-sdk/client-rds
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@aws-sdk/middleware-sdk-rds | AI (dependencies): First-party AWS SDK middleware package in the same @aws-sdk namespace; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@smithy/middleware-serde | AI (phantom-deps): Framework-scoped Smithy package loaded by convention in AWS SDK clients; stable false positive. | ai | |
| phantom-deps | phantom-dep:@smithy/middleware-stack | AI (phantom-deps): Framework-scoped Smithy package loaded by convention in AWS SDK clients; stable false positive. | ai |
Versions (showing 14 of 114)
| Version | Deps | Published |
|---|---|---|
| 3.947.0 | 41 / 6 | |
| 3.946.0 | 41 / 6 | |
| 3.943.0 | 41 / 6 | |
| 3.940.0 | 41 / 6 | |
| 3.939.0 | 41 / 6 | |
| 3.938.0 | 41 / 6 | |
| 3.937.0 | 41 / 6 | |
| 3.936.0 | 41 / 6 | |
| 3.935.0 | 41 / 6 | |
| 3.934.0 | 41 / 6 | |
| 3.933.0 | 41 / 6 | |
| 3.932.0 | 41 / 6 | |
| 3.931.0 | 41 / 6 | |
| 3.930.0 | 41 / 6 |
v3.947.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.946.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.943.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.940.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.939.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.938.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.937.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.936.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.935.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.934.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.933.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.932.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.931.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.930.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.