← Home

@aws-sdk/client-s3

AWS SDK for JavaScript S3 Client for Node.js, Browser and React Native

51
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

amzn-ossaws-sdk-bot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@aws-sdk/util-stream-browser AI (dependencies): First-party AWS SDK sub-package from the same monorepo, published by the same trusted aws-sdk-bot publisher. Not a security concern. ai
dependencies unvetted-dep:@aws-sdk/util-stream-node AI (dependencies): First-party AWS SDK sub-package from the same monorepo, published by the same trusted aws-sdk-bot publisher. Not a security concern. ai
phantom-deps phantom-dep:@aws-sdk/middleware-stack AI (phantom-deps): @aws-sdk/middleware-stack is explicitly declared as a direct dependency in package.json and is a legitimate AWS SDK framework package loaded by convention; stable false positive for this package. ai
dependencies unvetted-dep:@aws-sdk/middleware-ssec AI (dependencies): First-party AWS SDK middleware under the official @aws-sdk namespace; standard S3 client dependency. ai
dependencies unvetted-dep:@smithy/hash-stream-node AI (dependencies): First-party Smithy package under the official @smithy namespace; standard AWS SDK v3 dependency. ai
dependencies unvetted-dep:@aws-sdk/middleware-bucket-endpoint AI (dependencies): First-party AWS SDK middleware under the official @aws-sdk namespace; standard S3 client dependency. ai
dependencies unvetted-dep:@aws-sdk/middleware-expect-continue AI (dependencies): First-party AWS SDK middleware under the official @aws-sdk namespace; standard S3 client dependency. ai
dependencies unvetted-dep:@aws-sdk/middleware-location-constraint AI (dependencies): First-party AWS SDK middleware under the official @aws-sdk namespace; standard S3 client dependency. ai
dependencies unvetted-dep:@smithy/hash-blob-browser AI (dependencies): First-party Smithy package under the official @smithy namespace; standard AWS SDK v3 dependency. ai
dependencies unvetted-dep:@smithy/md5-js AI (dependencies): First-party Smithy/AWS SDK dependency published under the official @smithy namespace; part of the standard AWS SDK v3 ecosystem. ai
dependencies unvetted-dep:@aws-crypto/sha1-browser AI (dependencies): First-party AWS crypto package under the official @aws-crypto namespace; standard AWS SDK v3 dependency. ai
phantom-deps phantom-dep:@smithy/middleware-serde AI (phantom-deps): Framework-scoped Smithy package loaded by convention in the AWS SDK; not a real phantom dependency concern for this package. ai
provenance no-provenance AI (provenance): AWS SDK packages are published via automated bot without Sigstore provenance; publisher track record and package age provide sufficient trust. ai
phantom-deps phantom-dep:@smithy/middleware-stack AI (phantom-deps): Framework-scoped Smithy package loaded by convention in the AWS SDK; not a real phantom dependency concern for this package. ai

Versions (showing 51 of 650)

View all versions
Version Deps Published
3.1057.0 18 / 9
3.1056.0 18 / 9
3.1055.0 18 / 9
3.1054.0 18 / 9
3.1053.0 18 / 9
3.1052.0 18 / 9
3.1051.0 18 / 9
3.1050.0 18 / 9
3.1049.0 18 / 9
3.1048.0 18 / 9
3.1047.0 26 / 9
3.1046.0 26 / 9
3.1045.0 55 / 9
3.1044.0 55 / 9
3.1043.0 55 / 9
3.1042.0 55 / 9
3.1041.0 55 / 9
3.1040.0 55 / 9
3.1039.0 55 / 9
3.1038.0 55 / 9
3.1037.0 55 / 9
3.1036.0 55 / 9
3.1035.0 55 / 9
3.1034.0 55 / 9
3.1033.0 55 / 9
3.1032.0 55 / 9
3.1031.0 55 / 9
3.1030.0 55 / 9
3.1029.0 55 / 9
3.1028.0 55 / 9
3.1027.0 55 / 9
3.1026.0 55 / 9
3.1025.0 55 / 9
3.1024.0 55 / 9
3.1023.0 55 / 9
3.1022.0 55 / 9
3.1021.0 55 / 9
3.1020.0 55 / 9
3.1019.0 55 / 9
3.1018.0 55 / 9
3.1017.0 55 / 9
3.1016.0 55 / 9
3.1015.0 55 / 9
3.1014.0 55 / 9
3.1013.0 55 / 9
3.1012.0 55 / 9
3.1011.0 55 / 9
3.1010.0 55 / 9
3.1009.0 55 / 9
3.1008.0 55 / 9
3.1007.0 55 / 9

v3.1057.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1056.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1055.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1054.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1053.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1052.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1051.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1050.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1049.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1048.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1047.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1046.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1045.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1044.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1043.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1042.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1041.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1040.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1039.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1038.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1037.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1036.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1035.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.