@aws-sdk/middleware-flexible-checksums
[](https://www.npmjs.com/package/@aws-sdk/middleware-flexible-checksums) [ relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@aws-crypto/crc32c | AI (dependencies): First-party AWS cryptography package from the same AWS SDK ecosystem; unvetted flag is a pipeline artifact, not a genuine risk. | ai | |
| dependencies | unvetted-dep:@aws-sdk/crc64-nvme | AI (dependencies): First-party AWS SDK package published by the same aws-sdk-bot publisher; unvetted flag is a pipeline artifact, not a genuine risk. | ai | |
| provenance | no-provenance | AI (provenance): AWS SDK bot publishes hundreds of packages without Sigstore provenance; this is consistent across the entire SDK and not a risk indicator for this trusted publisher. | ai | |
| bogus-package | bogus-package | AI (bogus-package): AWS SDK middleware packages routinely have minimal READMEs and no keywords; this is a structural pattern of the monorepo, not a spam indicator. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/types | AI (phantom-deps): @aws-sdk/types is a types-only package used by convention across the AWS SDK v3 ecosystem; phantom detection is a stable false positive here. | ai |
Versions (showing 51 of 270)
| Version | Deps | Published |
|---|---|---|
| 3.974.23 | 9 / 5 | |
| 3.974.22 | 9 / 5 | |
| 3.974.21 | 9 / 5 | |
| 3.974.20 | 9 / 5 | |
| 3.974.19 | 9 / 5 | |
| 3.974.18 | 9 / 5 | |
| 3.974.17 | 9 / 5 | |
| 3.974.16 | 14 / 5 | |
| 3.974.15 | 14 / 5 | |
| 3.974.14 | 14 / 5 | |
| 3.974.13 | 14 / 5 | |
| 3.974.12 | 14 / 5 | |
| 3.974.11 | 14 / 5 | |
| 3.974.10 | 14 / 5 | |
| 3.974.9 | 14 / 5 | |
| 3.974.8 | 14 / 5 | |
| 3.974.7 | 14 / 5 | |
| 3.974.6 | 14 / 5 | |
| 3.974.5 | 14 / 5 | |
| 3.974.4 | 14 / 5 | |
| 3.974.3 | 14 / 5 | |
| 3.974.2 | 14 / 5 | |
| 3.974.1 | 14 / 5 | |
| 3.974.0 | 14 / 5 | |
| 3.973.6 | 14 / 5 | |
| 3.973.5 | 14 / 5 | |
| 3.973.4 | 14 / 5 | |
| 3.973.3 | 14 / 5 | |
| 3.973.2 | 14 / 5 | |
| 3.973.1 | 14 / 5 | |
| 3.973.0 | 14 / 5 | |
| 3.972.11 | 14 / 5 | |
| 3.972.10 | 14 / 5 | |
| 3.972.9 | 14 / 5 | |
| 3.972.8 | 14 / 5 | |
| 3.972.7 | 14 / 5 | |
| 3.972.6 | 14 / 5 | |
| 3.972.5 | 14 / 5 | |
| 3.972.4 | 14 / 5 | |
| 3.972.3 | 14 / 5 | |
| 3.972.2 | 14 / 5 | |
| 3.972.1 | 14 / 5 | |
| 3.972.0 | 14 / 5 | |
| 3.971.0 | 14 / 5 | |
| 3.970.0 | 14 / 5 | |
| 3.969.0 | 14 / 5 | |
| 3.968.0 | 14 / 5 | |
| 3.967.0 | 14 / 5 | |
| 3.966.0 | 14 / 5 | |
| 3.965.0 | 14 / 5 | |
| 3.964.0 | 14 / 5 |
v3.974.23
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.974.22
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.974.21
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.974.20
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.974.19
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.974.18
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.974.17
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.974.16
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.974.15
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.974.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.974.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.974.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.