@aws-sdk/middleware-sdk-sts
[](https://www.npmjs.com/package/@aws-sdk/middleware-sdk-sts) [](https://www.npmjs.com/packag
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@aws-sdk/middleware-signing | AI (dependencies): This is a sibling AWS SDK v3 package published in the same monorepo release cycle at the same version. The dependency pattern is stable and expected for all versions of this package. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/types | AI (phantom-deps): @aws-sdk/types is a framework-scoped package loaded by convention across the AWS SDK v3 ecosystem; stable false positive. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Short README and no keywords are typical for internal AWS SDK v3 middleware packages; not spam indicators. | ai | |
| phantom-deps | phantom-dep:tslib | AI (phantom-deps): tslib is a standard implicit dependency across all AWS SDK v3 packages; not a real phantom dep concern. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/signature-v4 | AI (phantom-deps): Declared dependency in AWS SDK monorepo; loaded by convention within SDK architecture. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/protocol-http | AI (phantom-deps): Declared dependency in AWS SDK monorepo; loaded by convention within SDK architecture. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/property-provider | AI (phantom-deps): Declared dependency in AWS SDK monorepo; loaded by convention within SDK architecture. | ai |
Versions (showing 51 of 200)
| Version | Deps | Published |
|---|---|---|
| 3.972.13 | 4 / 5 | |
| 3.972.12 | 4 / 5 | |
| 3.972.11 | 4 / 5 | |
| 3.972.10 | 4 / 5 | |
| 3.972.9 | 4 / 5 | |
| 3.972.8 | 4 / 5 | |
| 3.972.7 | 4 / 5 | |
| 3.972.6 | 4 / 5 | |
| 3.972.5 | 4 / 5 | |
| 3.972.4 | 4 / 5 | |
| 3.972.3 | 4 / 5 | |
| 3.972.2 | 4 / 5 | |
| 3.972.1 | 4 / 5 | |
| 3.972.0 | 4 / 5 | |
| 3.971.0 | 4 / 5 | |
| 3.969.0 | 4 / 5 | |
| 3.968.0 | 4 / 5 | |
| 3.965.0 | 4 / 5 | |
| 3.957.0 | 4 / 5 | |
| 3.956.0 | 4 / 5 | |
| 3.953.0 | 4 / 5 | |
| 3.936.0 | 4 / 5 | |
| 3.930.0 | 4 / 5 | |
| 3.922.0 | 4 / 5 | |
| 3.921.0 | 4 / 5 | |
| 3.920.0 | 4 / 5 | |
| 3.914.0 | 4 / 5 | |
| 3.910.0 | 4 / 5 | |
| 3.901.0 | 4 / 5 | |
| 3.893.0 | 4 / 5 | |
| 3.892.0 | 4 / 5 | |
| 3.891.0 | 4 / 5 | |
| 3.890.0 | 4 / 5 | |
| 3.887.0 | 4 / 5 | |
| 3.873.0 | 4 / 5 | |
| 3.862.0 | 4 / 5 | |
| 3.840.0 | 4 / 5 | |
| 3.821.0 | 4 / 5 | |
| 3.804.0 | 4 / 5 | |
| 3.796.0 | 4 / 5 | |
| 3.775.0 | 4 / 5 | |
| 3.734.0 | 4 / 5 | |
| 3.731.0 | 4 / 5 | |
| 3.723.0 | 4 / 5 | |
| 3.714.0 | 4 / 5 | |
| 3.713.0 | 4 / 5 | |
| 3.709.0 | 4 / 5 | |
| 3.696.0 | 4 / 5 | |
| 3.693.0 | 4 / 5 | |
| 3.692.0 | 4 / 5 | |
| 3.691.0 | 4 / 5 |
v3.972.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.972.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.972.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.