← Home

@aws-sdk/middleware-sdk-sts

[![NPM version](https://img.shields.io/npm/v/@aws-sdk/middleware-sdk-sts/latest.svg)](https://www.npmjs.com/package/@aws-sdk/middleware-sdk-sts) [![NPM downloads](https://img.shields.io/npm/dm/@aws-sdk/middleware-sdk-sts.svg)](https://www.npmjs.com/packag

100
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

amzn-ossaws-sdk-bot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@aws-sdk/middleware-signing AI (dependencies): This is a sibling AWS SDK v3 package published in the same monorepo release cycle at the same version. The dependency pattern is stable and expected for all versions of this package. ai
phantom-deps phantom-dep:@aws-sdk/types AI (phantom-deps): @aws-sdk/types is a framework-scoped package loaded by convention across the AWS SDK v3 ecosystem; stable false positive. ai
bogus-package bogus-package AI (bogus-package): Short README and no keywords are typical for internal AWS SDK v3 middleware packages; not spam indicators. ai
phantom-deps phantom-dep:tslib AI (phantom-deps): tslib is a standard implicit dependency across all AWS SDK v3 packages; not a real phantom dep concern. ai
phantom-deps phantom-dep:@aws-sdk/signature-v4 AI (phantom-deps): Declared dependency in AWS SDK monorepo; loaded by convention within SDK architecture. ai
phantom-deps phantom-dep:@aws-sdk/protocol-http AI (phantom-deps): Declared dependency in AWS SDK monorepo; loaded by convention within SDK architecture. ai
phantom-deps phantom-dep:@aws-sdk/property-provider AI (phantom-deps): Declared dependency in AWS SDK monorepo; loaded by convention within SDK architecture. ai

Versions (showing 100 of 200)

Version Deps Published
3.972.13 4 / 5
3.972.12 4 / 5
3.972.11 4 / 5
3.972.10 4 / 5
3.972.9 4 / 5
3.972.8 4 / 5
3.972.7 4 / 5
3.972.6 4 / 5
3.972.5 4 / 5
3.972.4 4 / 5
3.972.3 4 / 5
3.972.2 4 / 5
3.972.1 4 / 5
3.972.0 4 / 5
3.971.0 4 / 5
3.969.0 4 / 5
3.968.0 4 / 5
3.965.0 4 / 5
3.957.0 4 / 5
3.956.0 4 / 5
3.953.0 4 / 5
3.936.0 4 / 5
3.930.0 4 / 5
3.922.0 4 / 5
3.921.0 4 / 5
3.920.0 4 / 5
3.914.0 4 / 5
3.910.0 4 / 5
3.901.0 4 / 5
3.893.0 4 / 5
3.892.0 4 / 5
3.891.0 4 / 5
3.890.0 4 / 5
3.887.0 4 / 5
3.873.0 4 / 5
3.862.0 4 / 5
3.840.0 4 / 5
3.821.0 4 / 5
3.804.0 4 / 5
3.796.0 4 / 5
3.775.0 4 / 5
3.734.0 4 / 5
3.731.0 4 / 5
3.723.0 4 / 5
3.714.0 4 / 5
3.713.0 4 / 5
3.709.0 4 / 5
3.696.0 4 / 5
3.693.0 4 / 5
3.692.0 4 / 5
3.691.0 4 / 5
3.686.0 4 / 5
3.679.0 4 / 5
3.667.0 4 / 5
3.664.0 4 / 5
3.662.0 4 / 5
3.658.1 4 / 5
3.654.0 4 / 5
3.649.0 4 / 5
3.620.0 4 / 5
3.616.0 4 / 5
3.609.0 4 / 5
3.598.0 4 / 5
3.587.0 4 / 5
3.577.0 4 / 5
3.575.0 4 / 5
3.572.0 4 / 5
3.567.0 4 / 5
3.556.0 4 / 5
3.552.0 4 / 5
3.535.0 4 / 5
3.534.0 4 / 5
3.533.0 4 / 5
3.523.0 4 / 5
3.521.0 4 / 5
3.515.0 4 / 5
3.511.0 4 / 5
3.502.0 4 / 5
3.496.0 4 / 5
3.495.0 4 / 5
3.489.0 4 / 5
3.485.0 4 / 5
3.468.0 4 / 5
3.465.0 4 / 5
3.461.0 4 / 6
3.460.0 4 / 6
3.451.0 4 / 6
3.449.0 4 / 6
3.433.0 4 / 6
3.428.0 4 / 6
3.425.0 4 / 6
3.418.0 4 / 6
3.413.0 4 / 6
3.410.0 4 / 6
3.408.0 4 / 6
3.398.0 4 / 6
3.391.0 4 / 6
3.387.0 4 / 6
3.379.1 4 / 6
3.378.0 4 / 6
Showing 100 of 200 Next page →

v3.972.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.972.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.972.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.