@aws-sdk/token-providers
A collection of token providers
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:tslib | AI (phantom-deps): tslib is a standard implicit dependency in TypeScript ecosystems; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@aws-crypto/sha256-js | AI (phantom-deps): Referenced in config files; framework-scoped loading pattern in AWS SDK monorepo. | ai | |
| phantom-deps | phantom-dep:@smithy/middleware-stack | AI (phantom-deps): Framework-scoped package loaded by convention in Smithy middleware architecture. | ai |
Versions (showing 51 of 386)
| Version | Deps | Published |
|---|---|---|
| 3.1057.0 | 6 / 6 | |
| 3.1056.0 | 6 / 6 | |
| 3.1055.0 | 6 / 6 | |
| 3.1054.0 | 6 / 6 | |
| 3.1053.0 | 6 / 6 | |
| 3.1052.0 | 6 / 6 | |
| 3.1051.0 | 6 / 6 | |
| 3.1050.0 | 6 / 6 | |
| 3.1049.0 | 6 / 6 | |
| 3.1048.0 | 6 / 6 | |
| 3.1047.0 | 6 / 6 | |
| 3.1046.0 | 6 / 6 | |
| 3.1045.0 | 7 / 6 | |
| 3.1044.0 | 7 / 6 | |
| 3.1043.0 | 7 / 6 | |
| 3.1042.0 | 7 / 6 | |
| 3.1041.0 | 7 / 6 | |
| 3.1040.0 | 7 / 6 | |
| 3.1039.0 | 7 / 6 | |
| 3.1038.0 | 7 / 6 | |
| 3.1037.0 | 7 / 6 | |
| 3.1036.0 | 7 / 6 | |
| 3.1035.0 | 7 / 6 | |
| 3.1034.0 | 7 / 6 | |
| 3.1033.0 | 7 / 6 | |
| 3.1032.0 | 7 / 6 | |
| 3.1031.0 | 7 / 6 | |
| 3.1030.0 | 7 / 6 | |
| 3.1029.0 | 7 / 6 | |
| 3.1028.0 | 7 / 6 | |
| 3.1027.0 | 7 / 6 | |
| 3.1026.0 | 7 / 6 | |
| 3.1025.0 | 7 / 6 | |
| 3.1024.0 | 7 / 6 | |
| 3.1023.0 | 7 / 6 | |
| 3.1022.0 | 7 / 6 | |
| 3.1021.0 | 7 / 6 | |
| 3.1020.0 | 7 / 6 | |
| 3.1019.0 | 7 / 6 | |
| 3.1018.0 | 7 / 6 | |
| 3.1017.0 | 7 / 6 | |
| 3.1016.0 | 7 / 6 | |
| 3.1015.0 | 7 / 6 | |
| 3.1014.0 | 7 / 6 | |
| 3.1013.0 | 7 / 6 | |
| 3.1012.0 | 7 / 6 | |
| 3.1011.0 | 7 / 6 | |
| 3.1010.0 | 7 / 6 | |
| 3.1009.0 | 7 / 6 | |
| 3.1008.0 | 7 / 6 | |
| 3.1007.0 | 7 / 6 |
v3.1057.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1056.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1055.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1054.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1053.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1052.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1051.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1050.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1049.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1048.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1047.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1046.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1045.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1044.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1043.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1042.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1041.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1040.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1039.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1038.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1037.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1036.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1035.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.