@aws-sdk/token-providers
A collection of token providers
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:tslib | AI (phantom-deps): tslib is a standard implicit dependency in TypeScript ecosystems; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@aws-crypto/sha256-js | AI (phantom-deps): Referenced in config files; framework-scoped loading pattern in AWS SDK monorepo. | ai | |
| phantom-deps | phantom-dep:@smithy/middleware-stack | AI (phantom-deps): Framework-scoped package loaded by convention in Smithy middleware architecture. | ai |
Versions (showing 100 of 386)
| Version | Deps | Published |
|---|---|---|
| 3.686.0 | 5 / 6 | |
| 3.679.0 | 5 / 6 | |
| 3.667.0 | 5 / 6 | |
| 3.664.0 | 5 / 6 | |
| 3.662.0 | 5 / 6 | |
| 3.654.0 | 5 / 6 | |
| 3.649.0 | 5 / 6 | |
| 3.614.0 | 5 / 6 | |
| 3.609.0 | 5 / 6 | |
| 3.598.0 | 5 / 6 | |
| 3.587.0 | 5 / 6 | |
| 3.577.0 | 5 / 6 | |
| 3.575.0 | 5 / 6 | |
| 3.572.0 | 5 / 6 | |
| 3.568.0 | 5 / 6 | |
| 3.567.0 | 5 / 6 | |
| 3.565.0 | 5 / 6 | |
| 3.564.0 | 6 / 6 | |
| 3.556.0 | 6 / 6 | |
| 3.554.0 | 6 / 6 | |
| 3.552.0 | 6 / 6 | |
| 3.549.0 | 6 / 6 | |
| 3.540.0 | 6 / 6 | |
| 3.535.0 | 6 / 6 | |
| 3.533.0 | 6 / 6 | |
| 3.529.1 | 6 / 6 | |
| 3.529.0 | 6 / 6 | |
| 3.525.0 | 6 / 6 | |
| 3.523.0 | 6 / 6 | |
| 3.521.0 | 6 / 6 | |
| 3.515.0 | 6 / 6 | |
| 3.513.0 | 6 / 6 | |
| 3.511.0 | 6 / 6 | |
| 3.507.0 | 6 / 6 | |
| 3.504.0 | 6 / 6 | |
| 3.502.0 | 6 / 6 | |
| 3.501.0 | 37 / 6 | |
| 3.496.0 | 37 / 6 | |
| 3.495.0 | 37 / 6 | |
| 3.489.0 | 37 / 6 | |
| 3.485.0 | 37 / 6 | |
| 3.484.0 | 37 / 6 | |
| 3.481.0 | 37 / 6 | |
| 3.478.0 | 37 / 6 | |
| 3.470.0 | 37 / 6 | |
| 3.468.0 | 37 / 6 | |
| 3.465.0 | 37 / 6 | |
| 3.460.0 | 37 / 7 | |
| 3.451.0 | 37 / 7 | |
| 3.449.0 | 37 / 7 | |
| 3.438.0 | 37 / 7 | |
| 3.437.0 | 36 / 7 | |
| 3.435.0 | 36 / 7 | |
| 3.433.0 | 35 / 7 | |
| 3.431.0 | 35 / 7 | |
| 3.430.0 | 35 / 7 | |
| 3.429.0 | 35 / 7 | |
| 3.428.0 | 35 / 7 | |
| 3.427.0 | 35 / 7 | |
| 3.425.0 | 35 / 7 | |
| 3.418.0 | 35 / 7 | |
| 3.413.0 | 35 / 7 | |
| 3.410.0 | 35 / 7 | |
| 3.408.0 | 35 / 7 | |
| 3.405.0 | 35 / 7 | |
| 3.398.0 | 35 / 7 | |
| 3.391.0 | 35 / 7 | |
| 3.388.0 | 35 / 7 | |
| 3.387.0 | 5 / 7 | |
| 3.386.0 | 5 / 7 | |
| 3.385.0 | 5 / 7 | |
| 3.382.0 | 6 / 7 | |
| 3.379.1 | 6 / 7 | |
| 3.378.0 | 6 / 7 | |
| 3.370.0 | 6 / 7 | |
| 3.369.0 | 6 / 7 | |
| 3.363.0 | 6 / 7 | |
| 3.362.0 | 5 / 7 | |
| 3.360.0 | 5 / 7 | |
| 3.358.0 | 5 / 7 | |
| 3.357.0 | 5 / 7 | |
| 3.354.0 | 5 / 7 | |
| 3.353.0 | 5 / 7 | |
| 3.352.0 | 5 / 7 | |
| 3.350.0 | 5 / 7 | |
| 3.348.0 | 5 / 7 | |
| 3.347.0 | 5 / 7 | |
| 3.345.0 | 5 / 7 | |
| 3.344.0 | 5 / 7 | |
| 3.342.0 | 5 / 7 | |
| 3.341.0 | 5 / 7 | |
| 3.338.0 | 5 / 7 | |
| 3.337.0 | 5 / 7 | |
| 3.335.0 | 5 / 7 | |
| 3.332.0 | 5 / 7 | |
| 3.329.0 | 5 / 7 | |
| 3.328.0 | 5 / 7 | |
| 3.327.0 | 5 / 7 | |
| 3.326.0 | 5 / 7 | |
| 3.325.0 | 5 / 7 |
v3.556.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.554.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.552.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.549.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.540.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.535.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.533.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.529.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.529.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.525.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.523.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.521.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.515.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.513.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.511.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.507.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.504.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.502.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.501.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.496.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.495.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.489.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.485.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.484.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.481.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.478.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.470.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.468.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.465.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.460.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.451.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.449.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.438.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.437.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.435.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.433.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.431.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.430.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.429.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.428.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.427.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.425.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.418.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.413.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.410.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.408.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.405.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.398.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.391.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.388.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.387.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.386.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.385.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.382.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.379.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.378.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.370.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.369.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.363.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.362.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.360.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.358.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.357.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.354.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.353.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.352.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.350.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.348.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.347.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.345.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.344.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.342.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.341.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.338.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.337.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.335.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.332.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.329.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.328.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.327.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.326.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.325.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.