@aws-sdk/client-cloudcontrol
AWS SDK for JavaScript Cloudcontrol Client for Node.js, Browser and React Native
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | new-deps-added | AI (publish-pattern): @types/uuid is a TypeScript type definition package for the already-present uuid runtime dep; adding it is benign and consistent with normal SDK development practices. | ai | |
| provenance | no-provenance | AI (provenance): aws-sdk-bot is a well-established publisher with 16000+ approved packages; lack of Sigstore provenance is a known characteristic of this publisher and not a meaningful risk signal. | ai | |
| phantom-deps | phantom-dep:@types/uuid | AI (phantom-deps): @types/uuid is a benign TypeScript type definitions package for the uuid runtime dep already present; not a security concern for this package. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): AWS SDK v3 is maintained by aws-sdk-bot; individual maintainer removals reflect normal AWS team changes and do not indicate a takeover for this package. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/util-base64-browser | AI (phantom-deps): AWS SDK v3 packages use convention-based loading for utilities; phantom-dep is a false positive for this architecture. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/middleware-stack | AI (phantom-deps): AWS SDK v3 packages use convention-based loading for middleware; phantom-dep is a false positive for this architecture. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/util-base64-node | AI (phantom-deps): AWS SDK v3 packages use convention-based loading for utilities; phantom-dep is a false positive for this architecture. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/client-sts | AI (phantom-deps): Framework-scoped AWS SDK dependency loaded by convention; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@smithy/middleware-stack | AI (phantom-deps): Framework-scoped Smithy middleware dependency loaded by convention; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/client-sso-oidc | AI (phantom-deps): Framework-scoped AWS SDK dependency loaded by convention; stable pattern for this package. | ai |
Versions (showing 22 of 522)
| Version | Deps | Published |
|---|---|---|
| 3.54.0 | 35 / 9 | |
| 3.53.0 | 35 / 9 | |
| 3.52.0 | 35 / 9 | |
| 3.51.0 | 35 / 9 | |
| 3.50.0 | 35 / 9 | |
| 3.49.0 | 35 / 9 | |
| 3.48.0 | 35 / 3 | |
| 3.47.2 | 35 / 3 | |
| 3.47.1 | 35 / 3 | |
| 3.47.0 | 35 / 3 | |
| 3.46.0 | 33 / 3 | |
| 3.45.0 | 33 / 9 | |
| 3.43.0 | 33 / 9 | |
| 3.42.0 | 33 / 9 | |
| 3.41.0 | 33 / 9 | |
| 3.40.0 | 33 / 9 | |
| 3.39.0 | 33 / 9 | |
| 3.38.0 | 33 / 9 | |
| 3.37.0 | 33 / 9 | |
| 3.36.1 | 33 / 9 | |
| 3.36.0 | 33 / 9 | |
| 3.35.0 | 33 / 9 |
v3.54.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.53.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.52.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.51.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.50.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.49.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.48.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.47.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.47.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.47.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.46.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.45.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.43.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.42.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.41.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.40.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.39.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.38.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.37.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.36.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.36.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.35.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.