@aws-sdk/client-cloudfront
AWS SDK for JavaScript Cloudfront Client for Node.js, Browser and React Native
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist-es/schemas/schemas_0.js | AI (source-diff): AWS SDK v3 uses short constant aliases for XML/JSON field names to reduce bundle size. This is a documented pattern across all AWS SDK v3 clients, not obfuscation. | ai | |
| source-diff | large-new-source-files | AI (source-diff): AWS SDK clients regularly add new source files as AWS APIs expand. 66 new files is consistent with CloudFront API growth (new features visible in schema sample). | ai | |
| dependencies | unvetted-dep:@aws-crypto/sha256-js | AI (dependencies): Official AWS crypto library, part of the AWS SDK v3 ecosystem. | ai | |
| dependencies | unvetted-dep:@smithy/smithy-client | AI (dependencies): First-party Smithy client library, standard AWS SDK v3 dependency. | ai | |
| dependencies | unvetted-dep:@aws-sdk/util-endpoints | AI (dependencies): First-party AWS SDK v3 utility package from the same publisher. | ai | |
| dependencies | unvetted-dep:@smithy/middleware-retry | AI (dependencies): First-party Smithy middleware, standard AWS SDK v3 dependency. | ai | |
| dependencies | unvetted-dep:@smithy/middleware-serde | AI (dependencies): First-party Smithy middleware, standard AWS SDK v3 dependency. | ai | |
| dependencies | unvetted-dep:@aws-crypto/sha256-browser | AI (dependencies): Official AWS crypto library for browser environments, part of AWS SDK v3 ecosystem. | ai | |
| dependencies | unvetted-dep:@aws-sdk/middleware-logger | AI (dependencies): First-party AWS SDK v3 middleware package from the same publisher. | ai | |
| dependencies | unvetted-dep:@smithy/middleware-endpoint | AI (dependencies): First-party Smithy middleware, standard AWS SDK v3 dependency. | ai | |
| dependencies | unvetted-dep:@smithy/core | AI (dependencies): First-party AWS/Smithy SDK dependency; standard building block of AWS SDK v3 architecture. | ai | |
| dependencies | unvetted-dep:@aws-sdk/middleware-user-agent | AI (dependencies): First-party AWS SDK v3 middleware package from the same publisher. | ai | |
| dependencies | unvetted-dep:@aws-sdk/middleware-host-header | AI (dependencies): First-party AWS SDK v3 middleware package from the same publisher. | ai | |
| dependencies | unvetted-dep:@smithy/util-defaults-mode-node | AI (dependencies): First-party Smithy utility, standard AWS SDK v3 dependency. | ai | |
| dependencies | unvetted-dep:@aws-sdk/credential-provider-node | AI (dependencies): First-party AWS SDK v3 credential provider from the same publisher. | ai | |
| dependencies | unvetted-dep:@smithy/util-defaults-mode-browser | AI (dependencies): First-party Smithy utility for browser environments, standard AWS SDK v3 dependency. | ai | |
| phantom-deps | phantom-dep:@smithy/middleware-serde | AI (phantom-deps): Framework-scoped package loaded by convention in AWS SDK v3; expected pattern for Smithy middleware. | ai | |
| phantom-deps | phantom-dep:@smithy/middleware-stack | AI (phantom-deps): Framework-scoped package loaded by convention in AWS SDK v3; expected pattern for Smithy middleware. | ai | |
| provenance | no-provenance | AI (provenance): AWS SDK bot does not currently publish with Sigstore provenance; consistent across all AWS SDK v3 packages. | ai | |
| dependencies | unvetted-dep:@aws-sdk/util-user-agent-node | AI (dependencies): First-party AWS SDK v3 utility package from the same publisher. | ai | |
| dependencies | unvetted-dep:@aws-sdk/core | AI (dependencies): First-party AWS SDK v3 core package published by the same aws-sdk-bot publisher. | ai |
Versions (showing 51 of 579)
| Version | Deps | Published |
|---|---|---|
| 3.1046.0 | 18 / 8 | |
| 3.1045.0 | 41 / 8 | |
| 3.1044.0 | 41 / 8 | |
| 3.1043.0 | 41 / 8 | |
| 3.1042.0 | 41 / 8 | |
| 3.1041.0 | 41 / 8 | |
| 3.1040.0 | 41 / 8 | |
| 3.1039.0 | 41 / 8 | |
| 3.1038.0 | 41 / 8 | |
| 3.1037.0 | 41 / 8 | |
| 3.1036.0 | 41 / 8 | |
| 3.1035.0 | 41 / 8 | |
| 3.1034.0 | 41 / 6 | |
| 3.1033.0 | 41 / 6 | |
| 3.1032.0 | 41 / 6 | |
| 3.1031.0 | 41 / 6 | |
| 3.1030.0 | 41 / 6 | |
| 3.1029.0 | 41 / 6 | |
| 3.1028.0 | 41 / 6 | |
| 3.1027.0 | 41 / 6 | |
| 3.1026.0 | 41 / 6 | |
| 3.1025.0 | 41 / 6 | |
| 3.1024.0 | 41 / 6 | |
| 3.1023.0 | 41 / 6 | |
| 3.1022.0 | 41 / 6 | |
| 3.1021.0 | 41 / 6 | |
| 3.1020.0 | 41 / 6 | |
| 3.1019.0 | 41 / 6 | |
| 3.1018.0 | 41 / 6 | |
| 3.1017.0 | 41 / 6 | |
| 3.1016.0 | 41 / 6 | |
| 3.1015.0 | 41 / 6 | |
| 3.1014.0 | 41 / 6 | |
| 3.1013.0 | 41 / 6 | |
| 3.1012.0 | 41 / 6 | |
| 3.1011.0 | 41 / 6 | |
| 3.1010.0 | 41 / 6 | |
| 3.1009.0 | 41 / 6 | |
| 3.1008.0 | 41 / 6 | |
| 3.1007.0 | 41 / 6 | |
| 3.1006.0 | 41 / 6 | |
| 3.1005.0 | 41 / 6 | |
| 3.1004.0 | 41 / 6 | |
| 3.1003.0 | 41 / 6 | |
| 3.1002.0 | 41 / 6 | |
| 3.1001.0 | 41 / 6 | |
| 3.1000.0 | 41 / 6 | |
| 3.999.0 | 41 / 6 | |
| 3.998.0 | 41 / 6 | |
| 3.997.0 | 41 / 6 | |
| 3.996.0 | 41 / 6 |
v3.1046.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1045.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1044.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1043.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1042.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1041.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1040.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1039.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1038.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1037.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1036.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1035.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1034.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1033.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1032.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1031.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1030.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1029.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1028.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1027.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1026.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1025.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1024.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1023.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1022.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1021.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1020.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1019.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1018.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1017.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1016.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1015.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1014.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1013.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1012.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1011.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1010.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1009.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1008.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1007.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1006.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1005.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1004.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1003.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1002.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1001.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1000.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.999.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.998.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.997.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.996.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.