← Home

@aws-sdk/client-cloudfront

AWS SDK for JavaScript Cloudfront Client for Node.js, Browser and React Native

51
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

amzn-ossaws-sdk-bot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist-es/schemas/schemas_0.js AI (source-diff): AWS SDK v3 uses short constant aliases for XML/JSON field names to reduce bundle size. This is a documented pattern across all AWS SDK v3 clients, not obfuscation. ai
source-diff large-new-source-files AI (source-diff): AWS SDK clients regularly add new source files as AWS APIs expand. 66 new files is consistent with CloudFront API growth (new features visible in schema sample). ai
dependencies unvetted-dep:@aws-crypto/sha256-js AI (dependencies): Official AWS crypto library, part of the AWS SDK v3 ecosystem. ai
dependencies unvetted-dep:@smithy/smithy-client AI (dependencies): First-party Smithy client library, standard AWS SDK v3 dependency. ai
dependencies unvetted-dep:@aws-sdk/util-endpoints AI (dependencies): First-party AWS SDK v3 utility package from the same publisher. ai
dependencies unvetted-dep:@smithy/middleware-retry AI (dependencies): First-party Smithy middleware, standard AWS SDK v3 dependency. ai
dependencies unvetted-dep:@smithy/middleware-serde AI (dependencies): First-party Smithy middleware, standard AWS SDK v3 dependency. ai
dependencies unvetted-dep:@aws-crypto/sha256-browser AI (dependencies): Official AWS crypto library for browser environments, part of AWS SDK v3 ecosystem. ai
dependencies unvetted-dep:@aws-sdk/middleware-logger AI (dependencies): First-party AWS SDK v3 middleware package from the same publisher. ai
dependencies unvetted-dep:@smithy/middleware-endpoint AI (dependencies): First-party Smithy middleware, standard AWS SDK v3 dependency. ai
dependencies unvetted-dep:@smithy/core AI (dependencies): First-party AWS/Smithy SDK dependency; standard building block of AWS SDK v3 architecture. ai
dependencies unvetted-dep:@aws-sdk/middleware-user-agent AI (dependencies): First-party AWS SDK v3 middleware package from the same publisher. ai
dependencies unvetted-dep:@aws-sdk/middleware-host-header AI (dependencies): First-party AWS SDK v3 middleware package from the same publisher. ai
dependencies unvetted-dep:@smithy/util-defaults-mode-node AI (dependencies): First-party Smithy utility, standard AWS SDK v3 dependency. ai
dependencies unvetted-dep:@aws-sdk/credential-provider-node AI (dependencies): First-party AWS SDK v3 credential provider from the same publisher. ai
dependencies unvetted-dep:@smithy/util-defaults-mode-browser AI (dependencies): First-party Smithy utility for browser environments, standard AWS SDK v3 dependency. ai
phantom-deps phantom-dep:@smithy/middleware-serde AI (phantom-deps): Framework-scoped package loaded by convention in AWS SDK v3; expected pattern for Smithy middleware. ai
phantom-deps phantom-dep:@smithy/middleware-stack AI (phantom-deps): Framework-scoped package loaded by convention in AWS SDK v3; expected pattern for Smithy middleware. ai
provenance no-provenance AI (provenance): AWS SDK bot does not currently publish with Sigstore provenance; consistent across all AWS SDK v3 packages. ai
dependencies unvetted-dep:@aws-sdk/util-user-agent-node AI (dependencies): First-party AWS SDK v3 utility package from the same publisher. ai
dependencies unvetted-dep:@aws-sdk/core AI (dependencies): First-party AWS SDK v3 core package published by the same aws-sdk-bot publisher. ai

Versions (showing 51 of 579)

View all versions
Version Deps Published
3.1046.0 18 / 8
3.1045.0 41 / 8
3.1044.0 41 / 8
3.1043.0 41 / 8
3.1042.0 41 / 8
3.1041.0 41 / 8
3.1040.0 41 / 8
3.1039.0 41 / 8
3.1038.0 41 / 8
3.1037.0 41 / 8
3.1036.0 41 / 8
3.1035.0 41 / 8
3.1034.0 41 / 6
3.1033.0 41 / 6
3.1032.0 41 / 6
3.1031.0 41 / 6
3.1030.0 41 / 6
3.1029.0 41 / 6
3.1028.0 41 / 6
3.1027.0 41 / 6
3.1026.0 41 / 6
3.1025.0 41 / 6
3.1024.0 41 / 6
3.1023.0 41 / 6
3.1022.0 41 / 6
3.1021.0 41 / 6
3.1020.0 41 / 6
3.1019.0 41 / 6
3.1018.0 41 / 6
3.1017.0 41 / 6
3.1016.0 41 / 6
3.1015.0 41 / 6
3.1014.0 41 / 6
3.1013.0 41 / 6
3.1012.0 41 / 6
3.1011.0 41 / 6
3.1010.0 41 / 6
3.1009.0 41 / 6
3.1008.0 41 / 6
3.1007.0 41 / 6
3.1006.0 41 / 6
3.1005.0 41 / 6
3.1004.0 41 / 6
3.1003.0 41 / 6
3.1002.0 41 / 6
3.1001.0 41 / 6
3.1000.0 41 / 6
3.999.0 41 / 6
3.998.0 41 / 6
3.997.0 41 / 6
3.996.0 41 / 6

v3.1046.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1045.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1044.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1043.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1042.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1041.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1040.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1039.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1038.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1037.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1036.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1035.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1034.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1033.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1032.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1031.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1030.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1029.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1028.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1027.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1026.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1025.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1024.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1023.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1022.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1021.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1020.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1019.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1018.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1017.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1016.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1015.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1014.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1013.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1012.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1011.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1010.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1009.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1008.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1007.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1006.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1005.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1004.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1003.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1002.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1001.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1000.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.999.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.998.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.997.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.996.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.