@aws-sdk/middleware-endpoint-discovery
[](https://www.npmjs.com/package/@aws-sdk/middleware-endpoint-discovery) [ relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:tslib | AI (phantom-deps): tslib is a standard TypeScript runtime helper used implicitly by compiled AWS SDK output; not a real phantom dep for this package family. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/types | AI (phantom-deps): @aws-sdk/types is a framework-scoped types package loaded by convention across all AWS SDK v3 packages; stable false positive. | ai | |
| bogus-package | bogus-package | AI (bogus-package): AWS SDK internal utility packages routinely lack keywords and detailed READMEs; not indicative of spam or malicious intent. | ai |
Versions (showing 39 of 39)
| Version | Deps | Published |
|---|---|---|
| 3.972.12 | 5 / 5 | |
| 3.972.11 | 6 / 5 | |
| 3.972.10 | 6 / 5 | |
| 3.972.9 | 6 / 5 | |
| 3.972.8 | 6 / 5 | |
| 3.972.7 | 6 / 5 | |
| 3.972.6 | 6 / 5 | |
| 3.972.5 | 6 / 5 | |
| 3.972.4 | 6 / 5 | |
| 3.972.3 | 6 / 5 | |
| 3.972.2 | 6 / 5 | |
| 3.972.1 | 6 / 5 | |
| 3.972.0 | 6 / 5 | |
| 3.971.0 | 6 / 5 | |
| 3.969.0 | 6 / 5 | |
| 3.968.0 | 6 / 5 | |
| 3.965.0 | 6 / 5 | |
| 3.957.0 | 6 / 5 | |
| 3.956.0 | 6 / 5 | |
| 3.953.0 | 6 / 5 | |
| 3.936.0 | 6 / 5 | |
| 3.930.0 | 6 / 5 | |
| 3.922.0 | 6 / 5 | |
| 3.921.0 | 6 / 5 | |
| 3.920.0 | 6 / 5 | |
| 3.914.0 | 6 / 5 | |
| 3.910.0 | 6 / 5 | |
| 3.901.0 | 6 / 5 | |
| 3.893.0 | 6 / 5 | |
| 3.891.0 | 6 / 5 | |
| 3.890.0 | 6 / 5 | |
| 3.887.0 | 6 / 5 | |
| 3.873.0 | 6 / 5 | |
| 3.862.0 | 6 / 5 | |
| 3.840.0 | 6 / 5 | |
| 3.821.0 | 6 / 5 | |
| 3.808.0 | 6 / 5 | |
| 3.806.0 | 6 / 5 | |
| 3.804.0 | 6 / 5 |
v3.972.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.972.11
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.972.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.972.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.972.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.972.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.972.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.972.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.972.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.972.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.972.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.972.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.972.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.971.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.969.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.968.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.965.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.957.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.956.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.953.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.936.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.930.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.922.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.921.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.920.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.914.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.910.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.901.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.893.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.891.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.890.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.887.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.873.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.862.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.840.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.821.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.808.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.806.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.804.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.