@aws-sdk/types
Types for the AWS SDK
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-removed | AI (maintainer-change): AWS SDK team consolidates maintainers over time under aws-sdk-bot; removal of individual maintainers is a known pattern for this package family, not a takeover signal. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): tslib and @smithy/types are legitimate AWS/TypeScript ecosystem packages added as part of the AWS SDK v3 Smithy refactor; not a supply chain risk. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Diff is against a very old version (v3.12.0); 121 new files reflect legitimate accumulated development across 189 versions of an active AWS SDK package. | ai | |
| source-diff | source-size-dropped | AI (source-diff): Size reduction reflects intentional AWS SDK v3 refactoring where types were extracted into @smithy/types; this package now delegates to that, making it legitimately smaller. | ai | |
| phantom-deps | phantom-dep:tslib | AI (phantom-deps): tslib is a standard TypeScript runtime helper; phantom-dep false positive is stable for all TypeScript packages including this one. | ai | |
| provenance | no-provenance | AI (provenance): aws-sdk-bot is a well-established automated publisher; lack of Sigstore provenance is consistent across all AWS SDK packages and not a risk signal here. | ai | |
| bogus-package | bogus-package | AI (bogus-package): This is the official AWS SDK types package with 97 approved-dep edges; README/keyword signals are stable false positives for this package. | ai |
Versions (showing 100 of 164)
| Version | Deps | Published |
|---|---|---|
| 3.973.13 | 2 / 5 | |
| 3.973.12 | 2 / 5 | |
| 3.973.11 | 2 / 5 | |
| 3.973.10 | 2 / 5 | |
| 3.973.9 | 2 / 5 | |
| 3.973.8 | 2 / 5 | |
| 3.973.7 | 2 / 5 | |
| 3.973.6 | 2 / 5 | |
| 3.973.5 | 2 / 5 | |
| 3.973.4 | 2 / 5 | |
| 3.973.3 | 2 / 5 | |
| 3.973.2 | 2 / 5 | |
| 3.973.1 | 2 / 5 | |
| 3.973.0 | 2 / 5 | |
| 3.972.0 | 2 / 5 | |
| 3.969.0 | 2 / 5 | |
| 3.968.0 | 2 / 5 | |
| 3.965.0 | 2 / 5 | |
| 3.957.0 | 2 / 5 | |
| 3.956.0 | 2 / 5 | |
| 3.953.0 | 2 / 5 | |
| 3.936.0 | 2 / 5 | |
| 3.930.0 | 2 / 5 | |
| 3.922.0 | 2 / 5 | |
| 3.921.0 | 2 / 5 | |
| 3.920.0 | 2 / 5 | |
| 3.914.0 | 2 / 5 | |
| 3.910.0 | 2 / 5 | |
| 3.901.0 | 2 / 5 | |
| 3.893.0 | 2 / 5 | |
| 3.887.0 | 2 / 5 | |
| 3.862.0 | 2 / 5 | |
| 3.840.0 | 2 / 5 | |
| 3.821.0 | 2 / 5 | |
| 3.804.0 | 2 / 5 | |
| 3.775.0 | 2 / 5 | |
| 3.734.0 | 2 / 5 | |
| 3.731.0 | 2 / 5 | |
| 3.723.0 | 2 / 5 | |
| 3.714.0 | 2 / 5 | |
| 3.713.0 | 2 / 5 | |
| 3.709.0 | 2 / 5 | |
| 3.696.0 | 2 / 5 | |
| 3.692.0 | 2 / 5 | |
| 3.686.0 | 2 / 5 | |
| 3.679.0 | 2 / 5 | |
| 3.667.0 | 2 / 5 | |
| 3.664.0 | 2 / 5 | |
| 3.662.0 | 2 / 5 | |
| 3.654.0 | 2 / 5 | |
| 3.649.0 | 2 / 5 | |
| 3.609.0 | 2 / 5 | |
| 3.598.0 | 2 / 5 | |
| 3.577.0 | 2 / 5 | |
| 3.575.0 | 2 / 5 | |
| 3.567.0 | 2 / 5 | |
| 3.535.0 | 2 / 5 | |
| 3.533.0 | 2 / 5 | |
| 3.523.0 | 2 / 5 | |
| 3.521.0 | 2 / 5 | |
| 3.515.0 | 2 / 5 | |
| 3.511.0 | 2 / 5 | |
| 3.502.0 | 2 / 5 | |
| 3.496.0 | 2 / 5 | |
| 3.495.0 | 2 / 5 | |
| 3.489.0 | 2 / 5 | |
| 3.485.0 | 2 / 5 | |
| 3.468.0 | 2 / 5 | |
| 3.465.0 | 2 / 5 | |
| 3.460.0 | 2 / 6 | |
| 3.451.0 | 2 / 6 | |
| 3.449.0 | 2 / 6 | |
| 3.433.0 | 2 / 6 | |
| 3.428.0 | 2 / 6 | |
| 3.425.0 | 2 / 6 | |
| 3.418.0 | 2 / 6 | |
| 3.413.0 | 2 / 6 | |
| 3.410.0 | 2 / 6 | |
| 3.408.0 | 2 / 6 | |
| 3.398.0 | 2 / 6 | |
| 3.391.0 | 2 / 6 | |
| 3.387.0 | 2 / 6 | |
| 3.378.0 | 2 / 6 | |
| 3.370.0 | 2 / 6 | |
| 3.369.0 | 2 / 6 | |
| 3.357.0 | 1 / 6 | |
| 3.347.0 | 1 / 6 | |
| 3.342.0 | 1 / 6 | |
| 3.341.0 | 1 / 6 | |
| 3.338.0 | 1 / 6 | |
| 3.337.0 | 1 / 6 | |
| 3.329.0 | 1 / 6 | |
| 3.310.0 | 1 / 6 | |
| 3.306.0 | 1 / 6 | |
| 3.303.0 | 1 / 6 | |
| 3.296.0 | 1 / 6 | |
| 3.295.0 | 1 / 6 | |
| 3.292.0 | 1 / 6 | |
| 3.290.0 | 1 / 6 | |
| 3.289.0 | 1 / 6 |
v3.973.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.973.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.973.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.973.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.973.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.