AWS SDK for JavaScript Bedrock Client for Node.js, Browser and React Native
92%
Total Score
healthy
Frequent releases, active maintainers, and strong project backing outweigh minor workflow pinning and package-mapping gaps.
No build attestation or trusted-publisher provenance was reported, leaving publication origin less independently verifiable despite the package’s strong maintenance evidence.
The linked repository is a monorepo whose name does not match this package and whose README does not mention it directly; this creates a package-to-source mapping concern, although the monorepo structure makes the name mismatch unsurprising.
The repository uses established build and test tooling, including TypeScript and Vitest. No security scanning tools were detected, which is a minor transparency gap.
All 12 workflows were analyzed with no reported audit findings, no untrusted checkouts, and no script-injection paths. Seven of 24 action references are unpinned, creating a limited reproducibility and action-substitution risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
tslib Version ^2.6.2 | — | — |
@smithy/core Version ^3.35.2 | — | — |
@aws-sdk/core Version ^3.978.2 | — | — |
@smithy/types Version ^4.19.0 | — | — |
@aws-sdk/types Version ^3.974.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.