
Product
Introducing Reachability for PHP
Reachability analysis for PHP is now available in experimental, helping teams identify which vulnerabilities are actually exploitable.
AWS signing. Originally pulled from LearnBoost/knox, maintained as vendor in request, now a standalone module.
AWS signing. Originally pulled from LearnBoost/knox, maintained as vendor in request, now a standalone module.
The AWS SDK for JavaScript is a comprehensive package that provides a wide range of functionalities for interacting with AWS services, including request signing. Unlike aws-sign2, which focuses solely on signing requests, the AWS SDK offers a broad set of tools for various AWS services, making it more versatile but also larger in size.
aws4 is a package similar to aws-sign2 but for signing requests with AWS Signature Version 4. While aws-sign2 is used for services that require signature version 2, aws4 is necessary for newer AWS services and regions that mandate the use of signature version 4. It offers a similar API for signing requests but is tailored for the updated signature process.
FAQs
AWS signing. Originally pulled from LearnBoost/knox, maintained as vendor in request, now a standalone module.
The npm package aws-sign2 receives a total of 16,849,586 weekly downloads. As such, aws-sign2 popularity was classified as popular.
We found that aws-sign2 demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Product
Reachability analysis for PHP is now available in experimental, helping teams identify which vulnerabilities are actually exploitable.

Product
Export Socket alert data to your own cloud storage in JSON, CSV, or Parquet, with flexible snapshot or incremental delivery.

Research
/Security News
Bitwarden CLI 2026.4.0 was compromised in the Checkmarx supply chain campaign after attackers abused a GitHub Action in Bitwarden’s CI/CD pipeline.