← Home

@storybook/nextjs

Storybook for Next.js: Develop, document, and test UI components in isolation

51
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

ndelangenshilmantmeasdayghengeveldwinkervsbecksyannbfkylegachjreinholdkasperpeulenvalentinpalkovicdomyenstorybook-bot

Keywords

storybooknextnext.jswebpackcomponentcomponents

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@storybook/preview-api AI (phantom-deps): Same-org storybook dep; phantom-dep heuristic unreliable for peer/transitive usage patterns. ai
phantom-deps phantom-dep:@storybook/node-logger AI (phantom-deps): Same-org storybook dep; phantom-dep heuristic unreliable for peer/transitive usage patterns. ai
phantom-deps phantom-dep:@types/node AI (phantom-deps): Type-only dep; not directly imported at runtime, stable false positive for this package. ai
source-diff obfuscated-file:dist/preview.mjs AI (source-diff): Standard minified ESM bundle output for this Storybook framework package; not obfuscation. ai
phantom-deps phantom-dep:find-up AI (phantom-deps): Legitimate runtime dep used indirectly via config resolution; stable false positive for this package. ai
phantom-deps phantom-dep:ts-dedent AI (phantom-deps): Legitimate dep used indirectly; stable false positive for this package. ai
phantom-deps phantom-dep:pnp-webpack-plugin AI (phantom-deps): Webpack plugin referenced via config, not direct import; stable false positive for this package. ai
source-diff obfuscated-file:dist/index.mjs AI (source-diff): Standard bundled/minified dist output for @storybook/nextjs; code content is clearly Storybook React internals. ai
source-diff obfuscated-file:dist/next-image-loader-stub.mjs AI (source-diff): Bundled dist file containing sharp/image-size internals; expected for Next.js image loader stub. ai
bogus-package bogus-package AI (bogus-package): Framework adapter with minimal README; delegates to storybook docs. Not a spam indicator. ai
phantom-deps phantom-dep:@babel/plugin-transform-export-namespace-from AI (phantom-deps): Babel plugin loaded by convention in framework integration; stable pattern. ai
phantom-deps phantom-dep:@babel/plugin-transform-object-rest-spread AI (phantom-deps): Babel plugin loaded by convention in framework integration; stable pattern. ai
phantom-deps phantom-dep:@babel/preset-react AI (phantom-deps): Babel preset loaded by convention. ai
phantom-deps phantom-dep:@babel/preset-typescript AI (phantom-deps): Babel preset loaded by convention. ai
phantom-deps phantom-dep:@babel/plugin-syntax-bigint AI (phantom-deps): Babel plugin loaded by convention. ai
phantom-deps phantom-dep:@babel/plugin-transform-runtime AI (phantom-deps): Babel plugin loaded by convention. ai
typosquat typosquat.levenshtein:next AI (typosquat): @storybook/nextjs is the official Storybook framework for Next.js, not a typosquat. ai
phantom-deps phantom-dep:@babel/plugin-syntax-import-assertions AI (phantom-deps): Babel plugin loaded by convention. ai
phantom-deps phantom-dep:@babel/plugin-transform-class-properties AI (phantom-deps): Babel plugin loaded by convention. ai
phantom-deps phantom-dep:@babel/plugin-transform-numeric-separator AI (phantom-deps): Babel plugin loaded by convention. ai
phantom-deps phantom-dep:@babel/plugin-syntax-dynamic-import AI (phantom-deps): Babel plugin loaded by convention. ai
phantom-deps phantom-dep:postcss AI (phantom-deps): Webpack/build tool deps referenced by config convention, not direct imports — stable pattern for this package. ai
phantom-deps phantom-dep:css-loader AI (phantom-deps): Webpack loader referenced by config convention. ai
phantom-deps phantom-dep:sass-loader AI (phantom-deps): Webpack loader referenced by config convention. ai
phantom-deps phantom-dep:babel-loader AI (phantom-deps): Webpack loader referenced by config convention. ai
phantom-deps phantom-dep:style-loader AI (phantom-deps): Webpack loader referenced by config convention. ai
phantom-deps phantom-dep:react-refresh AI (phantom-deps): Referenced by webpack config convention in this framework package. ai
phantom-deps phantom-dep:postcss-loader AI (phantom-deps): Webpack loader referenced by config convention. ai
phantom-deps phantom-dep:resolve-url-loader AI (phantom-deps): Webpack loader referenced by config convention. ai
phantom-deps phantom-dep:@types/semver AI (phantom-deps): Type-only package, loaded by convention. ai
phantom-deps phantom-dep:@babel/runtime AI (phantom-deps): Framework-scoped babel runtime, loaded by convention. ai
phantom-deps phantom-dep:@babel/preset-env AI (phantom-deps): Babel preset loaded by convention in this framework. ai

Versions (showing 51 of 62)

View all versions
Version Deps Published
10.4.1 33 / 10
10.4.0 33 / 10
10.3.6 33 / 10
10.3.5 33 / 10
10.3.4 33 / 10
10.3.3 33 / 10
10.3.2 33 / 10
10.3.1 33 / 10
10.3.0 33 / 10
10.2.19 33 / 10
10.2.18 33 / 10
10.2.17 33 / 10
10.2.16 33 / 10
10.2.15 33 / 10
10.2.14 33 / 10
10.2.13 33 / 10
10.2.12 33 / 10
10.2.11 33 / 10
10.2.10 33 / 10
10.2.9 33 / 10
10.2.8 33 / 10
10.2.7 33 / 10
10.2.6 33 / 10
10.2.5 33 / 10
10.2.4 33 / 10
10.2.3 33 / 10
10.2.2 33 / 10
10.2.1 33 / 10
10.2.0 33 / 10
10.1.11 33 / 10
10.1.10 33 / 10
10.1.9 33 / 10
10.1.8 33 / 10
10.1.7 33 / 10
10.1.6 33 / 10
10.1.5 33 / 10
10.1.4 33 / 10
10.1.3 33 / 10
10.1.2 33 / 10
10.1.1 33 / 10
10.1.0 33 / 10
10.0.8 33 / 10
10.0.7 33 / 10
10.0.6 33 / 10
10.0.5 33 / 10
10.0.4 33 / 10
10.0.3 33 / 10
10.0.2 33 / 10
10.0.1 33 / 10
10.0.0 33 / 10
9.1.20 33 / 10

v10.4.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.3.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.3.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v10.3.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v10.3.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.3.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.3.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.2.19

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.2.18

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.2.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.2.16

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.2.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.2.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.2.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.2.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.2.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.2.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.2.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.2.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.2.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.2.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.2.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.2.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.2.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.2.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.2.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.1.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.1.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.1.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.1.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.1.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.1.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.1.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.1.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.1.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.0.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.0.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.0.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.0.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.0.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v10.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v10.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v10.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v10.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v9.1.20

3 findings
HIGH New obfuscated file: dist/index.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/preview.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.