← Home

@vercel/introspection

12
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

sebastianromingcraigandrewsgkaragkiaourisdglsparsonsbvred4244dummdidummadriancooney_verceleveporcellobcorn-celyatinuxdvoytenkoamyeganbrookemosbyfeugyswarnavasenguptaraunofreibergmamusogoncysmaeda-kshenryheffernangargis5wycatsyvonnezhouchibicodeandybitziamevilrabbittootallnatestyflematthewbinshtokmglagolajavivelascoluimeytimerlucleraymatheussanatrajkovskan0rlant1sjooliashitimneutkenselsighwitslpalmescl3arglasssamsislechriswdmrrizbizkitsismaelrumzanrich.davis.vercelcreationixfeedthejimcasey.gowrierauchghuozhialdoschlfadesokbeljerilynzhedyzandipadmaiadelbasokragsandhudbredvickhungrybearstudiocalebboydhellojennifertranmarcgreenstockagadziktknickmanjanoryjeffreyarnesonmattjaredmsimulcikgdbortoncorrettojscramforcekakadiadarpanmaxleiterkit-fostertilly3gecklfhealeycodesdferber90epallerolsnicolas-webdevschleznpm_bot_vercel_supportpieparkerjtaylor0196javierbyteemeraldsantogaspar09mmastracsr_interngudmundurnick.traceybmealeydoqueaaorrisnutadaniel.campbellquiibzchloe.teddermjakobismehulkartcc-sejohnsonfiliphassonlubakravchegnoffmatt.strakawbinnssmithofhousemknichel-vercelvvovercel-release-botrob-peters-vercelgt-codesbalazsorbantobiaslinstiago-loureirombrakkentimolinsanthonyshewcmeyer_verceltbremermiguelalcaldelaugharnviekorobin-vercelwude935zach-baldaah100101quietshuijjkvercelbenzharichjoey.berkowitzdfeinonsclomashok.gurumurthydavidvercelowoceergun1017shaper42ademaulayonthebeechjeffsee55zeejabacdlitemcabs3msemperekldavis4lukahartwigbgwsipexjeremyphilemoneprosimonrithmicdanmfoxn-vigiervercelmattjudegaovercel-ctatealbanesesceilerlgrammeljamesvclementstomocchinoaryamankhapranathipmattfroggetteps1lonpbzonamalewis5devjiwonchoikonstvzacktannergabenunezshadcnmikecurtisunstubbablesueplexethansheaidoatvercelwentsulvikhyathmischnichgstrmdcampvc01mitul-sjonpheyannagzhrich_harrisandrewbarbabcjrobertsmarc-vercelali-vercelduijfplmrrytmdojulianbenegasrao.chandanthebigsadowskigovind-verceltomjohndesignbshanzaubreychamberlainkmiddleton14yavorgracelliu1st1whatplanfmoorvercel-eddietristantcooperrklaesermerycodesnmelmsyasoobr0m7rceloestebansuarezbobmshannoncaseyokeefebhrigulaksshhzackelankelzceanahannah.hearthfalcoagustin.vercelnpasquinzokobologtimwhite96jnsahajastephen100sylviezhangmatiasgflukesheardadrienthebokarthiklangtraceelpransrihanarfanolivercarmontjjdopkinvercel_it_service_accountadamdongrhyssullivanvalerian-rocheallen-vercelalli-vercelethsheascotttrinhjaclarkebkonkleseverinlandoltkevinjosethomasjaygengelbachchriskindltk04gschokavinvallinsidnevyash-kothari-vercelrobherleymingchungxmbaizabenyebaitimothyjordantristano45andyw22shagrawalneil-vercelskullfacefernandorojokevin.corbettzacowanjoelhookswillvilesmarkandrusloganliffickyoungbloodcybkapehe_okhaydenbleaselquuujteesangpckirklanddavid_keefejeffreypoaormi-verceldarafshehmarkpython86lazarvtonypanjackjacksonvercelseif.ghezalamiksuwillsatheramanazadjacobparisicyjosephvercelliotlukesandbergnicolasmontonevoodootikigodjustinkroppsatya-callstackchristianhubbardwoshuajolkbennorstranglebmishkinmshepaneshkarimhasebouwilliamboutpranaygpalex-groverchrmcd-verallenzhou101dmoriiansbrashalice-wonderedmatchaivishalyathishsamselikoffmrsasuu_ckmtoth-vercelanshuman71runewolf7rohantaneja-vercelhp_arorajoyboy-0matiasperzjverceltannervercelgi_wrightymatthewstanciurickeymcgregorrichardkunklibwalvoordrobpruzandanielroerahuliyer-vercelty37zhangshawnfeldmanjohnphamous6aryricardo-agzaej11amclenhardreynaldo-verceljaredthompson22jetthenrobkebabraidaltcodyellowpablostanleyronnie-hanifzypxtheclepranavkarthikandy.rianchojonasherrvanessaxteotomdalevincent-derksgrappeggiavaguelyseriousmkrrdalyd14kaciebgr2mkarim_v1simhskal

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
maintainer-change maintainer-added AI (maintainer-change): Large Vercel org with frequent maintainer roster updates; vercel-release-bot publishes with CI provenance. ai
maintainer-change maintainer-removed AI (maintainer-change): Routine org maintainer rotation for Vercel monorepo packages. ai
bogus-package bogus-package AI (bogus-package): Legitimate Vercel internal package; no description/keywords are cosmetic issues, not spam indicators. ai
email-domain unclaimed-email:magic.io AI (email-domain): Vercel's release bot publishes with SLSA provenance; legacy maintainer email domain is not a meaningful hijack risk for this package. ai

Versions (showing 12 of 12)

Version Deps Published
0.0.13 1 / 3
0.0.12 1 / 3
0.0.11 1 / 3
0.0.10 2 / 15
0.0.9 2 / 15
0.0.8 2 / 15
0.0.7 2 / 15
0.0.6 2 / 15
0.0.5 2 / 15
0.0.4 2 / 15
0.0.3 2 / 15
0.0.2 2 / 15

v0.0.13

2 findings
HIGH Unclaimed maintainer email domain: magic.io email-domain

Maintainer email '[email protected]' uses domain 'magic.io' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.12

2 findings
HIGH Unclaimed maintainer email domain: magic.io email-domain

Maintainer email '[email protected]' uses domain 'magic.io' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.11

2 findings
HIGH Unclaimed maintainer email domain: magic.io email-domain

Maintainer email '[email protected]' uses domain 'magic.io' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.10

2 findings
HIGH Unclaimed maintainer email domain: magic.io email-domain

Maintainer email '[email protected]' uses domain 'magic.io' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.9

2 findings
HIGH Unclaimed maintainer email domain: magic.io email-domain

Maintainer email '[email protected]' uses domain 'magic.io' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.8

2 findings
HIGH Unclaimed maintainer email domain: magic.io email-domain

Maintainer email '[email protected]' uses domain 'magic.io' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.