← Home

next-server

13
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

alexalteaanatrajkovskaandybitzarunodaarzafranatcastlecaarlos0codetheorycoetrydav-isdevelopitfivepointsevengmonacoguybedfordhharnischousseindjirdehhuvikiamevilrabbitigorklopovijjkjanicklas-ralphjavivelascojoecohensjuancampakeanuleekikobeatsleolfadeslucleraymanovotnymarcosnilsmatheussmfix22mglagolamsweeneydevnkzawaollivpacopaulogdmprateekbhquietshurabautragojoserauchgsarupbanskotaskllcrnsophearakspanickerstyfletimertimneutkenstootallnateumegayawilliamlizeit-bot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
bogus-package bogus-package AI (bogus-package): Missing metadata (description, repo, keywords) is typical for monorepo sub-packages like next-server; not indicative of spam or malice given the package's age and download volume. ai
source-diff large-new-source-files AI (source-diff): next-server is a Next.js monorepo sub-package; large file additions are expected across major version bumps and reflect legitimate feature growth, not injected code. ai
provenance publisher-changed AI (provenance): zeit-bot is the legitimate Vercel/Zeit automation account for Next.js ecosystem publishing; the timneutkens → zeit-bot transition is a known, documented organizational change. ai
provenance no-provenance AI (provenance): Package predates Sigstore provenance; published by trusted zeit-bot automation. No provenance is expected for this package. ai
npm-metadata no-description AI (npm-metadata): next-server is a well-known monorepo sub-package of next.js; missing description is a stable characteristic, not a malware signal. ai
phantom-deps phantom-dep:prop-types AI (phantom-deps): prop-types is a legitimate runtime dependency in next-server used via config files; stable pattern for this package. ai
phantom-deps phantom-dep:styled-jsx AI (phantom-deps): styled-jsx is a core Next.js CSS-in-JS dependency referenced in config; stable pattern for this package. ai
publish-pattern new-deps-added AI (publish-pattern): New deps (content-type, cookie, raw-body, styled-jsx) are well-known packages added for Next.js 9 API routes and styling features; no suspicious packages. ai
maintainer-change maintainer-removed AI (maintainer-change): Maintainer removals are part of the same organizational transition; no evidence of hostile takeover. ai
maintainer-change maintainer-added AI (maintainer-change): Maintainer additions reflect the Zeit-to-Vercel transition and Next.js team growth; new maintainers are well-known JS ecosystem contributors, not suspicious actors. ai

Versions (showing 13 of 13)

Version Deps Published
9.0.5 14 / 10
9.0.4 14 / 10
9.0.3 13 / 10
9.0.2 13 / 10
9.0.1 13 / 10
9.0.0 13 / 10
8.1.0 10 / 8
8.0.4 7 / 8
8.0.3 7 / 8
8.0.2 7 / 8
8.0.1 7 / 8
8.0.0 7 / 8
0.0.1 0 / 0

v9.0.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.0.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.0.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.1.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.0.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.0.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.0.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.0.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.0.0

2 findings
HIGH Publisher changed: timneutkens → zeit-bot (on 2019-02-11) provenance

This version was published by a different npm account than previous versions on 2019-02-11. This could indicate a legitimate maintainer transition or an account compromise.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.