next-server
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| bogus-package | bogus-package | AI (bogus-package): Missing metadata (description, repo, keywords) is typical for monorepo sub-packages like next-server; not indicative of spam or malice given the package's age and download volume. | ai | |
| source-diff | large-new-source-files | AI (source-diff): next-server is a Next.js monorepo sub-package; large file additions are expected across major version bumps and reflect legitimate feature growth, not injected code. | ai | |
| provenance | publisher-changed | AI (provenance): zeit-bot is the legitimate Vercel/Zeit automation account for Next.js ecosystem publishing; the timneutkens → zeit-bot transition is a known, documented organizational change. | ai | |
| provenance | no-provenance | AI (provenance): Package predates Sigstore provenance; published by trusted zeit-bot automation. No provenance is expected for this package. | ai | |
| npm-metadata | no-description | AI (npm-metadata): next-server is a well-known monorepo sub-package of next.js; missing description is a stable characteristic, not a malware signal. | ai | |
| phantom-deps | phantom-dep:prop-types | AI (phantom-deps): prop-types is a legitimate runtime dependency in next-server used via config files; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:styled-jsx | AI (phantom-deps): styled-jsx is a core Next.js CSS-in-JS dependency referenced in config; stable pattern for this package. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New deps (content-type, cookie, raw-body, styled-jsx) are well-known packages added for Next.js 9 API routes and styling features; no suspicious packages. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Maintainer removals are part of the same organizational transition; no evidence of hostile takeover. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Maintainer additions reflect the Zeit-to-Vercel transition and Next.js team growth; new maintainers are well-known JS ecosystem contributors, not suspicious actors. | ai |
Versions (showing 13 of 13)
| Version | Deps | Published |
|---|---|---|
| 9.0.5 | 14 / 10 | |
| 9.0.4 | 14 / 10 | |
| 9.0.3 | 13 / 10 | |
| 9.0.2 | 13 / 10 | |
| 9.0.1 | 13 / 10 | |
| 9.0.0 | 13 / 10 | |
| 8.1.0 | 10 / 8 | |
| 8.0.4 | 7 / 8 | |
| 8.0.3 | 7 / 8 | |
| 8.0.2 | 7 / 8 | |
| 8.0.1 | 7 / 8 | |
| 8.0.0 | 7 / 8 | |
| 0.0.1 | 0 / 0 |
v9.0.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.0.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.0.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.0.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.0.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.0.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.1.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.0.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.0.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.0.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.0.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.0.0
2 findingsThis version was published by a different npm account than previous versions on 2019-02-11. This could indicate a legitimate maintainer transition or an account compromise.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.