postcss-cssnext
Use tomorrow’s CSS syntax, today
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): moox is Maxime Thirouin, the listed author of postcss-cssnext; the repo URL is github.com/MoOx/postcss-cssnext. Publisher change reflects the original author reclaiming sole ownership, not a takeover. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Postinstall runs 'npm run babelify' to transpile src/ to lib/ — a standard build step for this package's ES6 source. No network access or suspicious behavior. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): postcss-cssnext is a deprecated/superseded package; long dormancy is expected. Original author moox has strong track record with 806 approved packages. | ai |
Versions (showing 20 of 20)
| Version | Deps | Published |
|---|---|---|
| 3.1.1 | 31 / 58 | |
| 3.1.0 | 31 / 58 | |
| 3.0.2 | 31 / 58 | |
| 3.0.1 | 31 / 58 | |
| 3.0.0 | 31 / 57 | |
| 2.11.0 | 31 / 56 | |
| 2.10.0 | 30 / 56 | |
| 2.9.0 | 29 / 56 | |
| 2.8.0 | 27 / 56 | |
| 2.7.0 | 26 / 56 | |
| 2.6.0 | 25 / 56 | |
| 2.5.2 | 24 / 56 | |
| 2.5.1 | 24 / 56 | |
| 2.5.0 | 23 / 57 | |
| 2.4.0 | 23 / 51 | |
| 2.3.0 | 23 / 7 | |
| 2.2.0 | 23 / 7 | |
| 2.1.0 | 22 / 7 | |
| 2.0.1 | 21 / 7 | |
| 2.0.0 | 21 / 7 |
v3.1.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: moox.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1
2 findingsScript: npm run babelify
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.0
2 findingsThis version was published by a different npm account than previous versions on 2017-07-05. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.11.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2017-05-15. This could indicate a legitimate maintainer transition or an account compromise.
v2.10.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.9.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.8.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.7.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.6.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.5.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.5.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.5.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.4.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.