← Home

@akinon/next

Core package for Project Zero Next

51
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

akinon

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@neshca/cache-handler AI (dependencies): Known Next.js cache handler library; consistent with package purpose. ai
dependencies unvetted-dep:react-string-replace AI (dependencies): Small, well-known utility; no security concerns. ai
dependencies unvetted-dep:@mongodb-js/zstd AI (dependencies): Official MongoDB compression library; legitimate use in cache handler. ai
dependencies unvetted-dep:@sentry/nextjs AI (dependencies): Well-known Sentry SDK; stable dependency for this package. ai
provenance no-provenance AI (provenance): Long-established package with clean history; lack of provenance attestation is not a disqualifier here. ai
phantom-deps phantom-dep:@opentelemetry/resources AI (phantom-deps): Referenced in config files as expected for an instrumentation framework dep. ai
phantom-deps phantom-dep:lottie-web AI (phantom-deps): Framework re-exports deps; phantom detection is a stable false positive for this package. ai
phantom-deps phantom-dep:react-multi-carousel AI (phantom-deps): Framework re-exports deps; phantom detection is a stable false positive for this package. ai
phantom-deps phantom-dep:@opentelemetry/sdk-node AI (phantom-deps): Referenced in config files as expected for an instrumentation framework dep. ai
phantom-deps phantom-dep:@opentelemetry/sdk-trace-node AI (phantom-deps): Referenced in config files as expected for an instrumentation framework dep. ai
phantom-deps phantom-dep:@opentelemetry/semantic-conventions AI (phantom-deps): Referenced in config files as expected for an instrumentation framework dep. ai
phantom-deps phantom-dep:@opentelemetry/exporter-trace-otlp-http AI (phantom-deps): Referenced in config files as expected for an instrumentation framework dep. ai
typosquat typosquat.levenshtein:jest AI (typosquat): Same scoped package context; jest similarity is coincidental string distance. ai
semgrep semgrep:base64-decode AI (semgrep): Buffer.from with base64 used for cache compression/decompression; no obfuscation or exfiltration pattern. ai
semgrep semgrep:dynamic-require AI (semgrep): Loads user-configured plugins from a known path; standard plugin-loader pattern. ai
typosquat typosquat.levenshtein:nuxt AI (typosquat): Scoped @akinon package with 947-day history and 784 versions; not a typosquat of nuxt. ai
semgrep semgrep:child-process-import AI (semgrep): Used in bin/ CLI scripts for plugin/extension installation tooling; expected pattern for a framework package. ai
typosquat typosquat.levenshtein:knex AI (typosquat): Same scoped package context; knex similarity is coincidental string distance. ai

Versions (showing 51 of 59)

View all versions
Version Deps Published
2.0.18 17 / 14
2.0.17 17 / 14
2.0.16 17 / 14
2.0.15 17 / 14
2.0.14 17 / 14
2.0.13 17 / 14
2.0.12 17 / 14
2.0.11 17 / 14
2.0.10 17 / 14
2.0.9 17 / 14
2.0.8 17 / 14
2.0.7 17 / 14
2.0.6 17 / 16
2.0.5 18 / 16
2.0.1 18 / 16
2.0.0 18 / 16
1.126.3 16 / 16
1.126.2 16 / 16
1.126.1 16 / 16
1.126.0 16 / 16
1.125.2 16 / 16
1.125.1 16 / 16
1.125.0 16 / 16
1.124.0 16 / 16
1.123.0 16 / 16
1.122.0 16 / 16
1.121.0 16 / 16
1.120.0 16 / 16
1.119.0 16 / 16
1.118.0 16 / 16
1.117.0 16 / 16
1.116.0 16 / 16
1.115.0 16 / 16
1.114.0 16 / 16
1.113.0 16 / 16
1.112.0 16 / 16
1.111.0 16 / 16
1.110.0 16 / 16
1.109.0 16 / 16
1.108.0 16 / 16
1.107.0 16 / 16
1.106.0 16 / 16
1.105.0 16 / 16
1.104.0 16 / 16
1.103.0 16 / 16
1.102.0 16 / 16
1.101.0 16 / 16
1.100.0 16 / 16
1.99.0 16 / 16
1.98.0 15 / 16
1.97.0 15 / 16

v2.0.18

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.17

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.16

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.15

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.14

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.13

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.12

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.11

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.10

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.9

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.8

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.126.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.126.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.126.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.126.0

2 findings
HIGH typosquat.levenshtein: Possible typosquat of 'nuxt' typosquat

Package name '@akinon/next' is 1 edit(s) away from popular package 'nuxt'.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.125.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.125.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.125.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.124.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.123.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.122.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.121.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.120.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.119.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.118.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.117.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.116.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.115.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.114.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.113.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.112.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.111.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.110.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.109.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.108.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.107.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.106.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.105.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.104.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.103.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.102.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.101.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.100.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.99.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.98.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.97.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.