@cntrl-site/sdk-nextjs
SDK for Next.js
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@antfu/eslint-config | AI (dependencies): @antfu/eslint-config is a widely-used ESLint config; no security risk as a build/lint dependency. | ai | |
| phantom-deps | phantom-dep:@types/vimeo__player | AI (phantom-deps): Type-only dep for @vimeo/player; framework convention, stable FP. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): Used in evaluateComponentBundle.js to execute CMS component bundles — intentional and documented pattern for this SDK. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Legitimate SDK with 433 versions and active GitHub repo; sparse README is cosmetic. | ai |
Versions (showing 51 of 141)
| Version | Deps | Published |
|---|---|---|
| 1.9.99 | 10 / 14 | |
| 1.9.96 | 10 / 14 | |
| 1.9.95 | 10 / 14 | |
| 1.9.94 | 10 / 14 | |
| 1.9.93 | 10 / 14 | |
| 1.9.92 | 10 / 14 | |
| 1.9.91 | 10 / 14 | |
| 1.9.90 | 10 / 14 | |
| 1.9.89 | 10 / 14 | |
| 1.9.88 | 10 / 14 | |
| 1.9.87 | 10 / 14 | |
| 1.9.86 | 10 / 14 | |
| 1.9.85 | 10 / 14 | |
| 1.9.84 | 10 / 14 | |
| 1.9.83 | 10 / 14 | |
| 1.9.82 | 10 / 14 | |
| 1.9.81 | 10 / 14 | |
| 1.9.80 | 10 / 14 | |
| 1.9.79 | 10 / 14 | |
| 1.9.78 | 10 / 14 | |
| 1.9.77 | 10 / 14 | |
| 1.9.76 | 10 / 14 | |
| 1.9.75 | 10 / 14 | |
| 1.9.74 | 10 / 14 | |
| 1.9.73 | 10 / 14 | |
| 1.9.72 | 10 / 14 | |
| 1.9.69 | 10 / 14 | |
| 1.9.68 | 10 / 14 | |
| 1.9.67 | 10 / 14 | |
| 1.9.66 | 10 / 14 | |
| 1.9.60 | 10 / 14 | |
| 1.9.57 | 10 / 14 | |
| 1.9.54 | 10 / 13 | |
| 1.9.53 | 10 / 13 | |
| 1.9.52 | 10 / 13 | |
| 1.9.51 | 10 / 13 | |
| 1.9.40 | 10 / 13 | |
| 1.9.37 | 10 / 13 | |
| 1.9.31 | 10 / 13 | |
| 1.9.28 | 10 / 13 | |
| 1.9.27 | 10 / 13 | |
| 1.9.25 | 10 / 13 | |
| 1.9.19 | 10 / 13 | |
| 1.9.16 | 10 / 13 | |
| 1.9.14 | 10 / 13 | |
| 1.9.8 | 9 / 13 | |
| 1.9.6 | 9 / 13 | |
| 1.8.40 | 9 / 11 | |
| 1.8.39 | 9 / 11 | |
| 1.8.38 | 9 / 11 | |
| 1.8.37 | 9 / 11 |
v1.9.99
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.96
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.95
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (sergokiko) than the most recent previously approved version (timurvnukov) on 2026-07-27, but sergokiko is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.9.94
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.93
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.92
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (timurvnukov) than the most recent previously approved version (paula.uli) on 2026-07-20, but timurvnukov is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.9.91
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (paula.uli) than the most recent previously approved version (timurvnukov) on 2026-07-17, but paula.uli is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.9.90
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.89
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.88
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (timurvnukov) than the most recent previously approved version (paula.uli) on 2026-07-14, but timurvnukov is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.9.87
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (paula.uli) than the most recent previously approved version (timurvnukov) on 2026-07-13, but paula.uli is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.9.86
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.85
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.84
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.83
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (timurvnukov) than the most recent previously approved version (sergokiko) on 2026-07-08, but timurvnukov is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.9.82
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (sergokiko) than the most recent previously approved version (paula.uli) on 2026-07-07, but sergokiko is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.9.81
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.80
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.79
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (paula.uli) than the most recent previously approved version (timurvnukov) on 2026-07-03, but paula.uli is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.9.78
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.77
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.76
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.75
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.