← Home

@coursebuilder/commerce-next

Commerce Functionality for Course Builder with Next.js

3
Versions
ISC
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

joelhooks

Keywords

coursebuilder

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:next-cloudinary AI (dependencies): next-cloudinary is a well-known Cloudinary integration for Next.js; stable false positive for this package. ai
dependencies unvetted-dep:@react-email/components AI (dependencies): Popular React Email component library; no malicious history; stable false positive for this package. ai
phantom-deps phantom-dep:date-fns-tz AI (phantom-deps): Peer/config-level dependency pattern common in monorepo packages; not a security concern. ai
phantom-deps phantom-dep:tailwindcss AI (phantom-deps): CSS tooling dep; not directly imported in JS source by design. ai
phantom-deps phantom-dep:framer-motion AI (phantom-deps): Animation dep declared for consumers; phantom detection is a false positive. ai
phantom-deps phantom-dep:react-markdown AI (phantom-deps): Rendering dep; stable false positive for this library package. ai
phantom-deps phantom-dep:react-hot-toast AI (phantom-deps): UI dep declared for consumers; stable false positive. ai
phantom-deps phantom-dep:@heroicons/react AI (phantom-deps): Icon dep; stable false positive for this library. ai
phantom-deps phantom-dep:uuid AI (phantom-deps): Library dependency declared for consumers; not directly imported in library source is expected pattern. ai
phantom-deps phantom-dep:@react-email/render AI (phantom-deps): Email rendering dep; stable false positive for this library. ai
phantom-deps phantom-dep:@react-email/components AI (phantom-deps): Email components dep; stable false positive. ai
phantom-deps phantom-dep:@radix-ui/react-alert-dialog AI (phantom-deps): UI component dep; stable false positive for this library. ai
phantom-deps phantom-dep:@coursebuilder/email-templates AI (phantom-deps): Same-org dep; stable false positive. ai
phantom-deps phantom-dep:@hookform/resolvers AI (phantom-deps): Form validation dep; stable false positive. ai
phantom-deps phantom-dep:xstate AI (phantom-deps): State machine dep used via @xstate/react; phantom detection is a false positive here. ai
phantom-deps phantom-dep:@auth/core AI (phantom-deps): Auth integration dep; used indirectly via next-auth. Stable false positive for this package. ai

Versions (showing 3 of 3)

Version Deps Published
0.2.1 37 / 8
0.0.14 37 / 8
0.0.13 37 / 8

v0.2.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.