@graphcommerce/next-config
3
Versions
—
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
paalesbramvanderholst
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:znv | AI (dependencies): znv is a small env-var parsing utility; no malware history, stable use in this package. | ai | |
| dependencies | unvetted-dep:js-yaml-loader | AI (dependencies): js-yaml-loader is a webpack loader for YAML; well-known, no malware history. | ai | |
| phantom-deps | phantom-dep:@types/lodash | AI (phantom-deps): @types packages are type-only and loaded by convention; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@types/js-yaml | AI (phantom-deps): @types packages are type-only and loaded by convention; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:typescript | AI (phantom-deps): typescript is a declared dep used by codegen/build tooling; phantom-dep false positive. | ai | |
| semgrep | semgrep:hex-decode | AI (semgrep): Hex decode is part of a license/signature verification routine (sig.ts), not malicious payload hiding; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:js-yaml-loader | AI (phantom-deps): Declared dep used in webpack config files; phantom-dep false positive. | ai | |
| phantom-deps | phantom-dep:@swc/wasm-web | AI (phantom-deps): Declared dep used by SWC tooling at runtime; phantom-dep false positive. | ai | |
| phantom-deps | phantom-dep:znv | AI (phantom-deps): znv is a declared dependency used in config files by convention; phantom-dep is a false positive here. | ai | |
| phantom-deps | phantom-dep:graphql | AI (phantom-deps): graphql is a declared dep used transitively via codegen; phantom-dep is a false positive. | ai | |
| phantom-deps | phantom-dep:js-yaml | AI (phantom-deps): js-yaml declared dep used in config loading; phantom-dep false positive. | ai |
v10.0.3
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v10.0.2
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v10.0.1
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.