← Home

@graphcommerce/next-config

3
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

paalesbramvanderholst

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:znv AI (dependencies): znv is a small env-var parsing utility; no malware history, stable use in this package. ai
dependencies unvetted-dep:js-yaml-loader AI (dependencies): js-yaml-loader is a webpack loader for YAML; well-known, no malware history. ai
phantom-deps phantom-dep:@types/lodash AI (phantom-deps): @types packages are type-only and loaded by convention; stable false positive for this package. ai
phantom-deps phantom-dep:@types/js-yaml AI (phantom-deps): @types packages are type-only and loaded by convention; stable false positive for this package. ai
phantom-deps phantom-dep:typescript AI (phantom-deps): typescript is a declared dep used by codegen/build tooling; phantom-dep false positive. ai
semgrep semgrep:hex-decode AI (semgrep): Hex decode is part of a license/signature verification routine (sig.ts), not malicious payload hiding; stable pattern for this package. ai
phantom-deps phantom-dep:js-yaml-loader AI (phantom-deps): Declared dep used in webpack config files; phantom-dep false positive. ai
phantom-deps phantom-dep:@swc/wasm-web AI (phantom-deps): Declared dep used by SWC tooling at runtime; phantom-dep false positive. ai
phantom-deps phantom-dep:znv AI (phantom-deps): znv is a declared dependency used in config files by convention; phantom-dep is a false positive here. ai
phantom-deps phantom-dep:graphql AI (phantom-deps): graphql is a declared dep used transitively via codegen; phantom-dep is a false positive. ai
phantom-deps phantom-dep:js-yaml AI (phantom-deps): js-yaml declared dep used in config loading; phantom-dep false positive. ai

Versions (showing 3 of 3)

Version Deps Published
10.0.3 18 / 1
10.0.2 18 / 1
10.0.1 18 / 1

v10.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v10.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v10.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.