← Home

@interfere/next

Build software that never breaks.

11
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

skve

Keywords

observability@typescript/native-previewreactnextjserror-tracking

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@interfere/constants AI (phantom-deps): Workspace dependency; same org, re-exported via public API. ai
phantom-deps phantom-dep:@interfere/sdk AI (phantom-deps): Workspace dependency; same org, re-exported via public API. ai
phantom-deps phantom-dep:@interfere/react AI (phantom-deps): Workspace dependency; same org, re-exported via public API. ai
phantom-deps phantom-dep:@interfere/types AI (phantom-deps): Workspace dependency; same org, re-exported via public API. ai
phantom-deps phantom-dep:glob AI (phantom-deps): Build-tool dependency; referenced in config, stable for this package. ai
phantom-deps phantom-dep:uuid AI (phantom-deps): Utility dependency; referenced in config, stable for this package. ai
phantom-deps phantom-dep:chalk AI (phantom-deps): Build-tool dependency; referenced in config, stable for this package. ai
typosquat typosquat.levenshtein:jest AI (typosquat): False positive; package is a Next.js integration for the Interfere platform, unrelated to jest. ai
typosquat typosquat.levenshtein:knex AI (typosquat): False positive; package is a Next.js integration for the Interfere platform, unrelated to knex. ai
typosquat typosquat.levenshtein:nuxt AI (typosquat): @interfere/next is a scoped observability SDK, not a nuxt typosquat; name reflects Next.js integration. ai

Versions (showing 11 of 11)

Version Deps Published
9.0.2 7 / 17
9.0.1 7 / 17
9.0.0 7 / 17
8.1.6 7 / 17
8.1.2 6 / 18
8.1.0 6 / 18
1.0.4 7 / 19
1.0.3 7 / 19
1.0.2 7 / 19
1.0.1 7 / 19
1.0.0 7 / 19

v9.0.2

2 findings
HIGH typosquat.levenshtein: Possible typosquat of 'nuxt' typosquat

Package name '@interfere/next' is 1 edit(s) away from popular package 'nuxt'.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v9.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v9.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v8.1.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v8.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v8.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.