@module-federation/nextjs-mf
Module Federation helper for NextJS
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@module-federation/webpack-bundler-runtime | AI (phantom-deps): Same-org dep declared in package.json; phantom-dep heuristic false positive for this package. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Postinstall is a plain echo deprecation notice; no code execution risk. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Established package with 82k weekly downloads; sparse README/keywords are cosmetic issues only. | ai |
Versions (showing 16 of 16)
| Version | Deps | Published |
|---|---|---|
| 8.8.67 | 6 / 4 | |
| 8.8.66 | 6 / 4 | |
| 8.8.65 | 6 / 4 | |
| 8.8.64 | 6 / 4 | |
| 8.8.63 | 6 / 4 | |
| 8.8.61 | 6 / 4 | |
| 8.8.57 | 6 / 4 | |
| 8.8.53 | 6 / 3 | |
| 8.8.52 | 6 / 3 | |
| 8.8.49 | 6 / 3 | |
| 8.8.46 | 6 / 3 | |
| 8.8.44 | 6 / 3 | |
| 8.8.41 | 6 / 3 | |
| 8.8.37 | 6 / 3 | |
| 8.8.30 | 6 / 1 | |
| 8.8.29 | 6 / 1 |
v8.8.67
2 findingsScript: echo "Deprecation Notice: We intend to deprecate 'nextjs-mf'. Please see https://github.com/module-federation/core/issues/3153 for more details."
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.8.65
2 findingsScript: echo "Deprecation Notice: We intend to deprecate 'nextjs-mf'. Please see https://github.com/module-federation/core/issues/3153 for more details."
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.8.64
2 findingsScript: echo "Deprecation Notice: We intend to deprecate 'nextjs-mf'. Please see https://github.com/module-federation/core/issues/3153 for more details."
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.8.63
2 findingsScript: echo "Deprecation Notice: We intend to deprecate 'nextjs-mf'. Please see https://github.com/module-federation/core/issues/3153 for more details."
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.8.61
2 findingsScript: echo "Deprecation Notice: We intend to deprecate 'nextjs-mf'. Please see https://github.com/module-federation/core/issues/3153 for more details."
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.8.57
2 findingsScript: echo "Deprecation Notice: We intend to deprecate 'nextjs-mf'. Please see https://github.com/module-federation/core/issues/3153 for more details."
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.8.53
2 findingsScript: echo "Deprecation Notice: We intend to deprecate 'nextjs-mf'. Please see https://github.com/module-federation/core/issues/3153 for more details."
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.8.52
2 findingsScript: echo "Deprecation Notice: We intend to deprecate 'nextjs-mf'. Please see https://github.com/module-federation/core/issues/3153 for more details."
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.8.49
2 findingsScript: echo "Deprecation Notice: We intend to deprecate 'nextjs-mf'. Please see https://github.com/module-federation/core/issues/3153 for more details."
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.8.46
2 findingsScript: echo "Deprecation Notice: We intend to deprecate 'nextjs-mf'. Please see https://github.com/module-federation/core/issues/3153 for more details."
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.8.44
2 findingsScript: echo "Deprecation Notice: We intend to deprecate 'nextjs-mf'. Please see https://github.com/module-federation/core/issues/3153 for more details."
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.8.41
2 findingsScript: echo "Deprecation Notice: We intend to deprecate 'nextjs-mf'. Please see https://github.com/module-federation/core/issues/3153 for more details."
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.8.37
2 findingsScript: echo "Deprecation Notice: We intend to deprecate 'nextjs-mf'. Please see https://github.com/module-federation/core/issues/3153 for more details."
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.8.30
2 findingsScript: echo "Deprecation Notice: We intend to deprecate 'nextjs-mf'. Please see https://github.com/module-federation/core/issues/3153 for more details."
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.8.29
2 findingsScript: echo "Deprecation Notice: We intend to deprecate 'nextjs-mf'. Please see https://github.com/module-federation/core/issues/3153 for more details."
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.