← Home

@next/codemod

Next.js provides Codemod transformations to help upgrade your Next.js codebase when a feature is deprecated.

70
Versions
MIT
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures No source commit

Maintainers

vercel-release-botmatt.straka

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): SLSA provenance attestation present; gitHead absence reflects CI pipeline change, not a supply chain risk. ai
maintainer-change maintainer-removed AI (maintainer-change): Vercel org restructuring; published via GitHub Actions with SLSA attestation confirms legitimate org-controlled publish. ai
semgrep semgrep:env-spread AI (semgrep): Spreading process.env into execa for package manager invocation is standard and intentional for this codemod CLI. ai
semgrep semgrep:dynamic-require AI (semgrep): Dynamic require loads user-selected codemod transforms by name; core functionality of a codemod runner. ai
semgrep semgrep:child-process-import AI (semgrep): CLI tool that runs package managers and codemods inherently requires child_process; expected pattern. ai
bogus-package bogus-package AI (bogus-package): Monorepo sub-package from Vercel; sparse README and no keywords are normal for internal tooling packages. ai

Versions (showing 70 of 70)

Version Deps Published
16.2.12 11 / 5
16.2.11 11 / 5
16.2.10 11 / 5
16.2.9 11 / 5
16.2.8 11 / 5
16.2.7 11 / 5
16.2.6 11 / 5
16.2.5 11 / 5
16.2.4 11 / 5
16.2.3 11 / 5
16.2.2 11 / 5
16.2.1 11 / 5
16.2.0 11 / 5
16.1.7 11 / 5
16.1.6 11 / 5
16.1.5 11 / 5
16.1.4 11 / 5
16.1.3 11 / 5
16.1.2 11 / 5
16.1.1 11 / 5
16.1.0 11 / 5
16.0.11 11 / 5
16.0.10 11 / 5
16.0.9 11 / 5
16.0.8 11 / 5
16.0.7 11 / 5
16.0.6 11 / 5
16.0.5 11 / 5
16.0.4 11 / 5
16.0.3 11 / 5
16.0.2 11 / 5
16.0.1 11 / 5
16.0.0 11 / 5
15.5.22 11 / 5
15.5.21 11 / 5
15.5.20 11 / 5
15.5.19 11 / 5
15.5.18 11 / 5
15.5.16 11 / 5
15.5.15 11 / 5
15.5.14 11 / 5
15.5.13 11 / 5
15.5.12 11 / 5
15.5.11 11 / 5
15.5.10 11 / 5
15.5.9 11 / 5
15.5.8 11 / 5
15.5.7 11 / 5
15.4.11 11 / 5
15.4.10 11 / 5
15.4.9 11 / 5
15.4.8 11 / 5
15.3.9 11 / 5
15.3.8 11 / 5
15.3.7 11 / 5
15.3.6 11 / 5
15.2.9 11 / 5
15.2.8 11 / 5
15.2.7 11 / 5
15.2.6 11 / 5
15.1.12 11 / 5
15.1.11 11 / 5
15.1.10 11 / 5
15.1.9 11 / 5
15.0.8 11 / 5
15.0.7 11 / 5
15.0.6 11 / 5
15.0.5 11 / 5
14.2.35 8 / 1
14.2.34 8 / 1

v16.2.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v16.2.11

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

v16.2.10

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v15.5.22

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

v15.5.21

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

v15.5.20

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.