← Home

@next/mdx

70
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

vercel-release-botmatt.straka

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): Next.js moved to GitHub Actions CI/CD; gitHead absence is expected under this publish flow. ai
maintainer-change maintainer-removed AI (maintainer-change): Vercel org restructured npm maintainers; SLSA provenance confirms legitimate publish. ai
typosquat typosquat.levenshtein:mobx AI (typosquat): @next/mdx is an official Next.js scoped package; Levenshtein match against 'mobx' is noise. ai
semgrep semgrep:api-obfuscation-reflect AI (semgrep): Reflect.get() is standard Proxy trap boilerplate in a webpack loader; not obfuscation. ai

Versions (showing 70 of 70)

Version Deps Published
16.2.12 1 / 0
16.2.11 1 / 0
16.2.10 1 / 0
16.2.9 1 / 0
16.2.8 1 / 0
16.2.7 1 / 0
16.2.6 1 / 0
16.2.5 1 / 0
16.2.4 1 / 0
16.2.3 1 / 0
16.2.2 1 / 0
16.2.1 1 / 0
16.2.0 1 / 0
16.1.7 1 / 0
16.1.6 1 / 0
16.1.5 1 / 0
16.1.4 1 / 0
16.1.3 1 / 0
16.1.2 1 / 0
16.1.1 1 / 0
16.1.0 1 / 0
16.0.11 1 / 0
16.0.10 1 / 0
16.0.9 1 / 0
16.0.8 1 / 0
16.0.7 1 / 0
16.0.6 1 / 0
16.0.5 1 / 0
16.0.4 1 / 0
16.0.3 1 / 0
16.0.2 1 / 0
16.0.1 1 / 0
16.0.0 1 / 0
15.5.22 1 / 0
15.5.21 1 / 0
15.5.20 1 / 0
15.5.19 1 / 0
15.5.18 1 / 0
15.5.16 1 / 0
15.5.15 1 / 0
15.5.14 1 / 0
15.5.13 1 / 0
15.5.12 1 / 0
15.5.11 1 / 0
15.5.10 1 / 0
15.5.9 1 / 0
15.5.8 1 / 0
15.5.7 1 / 0
15.4.11 1 / 0
15.4.10 1 / 0
15.4.9 1 / 0
15.4.8 1 / 0
15.3.9 1 / 0
15.3.8 1 / 0
15.3.7 1 / 0
15.3.6 1 / 0
15.2.9 1 / 0
15.2.8 1 / 0
15.2.7 1 / 0
15.2.6 1 / 0
15.1.12 1 / 0
15.1.11 1 / 0
15.1.10 1 / 0
15.1.9 1 / 0
15.0.8 1 / 0
15.0.7 1 / 0
15.0.6 1 / 0
15.0.5 1 / 0
14.2.35 1 / 0
14.2.34 1 / 0

v16.2.12

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

v16.2.11

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

v16.2.10

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v15.5.22

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

v15.5.21

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

v15.5.20

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.