← Home

@next/third-parties

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

vercel-release-botmatt.straka

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): Next.js monorepo CI publishes may omit gitHead; SLSA attestation present. ai
maintainer-change maintainer-removed AI (maintainer-change): Vercel org maintainer list changes are routine for this scoped package. ai
provenance publisher-changed AI (provenance): Vercel migrated publishing from vercel-release-bot to GitHub Actions CI; SLSA attestation confirms legitimate pipeline. ai
dependencies unvetted-dep:third-party-capital AI (dependencies): third-party-capital is a Google-maintained library integral to @next/third-parties; stable dependency across versions. ai

Versions (showing 51 of 70)

View all versions
Version Deps Published
16.2.12 1 / 4
16.2.11 1 / 4
16.2.10 1 / 4
16.2.9 1 / 4
16.2.8 1 / 4
16.2.7 1 / 4
16.2.6 1 / 4
16.2.5 1 / 4
16.2.4 1 / 4
16.2.3 1 / 4
16.2.2 1 / 4
16.2.1 1 / 4
16.2.0 1 / 4
16.1.7 1 / 4
16.1.6 1 / 4
16.1.5 1 / 4
16.1.4 1 / 4
16.1.3 1 / 4
16.1.2 1 / 4
16.1.1 1 / 4
16.1.0 1 / 4
16.0.11 1 / 4
16.0.10 1 / 4
16.0.9 1 / 4
16.0.8 1 / 4
16.0.7 1 / 4
16.0.6 1 / 4
16.0.5 1 / 4
16.0.4 1 / 4
16.0.3 1 / 4
16.0.2 1 / 4
16.0.1 1 / 4
16.0.0 1 / 4
15.5.22 1 / 4
15.5.21 1 / 4
15.5.20 1 / 4
15.5.19 1 / 4
15.5.18 1 / 4
15.5.16 1 / 4
15.5.15 1 / 4
15.5.14 1 / 4
15.5.13 1 / 4
15.5.12 1 / 4
15.5.11 1 / 4
15.5.10 1 / 4
15.5.9 1 / 4
15.5.8 1 / 4
15.5.7 1 / 4
15.4.11 1 / 4
15.4.10 1 / 4
15.4.9 1 / 4

v16.2.12

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

v16.2.11

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

v16.2.10

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v15.5.22

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

v15.5.21

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

v15.5.20

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.