@vercel/nft
[](https://github.com/vercel/nft/actions/workflows/ci.yml)
88
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
matheussmatt.strakavercel-release-botzeit-bot
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| typosquat | typosquat.levenshtein:next | AI (typosquat): Official @vercel scoped package; Levenshtein match to 'next' is a false positive. | ai | |
| typosquat | typosquat.levenshtein:got | AI (typosquat): Official @vercel scoped package; Levenshtein match to 'got' is a false positive. | ai | |
| typosquat | typosquat.levenshtein:nuxt | AI (typosquat): Official @vercel scoped package; Levenshtein match to 'nuxt' is a false positive. | ai | |
| provenance | publisher-changed | AI (provenance): Transition from vercel-release-bot to GitHub Actions is a routine CI change within the Vercel org. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Reflect.get() is used inside a Proxy handler for module resolution interception — standard pattern for a module tracing tool, not obfuscation. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Removed maintainers appear to be former Vercel staff; consistent with normal org churn. No suspicious code changes. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Vercel org regularly updates maintainer roster as team grows; new maintainers are recognizable Vercel employees. No code changes accompany the roster update. | ai | |
| phantom-deps | phantom-dep:mkdirp | AI (phantom-deps): mkdirp is declared and used in config; phantom-dep pattern is stable for this package. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): picomatch is a well-known, widely-used glob library and is actually the engine underlying micromatch; this swap is a legitimate dependency simplification for this package. | ai | |
| dependencies | unvetted-dep:node-gyp-build | AI (dependencies): node-gyp-build is a standard native addon utility; its use in @vercel/nft for resolving native binary paths is expected and stable across versions. | ai | |
| semgrep | semgrep:eval-usage | AI (semgrep): eval('require.resolve(...)') is a known bundler-safe pattern for module resolution in static analysis tools; not an attack vector in this context. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require is core to nft's dependency-tracing functionality; it resolves node-gyp-build paths for native bindings analysis. Stable pattern across versions. | ai |
Versions (showing 88 of 88)
| Version | Deps | Published |
|---|---|---|
| 1.10.2 | 12 / 102 | |
| 1.10.0 | 12 / 102 | |
| 1.9.0 | 12 / 102 | |
| 1.5.0 | 12 / 102 | |
| 1.4.0 | 12 / 102 | |
| 1.3.2 | 12 / 102 | |
| 1.3.1 | 12 / 102 | |
| 1.3.0 | 12 / 102 | |
| 1.2.0 | 12 / 102 | |
| 1.1.1 | 12 / 102 | |
| 1.1.0 | 12 / 102 | |
| 1.0.0 | 12 / 102 | |
| 0.30.4 | 12 / 102 | |
| 0.30.3 | 12 / 102 | |
| 0.30.2 | 12 / 102 | |
| 0.30.1 | 12 / 102 | |
| 0.30.0 | 12 / 101 | |
| 0.29.4 | 12 / 103 | |
| 0.29.3 | 12 / 104 | |
| 0.29.2 | 12 / 104 | |
| 0.29.1 | 12 / 104 | |
| 0.29.0 | 12 / 104 | |
| 0.28.0 | 12 / 104 | |
| 0.27.10 | 12 / 104 | |
| 0.27.9 | 12 / 104 | |
| 0.27.8 | 12 / 104 | |
| 0.27.7 | 12 / 104 | |
| 0.27.6 | 12 / 104 | |
| 0.27.5 | 12 / 104 | |
| 0.27.4 | 12 / 103 | |
| 0.27.3 | 12 / 103 | |
| 0.27.2 | 12 / 103 | |
| 0.27.1 | 12 / 102 | |
| 0.27.0 | 12 / 101 | |
| 0.26.5 | 12 / 101 | |
| 0.26.4 | 12 / 98 | |
| 0.26.3 | 12 / 98 | |
| 0.26.2 | 12 / 98 | |
| 0.26.1 | 12 / 98 | |
| 0.26.0 | 12 / 98 | |
| 0.25.0 | 12 / 98 | |
| 0.24.4 | 11 / 98 | |
| 0.24.3 | 11 / 98 | |
| 0.24.2 | 11 / 97 | |
| 0.24.1 | 11 / 98 | |
| 0.24.0 | 11 / 97 | |
| 0.23.1 | 11 / 98 | |
| 0.23.0 | 11 / 98 | |
| 0.22.6 | 11 / 99 | |
| 0.22.5 | 11 / 99 | |
| 0.22.1 | 11 / 99 | |
| 0.22.0 | 11 / 99 | |
| 0.21.0 | 11 / 99 | |
| 0.20.1 | 10 / 99 | |
| 0.20.0 | 11 / 99 | |
| 0.19.1 | 11 / 99 | |
| 0.19.0 | 11 / 99 | |
| 0.18.2 | 11 / 98 | |
| 0.18.1 | 11 / 98 | |
| 0.18.0 | 11 / 97 | |
| 0.17.5 | 11 / 95 | |
| 0.17.4 | 11 / 95 | |
| 0.17.3 | 11 / 94 | |
| 0.17.2 | 12 / 94 | |
| 0.17.1 | 12 / 93 | |
| 0.17.0 | 15 / 92 | |
| 0.16.1 | 15 / 92 | |
| 0.16.0 | 15 / 92 | |
| 0.15.1 | 15 / 92 | |
| 0.15.0 | 15 / 92 | |
| 0.14.0 | 15 / 92 | |
| 0.13.1 | 14 / 88 | |
| 0.13.0 | 14 / 88 | |
| 0.12.2 | 14 / 87 | |
| 0.12.1 | 14 / 86 | |
| 0.12.0 | 14 / 86 | |
| 0.11.2 | 13 / 84 | |
| 0.11.1 | 13 / 83 | |
| 0.11.0 | 13 / 84 | |
| 0.10.1 | 13 / 84 | |
| 0.10.0 | 13 / 84 | |
| 0.9.6 | 16 / 84 | |
| 0.9.5 | 16 / 84 | |
| 0.9.4 | 16 / 84 | |
| 0.9.3 | 16 / 84 | |
| 0.9.2 | 16 / 84 | |
| 0.9.1 | 16 / 84 | |
| 0.9.0 | 16 / 84 |