← Home

next

The React Framework

3
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

matt.strakavercel-release-botzeit-bot

Keywords

reactframeworknextjswebservernodefront-endbackendclivercel

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:styled-jsx AI (phantom-deps): styled-jsx is bundled into Next.js dist output via the build pipeline; direct source imports are not expected. This is a stable false positive for this package. ai
phantom-deps phantom-dep:baseline-browser-mapping AI (phantom-deps): baseline-browser-mapping is used by Next.js build tooling and bundled into dist; not directly imported in source. Stable false positive for this package. ai

Versions (showing 3 of 3)

Version Deps Published
16.2.4 6 / 221
16.2.3 6 / 221
15.5.15 5 / 221

v16.2.4

3 findings
HIGH Phantom dependency: styled-jsx phantom-deps

Declared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).

HIGH Phantom dependency: baseline-browser-mapping phantom-deps

Declared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v16.2.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v15.5.15

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.