← Home

@teambit/api-server

51
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

teambit-ownershohamgiladdavidfirstranm8guysaaritaymendelerezbitjoshk2redigmayona007

Keywords

bitbit-aspectbit-core-aspectcomponentscollaborationweb

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
maintainer-change maintainer-removed AI (maintainer-change): Large monorepo team churn; publisher matched as known maintainer per provenance finding. ai
phantom-deps phantom-dep:@teambit/merging AI (phantom-deps): @teambit/merging is declared in dependencies; phantom-dep is a false positive for this package. ai
dependencies unvetted-dep:http-proxy AI (dependencies): http-proxy is a well-known, widely-used package; legitimate dependency for an API server component. ai
publish-pattern rapid-publish AI (publish-pattern): teambit publishes many coordinated packages in rapid succession via CI; this is a stable pattern across 2321+ versions. ai
publish-pattern new-deps-added AI (publish-pattern): express is a natural dependency for an api-server package; addition is contextually appropriate. ai
dependencies unvetted-dep:@teambit/legacy.logger AI (dependencies): Internal teambit monorepo dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/scope.network AI (dependencies): Internal teambit monorepo dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/legacy.consumer AI (dependencies): Internal teambit monorepo dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/legacy.constants AI (dependencies): Internal teambit monorepo dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/toolbox.network.get-port AI (dependencies): Internal teambit monorepo dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/component.modules.merge-helper AI (dependencies): Internal teambit monorepo dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/harmony AI (dependencies): Internal teambit monorepo dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/component.modules.component-url AI (dependencies): Internal teambit monorepo dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/harmony.modules.send-server-sent-events AI (dependencies): Internal teambit monorepo dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/harmony.modules.feature-toggle AI (dependencies): Internal teambit monorepo dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/lane-id AI (dependencies): Internal teambit monorepo dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/legacy.scope AI (dependencies): Internal teambit monorepo dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/legacy.utils AI (dependencies): Internal teambit monorepo dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/legacy.loader AI (dependencies): Internal teambit monorepo dependency; stable pattern across all versions. ai
provenance no-provenance AI (provenance): teambit publishes hundreds of packages without provenance; consistent across all versions. ai
npm-metadata no-description AI (npm-metadata): Stable pattern across all @teambit/* scoped packages; not a malware signal here. ai
phantom-deps phantom-dep:@teambit/component.modules.merge-helper AI (phantom-deps): Same-org @teambit scope dependency; phantom-dep heuristic unreliable for Bit's component-based monorepo structure. ai

Versions (showing 51 of 122)

View all versions
Version Deps Published
1.0.1095 49 / 8
1.0.1091 49 / 8
1.0.1087 49 / 8
1.0.1057 49 / 8
1.0.1051 49 / 8
1.0.1036 49 / 8
1.0.1025 49 / 8
1.0.1017 49 / 8
1.0.1010 49 / 8
1.0.1009 49 / 8
1.0.1008 49 / 8
1.0.1007 49 / 8
1.0.1006 49 / 8
1.0.1005 49 / 8
1.0.1004 49 / 8
1.0.998 49 / 8
1.0.996 48 / 7
1.0.995 48 / 7
1.0.994 48 / 7
1.0.992 48 / 7
1.0.991 48 / 7
1.0.973 48 / 7
1.0.971 48 / 7
1.0.967 48 / 7
1.0.965 48 / 7
1.0.963 48 / 7
1.0.960 48 / 7
1.0.953 48 / 7
1.0.949 48 / 7
1.0.948 48 / 7
1.0.947 48 / 7
1.0.867 47 / 7
1.0.786 48 / 8
1.0.758 48 / 8
1.0.717 47 / 7
1.0.710 47 / 7
1.0.602 44 / 7
1.0.486 37 / 7
1.0.382 31 / 6
1.0.350 25 / 5
1.0.344 24 / 5
1.0.342 24 / 5
1.0.341 24 / 5
1.0.340 24 / 5
1.0.339 24 / 5
1.0.338 24 / 5
1.0.336 24 / 5
1.0.331 24 / 5
1.0.330 23 / 5
1.0.329 23 / 5
1.0.328 23 / 5

v1.0.1095

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1091

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1087

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.758

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: davidfirst → teambit-owner (on 2025-09-19, known maintainer) provenance

This version was published by a different npm account (teambit-owner) than the most recent previously approved version (davidfirst) on 2025-09-19, but teambit-owner is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.710

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: davidfirst → teambit-owner (on 2025-08-14, known maintainer) provenance

This version was published by a different npm account (teambit-owner) than the most recent previously approved version (davidfirst) on 2025-08-14, but teambit-owner is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.602

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: davidfirst → teambit-owner (on 2025-04-19, known maintainer) provenance

This version was published by a different npm account (teambit-owner) than the most recent previously approved version (davidfirst) on 2025-04-19, but teambit-owner is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.486

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.382

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.350

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.344

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.342

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.341

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.340

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.339

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.338

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.336

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.331

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.330

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.329

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.328

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.