← Home

@teambit/api-server

100
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

teambit-ownershohamgiladdavidfirstranm8guysaaritaymendelerezbitjoshk2redigmayona007

Keywords

bitbit-aspectbit-core-aspectcomponentscollaborationweb

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
maintainer-change maintainer-removed AI (maintainer-change): Large monorepo team churn; publisher matched as known maintainer per provenance finding. ai
phantom-deps phantom-dep:@teambit/merging AI (phantom-deps): @teambit/merging is declared in dependencies; phantom-dep is a false positive for this package. ai
dependencies unvetted-dep:http-proxy AI (dependencies): http-proxy is a well-known, widely-used package; legitimate dependency for an API server component. ai
publish-pattern rapid-publish AI (publish-pattern): teambit publishes many coordinated packages in rapid succession via CI; this is a stable pattern across 2321+ versions. ai
publish-pattern new-deps-added AI (publish-pattern): express is a natural dependency for an api-server package; addition is contextually appropriate. ai
dependencies unvetted-dep:@teambit/legacy.logger AI (dependencies): Internal teambit monorepo dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/scope.network AI (dependencies): Internal teambit monorepo dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/legacy.consumer AI (dependencies): Internal teambit monorepo dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/legacy.constants AI (dependencies): Internal teambit monorepo dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/toolbox.network.get-port AI (dependencies): Internal teambit monorepo dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/component.modules.merge-helper AI (dependencies): Internal teambit monorepo dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/harmony AI (dependencies): Internal teambit monorepo dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/component.modules.component-url AI (dependencies): Internal teambit monorepo dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/harmony.modules.send-server-sent-events AI (dependencies): Internal teambit monorepo dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/harmony.modules.feature-toggle AI (dependencies): Internal teambit monorepo dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/lane-id AI (dependencies): Internal teambit monorepo dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/legacy.scope AI (dependencies): Internal teambit monorepo dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/legacy.utils AI (dependencies): Internal teambit monorepo dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/legacy.loader AI (dependencies): Internal teambit monorepo dependency; stable pattern across all versions. ai
provenance no-provenance AI (provenance): teambit publishes hundreds of packages without provenance; consistent across all versions. ai
npm-metadata no-description AI (npm-metadata): Stable pattern across all @teambit/* scoped packages; not a malware signal here. ai
phantom-deps phantom-dep:@teambit/component.modules.merge-helper AI (phantom-deps): Same-org @teambit scope dependency; phantom-dep heuristic unreliable for Bit's component-based monorepo structure. ai

Versions (showing 100 of 374)

Version Deps Published
1.0.1095 49 / 8
1.0.1091 49 / 8
1.0.1087 49 / 8
1.0.1057 49 / 8
1.0.1051 49 / 8
1.0.1036 49 / 8
1.0.1025 49 / 8
1.0.1017 49 / 8
1.0.1010 49 / 8
1.0.1009 49 / 8
1.0.1008 49 / 8
1.0.1007 49 / 8
1.0.1006 49 / 8
1.0.1005 49 / 8
1.0.1004 49 / 8
1.0.998 49 / 8
1.0.996 48 / 7
1.0.995 48 / 7
1.0.994 48 / 7
1.0.992 48 / 7
1.0.991 48 / 7
1.0.973 48 / 7
1.0.971 48 / 7
1.0.967 48 / 7
1.0.965 48 / 7
1.0.963 48 / 7
1.0.960 48 / 7
1.0.953 48 / 7
1.0.949 48 / 7
1.0.948 48 / 7
1.0.947 48 / 7
1.0.867 47 / 7
1.0.786 48 / 8
1.0.758 48 / 8
1.0.717 47 / 7
1.0.710 47 / 7
1.0.602 44 / 7
1.0.486 37 / 7
1.0.382 31 / 6
1.0.350 25 / 5
1.0.344 24 / 5
1.0.342 24 / 5
1.0.341 24 / 5
1.0.340 24 / 5
1.0.339 24 / 5
1.0.338 24 / 5
1.0.336 24 / 5
1.0.331 24 / 5
1.0.330 23 / 5
1.0.329 23 / 5
1.0.328 23 / 5
1.0.327 23 / 5
1.0.326 23 / 5
1.0.325 23 / 5
1.0.324 23 / 5
1.0.323 23 / 5
1.0.322 23 / 5
1.0.321 23 / 5
1.0.320 23 / 5
1.0.319 23 / 5
1.0.318 23 / 5
1.0.317 23 / 5
1.0.316 23 / 5
1.0.315 23 / 5
1.0.314 23 / 5
1.0.313 23 / 5
1.0.312 23 / 5
1.0.311 23 / 5
1.0.310 23 / 5
1.0.309 23 / 5
1.0.308 23 / 5
1.0.307 23 / 5
1.0.306 23 / 5
1.0.305 23 / 5
1.0.304 23 / 5
1.0.303 23 / 5
1.0.302 23 / 5
1.0.301 23 / 5
1.0.300 23 / 5
1.0.299 23 / 5
1.0.298 23 / 5
1.0.297 23 / 5
1.0.296 23 / 5
1.0.295 23 / 5
1.0.294 23 / 5
1.0.293 23 / 5
1.0.292 23 / 5
1.0.291 23 / 5
1.0.290 23 / 5
1.0.289 23 / 5
1.0.288 23 / 5
1.0.287 23 / 5
1.0.286 23 / 5
1.0.285 23 / 5
1.0.284 23 / 5
1.0.283 23 / 5
1.0.282 23 / 5
1.0.281 23 / 5
1.0.280 23 / 5
1.0.279 23 / 5
Showing 100 of 374 Next page →

v1.0.1095

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1091

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1087

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.758

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: davidfirst → teambit-owner (on 2025-09-19, known maintainer) provenance

This version was published by a different npm account (teambit-owner) than the most recent previously approved version (davidfirst) on 2025-09-19, but teambit-owner is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.710

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: davidfirst → teambit-owner (on 2025-08-14, known maintainer) provenance

This version was published by a different npm account (teambit-owner) than the most recent previously approved version (davidfirst) on 2025-08-14, but teambit-owner is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.602

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: davidfirst → teambit-owner (on 2025-04-19, known maintainer) provenance

This version was published by a different npm account (teambit-owner) than the most recent previously approved version (davidfirst) on 2025-04-19, but teambit-owner is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.486

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.382

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.350

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.344

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.342

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.341

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.340

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.339

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.338

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.336

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.331

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.330

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.329

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.328

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.327

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.326

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.325

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.324

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.323

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.322

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.321

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.320

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.319

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.318

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.317

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.316

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.315

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.314

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.313

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.312

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.311

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.310

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.309

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.308

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.307

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.306

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.305

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.304

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.303

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.302

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.301

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.300

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.299

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.298

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.297

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.296

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.295

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.294

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.293

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.292

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.291

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.290

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.289

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.288

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.287

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.286

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.285

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.284

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.283

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.282

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.281

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.280

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.279

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.