← Home

@teambit/builder

29
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

teambit-ownershohamgiladdavidfirstranm8guysaaritaymendelerezbitjoshk2redigmayona007

Keywords

bitbit-aspectbit-core-aspectcomponentscollaborationweb

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@teambit/toolbox.array.duplications-finder AI (dependencies): Internal @teambit sibling dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/legacy.consumer-component AI (dependencies): Internal @teambit sibling dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/toolbox.string.capitalize AI (dependencies): Internal @teambit sibling dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/harmony AI (dependencies): Internal @teambit sibling dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/lane-id AI (dependencies): Internal @teambit sibling dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/bit-error AI (dependencies): Internal @teambit sibling dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/component-id AI (dependencies): Internal @teambit sibling dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/legacy.scope AI (dependencies): Internal @teambit sibling dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/legacy.utils AI (dependencies): Internal @teambit sibling dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/component-issues AI (dependencies): Internal @teambit sibling dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/graph.cleargraph AI (dependencies): Internal @teambit sibling dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/legacy.constants AI (dependencies): Internal @teambit sibling dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/component.sources AI (dependencies): Internal @teambit sibling dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/bit.get-bit-version AI (dependencies): Internal @teambit sibling dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/legacy.extension-data AI (dependencies): Internal @teambit sibling dep; stable pattern across all versions of this package. ai
provenance no-provenance AI (provenance): No provenance is consistent across all @teambit monorepo releases; not a risk signal here. ai
npm-metadata no-description AI (npm-metadata): Automated monorepo publish; missing description is a stable pattern for @teambit packages. ai

Versions (showing 29 of 29)

Version Deps Published
1.0.972 41 / 9
1.0.971 41 / 9
1.0.970 41 / 9
1.0.968 41 / 9
1.0.967 41 / 9
1.0.964 41 / 9
1.0.963 41 / 9
1.0.960 41 / 9
1.0.957 41 / 9
1.0.955 41 / 9
1.0.954 41 / 9
1.0.953 41 / 9
1.0.951 41 / 9
1.0.949 41 / 9
1.0.948 41 / 9
1.0.947 41 / 9
1.0.945 41 / 9
1.0.944 41 / 9
1.0.943 41 / 9
1.0.940 41 / 9
1.0.939 41 / 9
1.0.938 41 / 9
1.0.937 41 / 9
1.0.934 41 / 9
1.0.933 41 / 9
1.0.931 41 / 9
1.0.930 41 / 9
1.0.927 41 / 9
1.0.925 41 / 9

v1.0.972

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.971

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.970

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.