@teambit/checkout
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | rapid-publish | AI (publish-pattern): teambit uses automated monorepo releases; rapid successive publishes are normal for this package family. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New dep is a same-org sibling at matching version; consistent with teambit monorepo co-release pattern. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Stable for this package; internal monorepo component with componentId metadata. | ai | |
| provenance | no-provenance | AI (provenance): Established package; provenance absence is not a blocker for mature internal packages. | ai | |
| dependencies | unvetted-dep:@teambit/harmony | AI (dependencies): Sibling @teambit/* monorepo dep; not an independent risk. | ai | |
| dependencies | unvetted-dep:@teambit/objects | AI (dependencies): Sibling @teambit/* monorepo dep; not an independent risk. | ai | |
| dependencies | unvetted-dep:@teambit/importer | AI (dependencies): Sibling @teambit/* monorepo dep; not an independent risk. | ai | |
| dependencies | unvetted-dep:@teambit/bit-error | AI (dependencies): Sibling @teambit/* monorepo dep; not an independent risk. | ai | |
| dependencies | unvetted-dep:@teambit/workspace | AI (dependencies): Sibling @teambit/* monorepo dep; not an independent risk. | ai | |
| dependencies | unvetted-dep:@teambit/component-id | AI (dependencies): Sibling @teambit/* monorepo dep; not an independent risk. | ai | |
| dependencies | unvetted-dep:@teambit/legacy.scope | AI (dependencies): Sibling @teambit/* monorepo dep; not an independent risk. | ai | |
| dependencies | unvetted-dep:@teambit/cli | AI (dependencies): Sibling @teambit/* monorepo dep; not an independent risk. | ai | |
| dependencies | unvetted-dep:@teambit/legacy.bit-map | AI (dependencies): Sibling @teambit/* monorepo dep; not an independent risk. | ai | |
| dependencies | unvetted-dep:@teambit/legacy.consumer | AI (dependencies): Sibling @teambit/* monorepo dep; not an independent risk. | ai | |
| dependencies | unvetted-dep:@teambit/component-writer | AI (dependencies): Sibling @teambit/* monorepo dep; not an independent risk. | ai | |
| dependencies | unvetted-dep:@teambit/legacy.constants | AI (dependencies): Sibling @teambit/* monorepo dep; not an independent risk. | ai | |
| dependencies | unvetted-dep:@teambit/component.sources | AI (dependencies): Sibling @teambit/* monorepo dep; not an independent risk. | ai | |
| dependencies | unvetted-dep:@teambit/legacy.consumer-component | AI (dependencies): Sibling @teambit/* monorepo dep; not an independent risk. | ai | |
| dependencies | unvetted-dep:@teambit/component.modules.merge-helper | AI (dependencies): Sibling @teambit/* monorepo dep; not an independent risk. | ai | |
| dependencies | unvetted-dep:@teambit/legacy.utils | AI (dependencies): Sibling @teambit/* monorepo dep; not an independent risk. | ai | |
| dependencies | unvetted-dep:@teambit/lister | AI (dependencies): Sibling @teambit/* monorepo dep; not an independent risk. | ai | |
| dependencies | unvetted-dep:@teambit/logger | AI (dependencies): Sibling @teambit/* monorepo dep; not an independent risk. | ai | |
| dependencies | unvetted-dep:@teambit/remove | AI (dependencies): Sibling @teambit/* monorepo dep; not an independent risk. | ai |
Versions (showing 51 of 103)
| Version | Deps | Published |
|---|---|---|
| 1.0.1065 | 22 / 9 | |
| 1.0.1061 | 22 / 9 | |
| 1.0.1027 | 22 / 9 | |
| 1.0.1022 | 22 / 9 | |
| 1.0.1019 | 22 / 9 | |
| 1.0.1000 | 22 / 9 | |
| 1.0.998 | 22 / 9 | |
| 1.0.996 | 22 / 9 | |
| 1.0.995 | 22 / 9 | |
| 1.0.991 | 22 / 9 | |
| 1.0.973 | 22 / 9 | |
| 1.0.972 | 22 / 9 | |
| 1.0.971 | 22 / 9 | |
| 1.0.969 | 22 / 9 | |
| 1.0.961 | 22 / 9 | |
| 1.0.957 | 22 / 9 | |
| 1.0.956 | 22 / 9 | |
| 1.0.952 | 22 / 9 | |
| 1.0.950 | 22 / 9 | |
| 1.0.946 | 22 / 9 | |
| 1.0.942 | 22 / 9 | |
| 1.0.941 | 22 / 9 | |
| 1.0.937 | 22 / 9 | |
| 1.0.929 | 22 / 9 | |
| 1.0.928 | 22 / 9 | |
| 1.0.926 | 21 / 10 | |
| 1.0.925 | 21 / 10 | |
| 1.0.482 | 16 / 12 | |
| 1.0.332 | 14 / 14 | |
| 1.0.330 | 13 / 14 | |
| 1.0.329 | 13 / 14 | |
| 1.0.328 | 13 / 14 | |
| 1.0.327 | 13 / 14 | |
| 1.0.326 | 13 / 14 | |
| 1.0.325 | 13 / 14 | |
| 1.0.324 | 13 / 14 | |
| 1.0.323 | 13 / 14 | |
| 1.0.322 | 13 / 14 | |
| 1.0.321 | 13 / 14 | |
| 1.0.320 | 13 / 14 | |
| 1.0.319 | 13 / 14 | |
| 1.0.318 | 13 / 14 | |
| 1.0.317 | 13 / 14 | |
| 1.0.316 | 13 / 14 | |
| 1.0.315 | 13 / 14 | |
| 1.0.314 | 13 / 14 | |
| 1.0.313 | 13 / 14 | |
| 1.0.312 | 13 / 14 | |
| 1.0.311 | 13 / 14 | |
| 1.0.310 | 13 / 14 | |
| 1.0.309 | 13 / 14 |
v1.0.1065
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1061
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.482
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.332
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.330
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.329
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.328
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.327
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.326
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.325
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.324
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.323
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.322
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.321
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.320
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.319
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.318
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.317
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.316
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.315
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.314
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.313
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.312
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.311
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.310
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.309
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.