@teambit/cli-mcp-server
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): davidfirst is a long-standing Teambit contributor (1791 days, 146 approved pkgs); transition appears legitimate. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size growth matches 14 new runtime deps and added spec map file; no obfuscation indicators. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): teambit-owner is the canonical org publisher; maintainer churn within the org is routine housekeeping. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New deps are first-party @teambit/* packages from the same org; not a supply-chain risk. | ai | |
| dependencies | unvetted-dep:@teambit/scope.modules.find-scope-path | AI (dependencies): First-party @teambit scoped package; consistent with the rest of the dependency tree for this package. | ai | |
| dependencies | unvetted-dep:@teambit/scope.remotes | AI (dependencies): Internal @teambit monorepo dependency; same publisher org. | ai | |
| dependencies | unvetted-dep:@teambit/legacy.consumer | AI (dependencies): Internal @teambit monorepo dependency; same publisher org. | ai | |
| dependencies | unvetted-dep:@teambit/legacy.constants | AI (dependencies): Internal @teambit monorepo dependency; same publisher org. | ai | |
| dependencies | unvetted-dep:@teambit/mcp.mcp-config-writer | AI (dependencies): Internal @teambit monorepo dependency; same publisher org. | ai | |
| dependencies | unvetted-dep:@teambit/cli | AI (dependencies): Internal @teambit monorepo dependency; same publisher org, stable pattern across all versions. | ai | |
| dependencies | unvetted-dep:@teambit/pkg.modules.component-package-name | AI (dependencies): Internal @teambit monorepo dependency; same publisher org. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Auto-published monorepo component; missing description is a consistent pattern across all versions. | ai | |
| provenance | no-provenance | AI (provenance): Teambit publishes 500+ versions without provenance; consistent pattern, not a malware signal. | ai | |
| dependencies | unvetted-dep:@teambit/component.modules.component-url | AI (dependencies): Internal @teambit monorepo dependency; same publisher org. | ai | |
| dependencies | unvetted-dep:@teambit/logger | AI (dependencies): Internal @teambit monorepo dependency; same publisher org. | ai | |
| dependencies | unvetted-dep:@teambit/harmony | AI (dependencies): Internal @teambit monorepo dependency; same publisher org. | ai | |
| dependencies | unvetted-dep:@teambit/component-id | AI (dependencies): Internal @teambit monorepo dependency; same publisher org. | ai | |
| dependencies | unvetted-dep:@teambit/scope.network | AI (dependencies): Internal @teambit monorepo dependency; same publisher org. | ai |
Versions (showing 33 of 33)
| Version | Deps | Published |
|---|---|---|
| 0.0.180 | 20 / 7 | |
| 0.0.179 | 20 / 7 | |
| 0.0.178 | 20 / 7 | |
| 0.0.174 | 20 / 7 | |
| 0.0.170 | 20 / 7 | |
| 0.0.169 | 19 / 7 | |
| 0.0.168 | 19 / 7 | |
| 0.0.165 | 19 / 7 | |
| 0.0.164 | 19 / 7 | |
| 0.0.163 | 19 / 7 | |
| 0.0.162 | 19 / 7 | |
| 0.0.157 | 19 / 7 | |
| 0.0.156 | 19 / 7 | |
| 0.0.155 | 19 / 7 | |
| 0.0.154 | 19 / 7 | |
| 0.0.153 | 19 / 7 | |
| 0.0.151 | 19 / 7 | |
| 0.0.145 | 19 / 7 | |
| 0.0.143 | 19 / 7 | |
| 0.0.139 | 19 / 7 | |
| 0.0.138 | 19 / 7 | |
| 0.0.137 | 19 / 7 | |
| 0.0.135 | 19 / 7 | |
| 0.0.131 | 19 / 7 | |
| 0.0.126 | 19 / 7 | |
| 0.0.124 | 19 / 7 | |
| 0.0.121 | 19 / 7 | |
| 0.0.97 | 19 / 7 | |
| 0.0.86 | 14 / 7 | |
| 0.0.12 | 8 / 2 | |
| 0.0.4 | 7 / 1 | |
| 0.0.2 | 5 / 1 | |
| 0.0.1 | 5 / 1 |
v0.0.180
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.179
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.178
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.174
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.170
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.168
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.165
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.164
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.163
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.162
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.157
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.156
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.155
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.151
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.145
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.143
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.139
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.138
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.137
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.135
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.131
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.126
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.124
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.121
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.97
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.86
2 findingsThis version was published by a different npm account than previous versions on 2025-08-19. This could indicate a legitimate maintainer transition or an account compromise.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.