@teambit/command-bar
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@teambit/workspace.ui.use-workspace-mode | AI (dependencies): First-party teambit monorepo dependency, consistent with package's ecosystem. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New dep is a first-party @teambit package, typical for this monorepo. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): Monorepo lockstep releases publish many @teambit packages in quick succession; benign pattern. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Established package with 2900+ versions; missing description is stable metadata pattern. | ai | |
| provenance | no-provenance | AI (provenance): Long-standing package; provenance absence is consistent across versions. | ai | |
| dependencies | unvetted-dep:@teambit/base-ui.text.muted-text | AI (dependencies): Sibling @teambit/* package from same monorepo; unvetted status is a registry gap, not a risk. | ai | |
| dependencies | unvetted-dep:@teambit/explorer.ui.command-bar | AI (dependencies): Sibling @teambit/* package from same monorepo; unvetted status is a registry gap, not a risk. | ai | |
| dependencies | unvetted-dep:@teambit/ui-foundation.ui.keycap | AI (dependencies): Sibling @teambit/* package from same monorepo; unvetted status is a registry gap, not a risk. | ai | |
| dependencies | unvetted-dep:@teambit/ui | AI (dependencies): Sibling @teambit/* package from same monorepo; unvetted status is a registry gap, not a risk. | ai | |
| dependencies | unvetted-dep:@teambit/ui-foundation.ui.is-browser | AI (dependencies): Sibling @teambit/* package from same monorepo; unvetted status is a registry gap, not a risk. | ai | |
| dependencies | unvetted-dep:@teambit/design.buttons.action-button | AI (dependencies): Sibling @teambit/* package from same monorepo; unvetted status is a registry gap, not a risk. | ai | |
| dependencies | unvetted-dep:@teambit/design.ui.styles.ellipsis | AI (dependencies): Sibling @teambit/* package from same monorepo; unvetted status is a registry gap, not a risk. | ai | |
| dependencies | unvetted-dep:@teambit/pubsub | AI (dependencies): Sibling @teambit/* package from same monorepo; unvetted status is a registry gap, not a risk. | ai | |
| dependencies | unvetted-dep:@teambit/harmony | AI (dependencies): Sibling @teambit/* package from same monorepo; unvetted status is a registry gap, not a risk. | ai | |
| dependencies | unvetted-dep:@teambit/bit-error | AI (dependencies): Sibling @teambit/* package from same monorepo; unvetted status is a registry gap, not a risk. | ai | |
| dependencies | unvetted-dep:@teambit/react-router | AI (dependencies): Sibling @teambit/* package from same monorepo; unvetted status is a registry gap, not a risk. | ai |
Versions (showing 100 of 494)
| Version | Deps | Published |
|---|---|---|
| 1.0.667 | 16 / 6 | |
| 1.0.666 | 16 / 6 | |
| 1.0.665 | 16 / 6 | |
| 1.0.664 | 16 / 6 | |
| 1.0.663 | 16 / 6 | |
| 1.0.662 | 16 / 6 | |
| 1.0.661 | 16 / 6 | |
| 1.0.659 | 16 / 6 | |
| 1.0.658 | 16 / 6 | |
| 1.0.657 | 16 / 6 | |
| 1.0.656 | 16 / 6 | |
| 1.0.655 | 16 / 6 | |
| 1.0.654 | 16 / 6 | |
| 1.0.653 | 16 / 6 | |
| 1.0.652 | 16 / 6 | |
| 1.0.651 | 16 / 6 | |
| 1.0.650 | 16 / 6 | |
| 1.0.649 | 16 / 6 | |
| 1.0.647 | 16 / 6 | |
| 1.0.646 | 16 / 6 | |
| 1.0.645 | 16 / 6 | |
| 1.0.644 | 16 / 6 | |
| 1.0.642 | 16 / 6 | |
| 1.0.641 | 16 / 6 | |
| 1.0.640 | 16 / 6 | |
| 1.0.639 | 16 / 6 | |
| 1.0.638 | 16 / 6 | |
| 1.0.637 | 16 / 6 | |
| 1.0.635 | 16 / 6 | |
| 1.0.634 | 16 / 6 | |
| 1.0.633 | 16 / 6 | |
| 1.0.632 | 16 / 6 | |
| 1.0.631 | 16 / 6 | |
| 1.0.630 | 16 / 6 | |
| 1.0.628 | 16 / 6 | |
| 1.0.627 | 16 / 6 | |
| 1.0.626 | 16 / 6 | |
| 1.0.625 | 16 / 6 | |
| 1.0.624 | 16 / 6 | |
| 1.0.622 | 16 / 6 | |
| 1.0.621 | 16 / 6 | |
| 1.0.620 | 16 / 6 | |
| 1.0.619 | 16 / 6 | |
| 1.0.618 | 16 / 6 | |
| 1.0.617 | 16 / 6 | |
| 1.0.615 | 16 / 6 | |
| 1.0.614 | 16 / 6 | |
| 1.0.613 | 16 / 6 | |
| 1.0.612 | 16 / 6 | |
| 1.0.611 | 16 / 6 | |
| 1.0.610 | 16 / 6 | |
| 1.0.431 | 15 / 6 | |
| 1.0.430 | 15 / 6 | |
| 1.0.428 | 15 / 6 | |
| 1.0.426 | 15 / 6 | |
| 1.0.424 | 15 / 6 | |
| 1.0.422 | 15 / 6 | |
| 1.0.421 | 15 / 6 | |
| 1.0.418 | 15 / 6 | |
| 1.0.416 | 15 / 6 | |
| 1.0.413 | 15 / 6 | |
| 1.0.412 | 15 / 6 | |
| 1.0.411 | 15 / 7 | |
| 1.0.410 | 15 / 7 | |
| 1.0.409 | 15 / 7 | |
| 1.0.407 | 15 / 7 | |
| 1.0.406 | 15 / 7 | |
| 1.0.405 | 15 / 7 | |
| 1.0.402 | 15 / 7 | |
| 1.0.401 | 15 / 7 | |
| 1.0.400 | 15 / 7 | |
| 1.0.399 | 15 / 7 | |
| 1.0.398 | 15 / 7 | |
| 1.0.396 | 15 / 7 | |
| 1.0.395 | 15 / 7 | |
| 1.0.394 | 15 / 7 | |
| 1.0.393 | 15 / 7 | |
| 1.0.391 | 15 / 7 | |
| 1.0.389 | 15 / 7 | |
| 1.0.388 | 15 / 7 | |
| 1.0.387 | 15 / 7 | |
| 1.0.386 | 15 / 7 | |
| 1.0.383 | 15 / 7 | |
| 1.0.381 | 15 / 7 | |
| 1.0.379 | 15 / 7 | |
| 1.0.378 | 15 / 7 | |
| 1.0.377 | 15 / 7 | |
| 1.0.376 | 15 / 7 | |
| 1.0.375 | 15 / 7 | |
| 1.0.374 | 15 / 7 | |
| 1.0.373 | 15 / 7 | |
| 1.0.372 | 15 / 7 | |
| 1.0.371 | 15 / 7 | |
| 1.0.370 | 15 / 7 | |
| 1.0.369 | 15 / 7 | |
| 1.0.360 | 15 / 7 | |
| 1.0.357 | 15 / 7 | |
| 1.0.356 | 15 / 7 | |
| 1.0.355 | 15 / 7 | |
| 1.0.353 | 15 / 7 |
v1.0.667
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.666
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.665
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.664
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.663
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.662
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.661
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.659
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.658
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.657
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.656
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.655
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.654
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.653
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.652
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.651
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.650
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.649
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.647
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.646
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.645
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.644
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.642
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.641
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.640
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.639
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.638
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.637
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.635
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.634
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.633
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.632
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.631
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.630
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.628
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.627
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.626
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.625
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.624
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.622
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.621
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.620
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.619
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.618
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.617
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.615
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.614
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.613
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.612
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.611
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.610
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.431
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.430
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.428
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.426
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.424
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.422
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.421
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.418
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.416
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.413
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.412
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.411
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.410
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.409
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.407
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.406
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.405
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.402
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.401
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.400
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.399
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.398
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.396
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.395
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.394
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.393
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.391
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.389
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.388
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.387
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.386
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.383
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.381
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.379
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.378
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.377
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.376
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.375
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.374
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.373
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.372
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.371
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.370
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.369
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.360
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.357
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.356
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.355
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.353
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.