@teambit/component-descriptor
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Versions (showing 35 of 35)
| Version | Deps | Published |
|---|---|---|
| 0.0.457 | 0 / 4 | |
| 0.0.456 | 0 / 4 | |
| 0.0.455 | 0 / 4 | |
| 0.0.454 | 0 / 4 | |
| 0.0.453 | 0 / 4 | |
| 0.0.452 | 0 / 4 | |
| 0.0.451 | 0 / 4 | |
| 0.0.450 | 0 / 4 | |
| 0.0.449 | 0 / 4 | |
| 0.0.448 | 0 / 4 | |
| 0.0.447 | 0 / 4 | |
| 0.0.446 | 0 / 4 | |
| 0.0.445 | 0 / 4 | |
| 0.0.444 | 0 / 4 | |
| 0.0.443 | 0 / 4 | |
| 0.0.440 | 0 / 4 | |
| 0.0.439 | 0 / 4 | |
| 0.0.438 | 0 / 4 | |
| 0.0.437 | 0 / 4 | |
| 0.0.436 | 0 / 4 | |
| 0.0.435 | 0 / 4 | |
| 0.0.433 | 0 / 4 | |
| 0.0.432 | 0 / 4 | |
| 0.0.431 | 0 / 4 | |
| 0.0.430 | 0 / 5 | |
| 0.0.429 | 0 / 5 | |
| 0.0.428 | 0 / 5 | |
| 0.0.427 | 0 / 5 | |
| 0.0.426 | 0 / 5 | |
| 0.0.425 | 0 / 5 | |
| 0.0.424 | 0 / 5 | |
| 0.0.423 | 0 / 6 | |
| 0.0.422 | 0 / 6 | |
| 0.0.421 | 0 / 6 | |
| 0.0.420 | 0 / 6 |
v0.0.457
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.456
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.455
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.435
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (teambit-owner) than the most recent previously approved version (davidfirst) on 2025-04-16, but teambit-owner is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.0.433
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.432
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.431
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.430
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.429
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.428
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.427
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.426
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.425
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.424
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.423
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.422
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.421
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.420
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.