@teambit/component-log
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@teambit/legacy.constants | AI (dependencies): First-party teambit monorepo dependency, not third-party unvetted code. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New deps are first-party teambit package and semver; benign monorepo pattern. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): Monorepo lockstep publishing pattern typical for Teambit packages, not malicious automation. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Established package with 1562-day history; missing description is metadata gap, not malware indicator. | ai | |
| provenance | no-provenance | AI (provenance): Provenance absence is infrastructure gap; stable across this package's long history. | ai | |
| dependencies | unvetted-dep:@teambit/scope.remotes | AI (dependencies): Sibling @teambit monorepo dep; stable false positive for this package family. | ai | |
| dependencies | unvetted-dep:@teambit/graph.cleargraph | AI (dependencies): Sibling @teambit monorepo dep; stable false positive for this package family. | ai | |
| dependencies | unvetted-dep:@teambit/cli | AI (dependencies): Sibling @teambit monorepo dep; stable false positive for this package family. | ai | |
| dependencies | unvetted-dep:@teambit/legacy-component-log | AI (dependencies): Sibling @teambit monorepo dep; stable false positive for this package family. | ai | |
| dependencies | unvetted-dep:@teambit/legacy.component-diff | AI (dependencies): Sibling @teambit monorepo dep; stable false positive for this package family. | ai | |
| dependencies | unvetted-dep:@teambit/toolbox.path.path | AI (dependencies): Sibling @teambit monorepo dep; stable false positive for this package family. | ai | |
| dependencies | unvetted-dep:@teambit/harmony | AI (dependencies): Sibling @teambit monorepo dep; stable false positive for this package family. | ai | |
| dependencies | unvetted-dep:@teambit/objects | AI (dependencies): Sibling @teambit monorepo dep; stable false positive for this package family. | ai | |
| dependencies | unvetted-dep:@teambit/workspace | AI (dependencies): Sibling @teambit monorepo dep; stable false positive for this package family. | ai | |
| dependencies | unvetted-dep:@teambit/component-id | AI (dependencies): Sibling @teambit monorepo dep; stable false positive for this package family. | ai |
Versions (showing 100 of 431)
| Version | Deps | Published |
|---|---|---|
| 1.0.1064 | 17 / 5 | |
| 1.0.1043 | 17 / 5 | |
| 1.0.1042 | 17 / 5 | |
| 1.0.1041 | 17 / 5 | |
| 1.0.1040 | 19 / 6 | |
| 1.0.1039 | 19 / 6 | |
| 1.0.1038 | 19 / 6 | |
| 1.0.1037 | 19 / 6 | |
| 1.0.1036 | 19 / 6 | |
| 1.0.1035 | 19 / 6 | |
| 1.0.1034 | 19 / 6 | |
| 1.0.1033 | 19 / 6 | |
| 1.0.1032 | 19 / 6 | |
| 1.0.1031 | 19 / 6 | |
| 1.0.1030 | 19 / 6 | |
| 1.0.1029 | 19 / 6 | |
| 1.0.1028 | 19 / 6 | |
| 1.0.1027 | 19 / 6 | |
| 1.0.1026 | 17 / 5 | |
| 1.0.1025 | 17 / 5 | |
| 1.0.1024 | 17 / 5 | |
| 1.0.1023 | 17 / 5 | |
| 1.0.1022 | 17 / 5 | |
| 1.0.1021 | 17 / 5 | |
| 1.0.1020 | 17 / 5 | |
| 1.0.1019 | 17 / 5 | |
| 1.0.1018 | 17 / 5 | |
| 1.0.1017 | 17 / 5 | |
| 1.0.1016 | 17 / 5 | |
| 1.0.1015 | 17 / 5 | |
| 1.0.1014 | 17 / 5 | |
| 1.0.1013 | 17 / 5 | |
| 1.0.1012 | 17 / 5 | |
| 1.0.1011 | 17 / 5 | |
| 1.0.1010 | 17 / 5 | |
| 1.0.1009 | 17 / 5 | |
| 1.0.1008 | 17 / 5 | |
| 1.0.1007 | 17 / 5 | |
| 1.0.1006 | 17 / 5 | |
| 1.0.1005 | 17 / 5 | |
| 1.0.1004 | 17 / 5 | |
| 1.0.1003 | 17 / 5 | |
| 1.0.1002 | 17 / 5 | |
| 1.0.1001 | 17 / 5 | |
| 1.0.1000 | 17 / 5 | |
| 1.0.999 | 17 / 5 | |
| 1.0.998 | 17 / 5 | |
| 1.0.997 | 17 / 5 | |
| 1.0.996 | 17 / 5 | |
| 1.0.995 | 17 / 5 | |
| 1.0.994 | 17 / 5 | |
| 1.0.993 | 17 / 5 | |
| 1.0.992 | 17 / 5 | |
| 1.0.991 | 17 / 5 | |
| 1.0.990 | 17 / 5 | |
| 1.0.989 | 17 / 5 | |
| 1.0.988 | 17 / 5 | |
| 1.0.987 | 17 / 5 | |
| 1.0.986 | 17 / 5 | |
| 1.0.985 | 17 / 5 | |
| 1.0.984 | 17 / 5 | |
| 1.0.983 | 17 / 5 | |
| 1.0.982 | 17 / 5 | |
| 1.0.981 | 17 / 5 | |
| 1.0.980 | 17 / 5 | |
| 1.0.979 | 17 / 5 | |
| 1.0.978 | 17 / 5 | |
| 1.0.977 | 17 / 5 | |
| 1.0.976 | 17 / 5 | |
| 1.0.975 | 17 / 5 | |
| 1.0.974 | 17 / 5 | |
| 1.0.973 | 17 / 5 | |
| 1.0.972 | 17 / 5 | |
| 1.0.971 | 17 / 5 | |
| 1.0.970 | 17 / 5 | |
| 1.0.969 | 17 / 5 | |
| 1.0.968 | 17 / 5 | |
| 1.0.967 | 17 / 5 | |
| 1.0.966 | 17 / 5 | |
| 1.0.965 | 17 / 5 | |
| 1.0.964 | 17 / 5 | |
| 1.0.963 | 17 / 5 | |
| 1.0.962 | 17 / 5 | |
| 1.0.961 | 17 / 5 | |
| 1.0.960 | 17 / 5 | |
| 1.0.959 | 17 / 5 | |
| 1.0.958 | 17 / 5 | |
| 1.0.957 | 17 / 5 | |
| 1.0.956 | 17 / 5 | |
| 1.0.955 | 17 / 5 | |
| 1.0.954 | 17 / 5 | |
| 1.0.953 | 17 / 5 | |
| 1.0.952 | 17 / 5 | |
| 1.0.951 | 17 / 5 | |
| 1.0.950 | 17 / 5 | |
| 1.0.949 | 17 / 5 | |
| 1.0.948 | 17 / 5 | |
| 1.0.947 | 17 / 5 | |
| 1.0.946 | 17 / 5 | |
| 1.0.945 | 17 / 5 |
v1.0.1064
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1043
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1042
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1041
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1040
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1002
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.993
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.992
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.991
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.990
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.989
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.988
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.987
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.986
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.985
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.984
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.983
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.982
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.981
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.980
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.979
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.978
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.977
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.976
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.973
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.965
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.963
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.960
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.956
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.955
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.954
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.952
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.950
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.