← Home

@teambit/component-log

31
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

teambit-ownershohamgiladdavidfirstranm8guysaaritaymendelerezbitjoshk2redigmayona007

Keywords

bitbit-aspectbit-core-aspectcomponentscollaborationweb

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@teambit/legacy.constants AI (dependencies): First-party teambit monorepo dependency, not third-party unvetted code. ai
publish-pattern new-deps-added AI (publish-pattern): New deps are first-party teambit package and semver; benign monorepo pattern. ai
publish-pattern rapid-publish AI (publish-pattern): Monorepo lockstep publishing pattern typical for Teambit packages, not malicious automation. ai
npm-metadata no-description AI (npm-metadata): Established package with 1562-day history; missing description is metadata gap, not malware indicator. ai
provenance no-provenance AI (provenance): Provenance absence is infrastructure gap; stable across this package's long history. ai
dependencies unvetted-dep:@teambit/scope.remotes AI (dependencies): Sibling @teambit monorepo dep; stable false positive for this package family. ai
dependencies unvetted-dep:@teambit/graph.cleargraph AI (dependencies): Sibling @teambit monorepo dep; stable false positive for this package family. ai
dependencies unvetted-dep:@teambit/cli AI (dependencies): Sibling @teambit monorepo dep; stable false positive for this package family. ai
dependencies unvetted-dep:@teambit/legacy-component-log AI (dependencies): Sibling @teambit monorepo dep; stable false positive for this package family. ai
dependencies unvetted-dep:@teambit/legacy.component-diff AI (dependencies): Sibling @teambit monorepo dep; stable false positive for this package family. ai
dependencies unvetted-dep:@teambit/toolbox.path.path AI (dependencies): Sibling @teambit monorepo dep; stable false positive for this package family. ai
dependencies unvetted-dep:@teambit/harmony AI (dependencies): Sibling @teambit monorepo dep; stable false positive for this package family. ai
dependencies unvetted-dep:@teambit/objects AI (dependencies): Sibling @teambit monorepo dep; stable false positive for this package family. ai
dependencies unvetted-dep:@teambit/workspace AI (dependencies): Sibling @teambit monorepo dep; stable false positive for this package family. ai
dependencies unvetted-dep:@teambit/component-id AI (dependencies): Sibling @teambit monorepo dep; stable false positive for this package family. ai

Versions (showing 31 of 431)

Version Deps Published
1.0.640 17 / 5
1.0.639 17 / 5
1.0.638 17 / 5
1.0.637 17 / 5
1.0.636 17 / 5
1.0.635 17 / 5
1.0.634 17 / 5
1.0.633 17 / 5
1.0.632 17 / 5
1.0.631 17 / 5
1.0.630 17 / 5
1.0.629 17 / 5
1.0.628 17 / 5
1.0.627 17 / 5
1.0.626 17 / 5
1.0.625 17 / 5
1.0.624 17 / 5
1.0.623 17 / 5
1.0.622 17 / 5
1.0.621 17 / 5
1.0.620 17 / 5
1.0.619 17 / 5
1.0.618 17 / 5
1.0.617 17 / 5
1.0.616 17 / 5
1.0.615 17 / 5
1.0.614 17 / 5
1.0.613 17 / 5
1.0.612 17 / 5
1.0.611 17 / 5
1.0.610 17 / 5

v1.0.640

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.639

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.638

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.637

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.636

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.635

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.634

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.633

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.632

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.631

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.630

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.629

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.628

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.627

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.626

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.625

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.624

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.623

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.622

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.621

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.620

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.619

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.618

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.617

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.616

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.615

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.614

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.613

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.612

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.611

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.610

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.