← Home

@teambit/compositions

51
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

teambit-ownershohamgiladdavidfirstranm8guysaaritaymendelerezbitjoshk2redigmayona007

Keywords

bitbit-aspectbit-core-aspectcomponentscollaborationweb

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern new-deps-added AI (publish-pattern): New deps are first-party @teambit org packages, typical for this monorepo's frequent releases. ai
publish-pattern rapid-publish AI (publish-pattern): Bit monorepo publishes hundreds of packages in lockstep; expected pattern. ai
dependencies unvetted-dep:@teambit/design.inputs.text-area AI (dependencies): Internal @teambit scoped dep; routine for this monorepo-style package. ai
dependencies unvetted-dep:@teambit/design.inputs.date-picker AI (dependencies): Internal @teambit scoped dep; routine for this monorepo-style package. ai
dependencies unvetted-dep:@teambit/legacy.consumer-component AI (dependencies): Internal @teambit scoped dep; routine for this monorepo-style package. ai
dependencies unvetted-dep:@teambit/component.sources AI (dependencies): Internal @teambit scoped dep; routine for this monorepo-style package. ai
dependencies unvetted-dep:@teambit/workspace.ui.use-workspace-mode AI (dependencies): Internal @teambit scoped dep; routine for this monorepo-style package. ai
dependencies unvetted-dep:@teambit/compositions.ui.composition-compare AI (dependencies): Internal @teambit scoped dep; routine for this monorepo-style package. ai
dependencies unvetted-dep:@teambit/compositions.ui.composition-live-controls AI (dependencies): Internal @teambit scoped dep; routine for this monorepo-style package. ai
npm-metadata no-description AI (npm-metadata): Bit core aspects consistently omit descriptions; stable false positive for this package family. ai
provenance no-provenance AI (provenance): Teambit publishes without Sigstore provenance across all versions; not a risk signal here. ai
phantom-deps phantom-dep:@teambit/ui-foundation.ui.constants.z-indexes AI (phantom-deps): Same-org Bit aspect dependency; phantom-dep heuristic unreliable for Bit's module resolution model. ai

Versions (showing 51 of 95)

View all versions
Version Deps Published
1.0.1070 56 / 7
1.0.1064 56 / 7
1.0.1060 56 / 7
1.0.1021 56 / 7
1.0.972 56 / 7
1.0.971 56 / 7
1.0.970 56 / 7
1.0.969 56 / 7
1.0.968 56 / 7
1.0.926 57 / 7
1.0.925 57 / 7
1.0.912 57 / 7
1.0.890 55 / 7
1.0.887 55 / 7
1.0.885 55 / 7
1.0.884 55 / 7
1.0.881 55 / 7
1.0.879 55 / 7
1.0.333 44 / 8
1.0.332 43 / 8
1.0.331 43 / 8
1.0.330 43 / 8
1.0.329 43 / 8
1.0.328 43 / 8
1.0.327 43 / 8
1.0.326 43 / 8
1.0.325 43 / 8
1.0.324 43 / 8
1.0.323 43 / 8
1.0.322 43 / 8
1.0.321 43 / 8
1.0.320 43 / 8
1.0.319 43 / 8
1.0.318 43 / 8
1.0.317 43 / 8
1.0.316 43 / 8
1.0.315 43 / 8
1.0.314 43 / 8
1.0.313 43 / 8
1.0.312 43 / 8
1.0.311 43 / 8
1.0.310 42 / 8
1.0.309 42 / 8
1.0.308 42 / 8
1.0.307 42 / 8
1.0.306 42 / 8
1.0.305 42 / 8
1.0.304 42 / 8
1.0.303 42 / 8
1.0.302 42 / 8
1.0.301 42 / 8

v1.0.1070

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1064

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1060

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.912

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.890

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.333

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.332

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.331

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.330

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.329

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.328

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.327

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.326

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.325

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.324

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.323

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.322

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.321

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.320

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.319

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.318

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.317

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.316

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.315

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.314

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.313

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.312

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.311

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.310

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.309

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.308

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.307

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.306

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.305

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.304

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.303

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.302

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.301

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.