← Home

@teambit/config-merger

51
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

teambit-ownershohamgiladdavidfirstranm8guysaaritaymendelerezbitjoshk2redigmayona007

Keywords

bitbit-aspectbit-core-aspectcomponentscollaborationweb

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@teambit/scope.objects AI (dependencies): First-party Teambit monorepo package, same publisher/org. ai
publish-pattern new-deps-added AI (publish-pattern): First-party @teambit dependency, routine for this monorepo's release cadence. ai
publish-pattern rapid-publish AI (publish-pattern): Monorepo lockstep publishing pattern typical for Teambit packages, not malicious. ai
dependencies unvetted-dep:@teambit/component-id AI (dependencies): Internal @teambit monorepo dependency; stable false positive for this package family. ai
dependencies unvetted-dep:@teambit/legacy.constants AI (dependencies): Internal @teambit monorepo dependency; stable false positive for this package family. ai
dependencies unvetted-dep:@teambit/component-version AI (dependencies): Internal @teambit monorepo dependency; stable false positive for this package family. ai
dependencies unvetted-dep:@teambit/component-package-version AI (dependencies): Internal @teambit monorepo dependency; stable false positive for this package family. ai
dependencies unvetted-dep:@teambit/legacy.consumer-component AI (dependencies): Internal @teambit monorepo dependency; stable false positive for this package family. ai
dependencies unvetted-dep:@teambit/pkg.modules.semver-helper AI (dependencies): Internal @teambit monorepo dependency; stable false positive for this package family. ai
dependencies unvetted-dep:@teambit/component.modules.merge-helper AI (dependencies): Internal @teambit monorepo dependency; stable false positive for this package family. ai
dependencies unvetted-dep:@teambit/legacy.extension-data AI (dependencies): Internal @teambit monorepo dependency; stable false positive for this package family. ai
dependencies unvetted-dep:@teambit/harmony AI (dependencies): Internal @teambit monorepo dependency; stable false positive for this package family. ai
dependencies unvetted-dep:@teambit/bit-error AI (dependencies): Internal @teambit monorepo dependency; stable false positive for this package family. ai
npm-metadata no-description AI (npm-metadata): Teambit monorepo component; missing description is a stable pattern across all @teambit/* packages. ai
provenance no-provenance AI (provenance): No provenance is consistent across all @teambit/* releases; not a risk signal for this publisher. ai

Versions (showing 51 of 284)

View all versions
Version Deps Published
0.0.931 22 / 4
0.0.927 22 / 4
0.0.923 22 / 4
0.0.922 22 / 4
0.0.919 22 / 4
0.0.918 22 / 4
0.0.904 22 / 4
0.0.903 22 / 4
0.0.900 22 / 4
0.0.899 22 / 4
0.0.898 22 / 4
0.0.897 22 / 4
0.0.896 22 / 4
0.0.893 22 / 4
0.0.892 22 / 4
0.0.891 22 / 4
0.0.890 22 / 4
0.0.889 22 / 4
0.0.888 22 / 4
0.0.887 22 / 4
0.0.886 22 / 4
0.0.885 22 / 4
0.0.884 22 / 4
0.0.883 22 / 4
0.0.882 22 / 4
0.0.881 22 / 4
0.0.880 22 / 4
0.0.879 22 / 4
0.0.878 22 / 4
0.0.877 22 / 4
0.0.876 22 / 4
0.0.875 22 / 4
0.0.874 22 / 4
0.0.872 22 / 4
0.0.871 22 / 4
0.0.870 22 / 4
0.0.869 22 / 4
0.0.868 22 / 4
0.0.867 22 / 4
0.0.866 22 / 4
0.0.865 22 / 4
0.0.864 22 / 4
0.0.862 22 / 4
0.0.861 22 / 4
0.0.842 22 / 4
0.0.841 22 / 4
0.0.839 22 / 4
0.0.838 22 / 4
0.0.837 22 / 4
0.0.836 22 / 4
0.0.835 22 / 4

v0.0.931

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.927

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.923

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.922

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.919

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.918

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.