← Home

@teambit/config-merger

100
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

teambit-ownershohamgiladdavidfirstranm8guysaaritaymendelerezbitjoshk2redigmayona007

Keywords

bitbit-aspectbit-core-aspectcomponentscollaborationweb

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@teambit/scope.objects AI (dependencies): First-party Teambit monorepo package, same publisher/org. ai
publish-pattern new-deps-added AI (publish-pattern): First-party @teambit dependency, routine for this monorepo's release cadence. ai
publish-pattern rapid-publish AI (publish-pattern): Monorepo lockstep publishing pattern typical for Teambit packages, not malicious. ai
dependencies unvetted-dep:@teambit/component-id AI (dependencies): Internal @teambit monorepo dependency; stable false positive for this package family. ai
dependencies unvetted-dep:@teambit/legacy.constants AI (dependencies): Internal @teambit monorepo dependency; stable false positive for this package family. ai
dependencies unvetted-dep:@teambit/component-version AI (dependencies): Internal @teambit monorepo dependency; stable false positive for this package family. ai
dependencies unvetted-dep:@teambit/component-package-version AI (dependencies): Internal @teambit monorepo dependency; stable false positive for this package family. ai
dependencies unvetted-dep:@teambit/legacy.consumer-component AI (dependencies): Internal @teambit monorepo dependency; stable false positive for this package family. ai
dependencies unvetted-dep:@teambit/pkg.modules.semver-helper AI (dependencies): Internal @teambit monorepo dependency; stable false positive for this package family. ai
dependencies unvetted-dep:@teambit/component.modules.merge-helper AI (dependencies): Internal @teambit monorepo dependency; stable false positive for this package family. ai
dependencies unvetted-dep:@teambit/legacy.extension-data AI (dependencies): Internal @teambit monorepo dependency; stable false positive for this package family. ai
dependencies unvetted-dep:@teambit/harmony AI (dependencies): Internal @teambit monorepo dependency; stable false positive for this package family. ai
dependencies unvetted-dep:@teambit/bit-error AI (dependencies): Internal @teambit monorepo dependency; stable false positive for this package family. ai
npm-metadata no-description AI (npm-metadata): Teambit monorepo component; missing description is a stable pattern across all @teambit/* packages. ai
provenance no-provenance AI (provenance): No provenance is consistent across all @teambit/* releases; not a risk signal for this publisher. ai

Versions (showing 100 of 284)

Version Deps Published
0.0.931 22 / 4
0.0.927 22 / 4
0.0.923 22 / 4
0.0.922 22 / 4
0.0.919 22 / 4
0.0.918 22 / 4
0.0.904 22 / 4
0.0.903 22 / 4
0.0.900 22 / 4
0.0.899 22 / 4
0.0.898 22 / 4
0.0.897 22 / 4
0.0.896 22 / 4
0.0.893 22 / 4
0.0.892 22 / 4
0.0.891 22 / 4
0.0.890 22 / 4
0.0.889 22 / 4
0.0.888 22 / 4
0.0.887 22 / 4
0.0.886 22 / 4
0.0.885 22 / 4
0.0.884 22 / 4
0.0.883 22 / 4
0.0.882 22 / 4
0.0.881 22 / 4
0.0.880 22 / 4
0.0.879 22 / 4
0.0.878 22 / 4
0.0.877 22 / 4
0.0.876 22 / 4
0.0.875 22 / 4
0.0.874 22 / 4
0.0.872 22 / 4
0.0.871 22 / 4
0.0.870 22 / 4
0.0.869 22 / 4
0.0.868 22 / 4
0.0.867 22 / 4
0.0.866 22 / 4
0.0.865 22 / 4
0.0.864 22 / 4
0.0.862 22 / 4
0.0.861 22 / 4
0.0.842 22 / 4
0.0.841 22 / 4
0.0.839 22 / 4
0.0.838 22 / 4
0.0.837 22 / 4
0.0.836 22 / 4
0.0.835 22 / 4
0.0.831 22 / 4
0.0.797 22 / 4
0.0.792 22 / 4
0.0.383 21 / 4
0.0.376 21 / 4
0.0.375 21 / 4
0.0.374 21 / 4
0.0.369 21 / 4
0.0.358 21 / 4
0.0.356 21 / 4
0.0.354 18 / 4
0.0.352 18 / 4
0.0.351 17 / 4
0.0.350 17 / 4
0.0.349 17 / 4
0.0.348 17 / 4
0.0.347 17 / 4
0.0.346 17 / 4
0.0.345 17 / 4
0.0.344 17 / 4
0.0.343 17 / 4
0.0.342 17 / 4
0.0.341 17 / 4
0.0.340 17 / 4
0.0.339 17 / 4
0.0.338 17 / 4
0.0.337 17 / 4
0.0.336 17 / 4
0.0.335 17 / 4
0.0.334 17 / 4
0.0.333 17 / 4
0.0.332 17 / 4
0.0.331 17 / 4
0.0.330 17 / 4
0.0.329 17 / 4
0.0.328 17 / 4
0.0.327 17 / 4
0.0.326 17 / 4
0.0.325 17 / 4
0.0.324 17 / 4
0.0.323 17 / 4
0.0.322 17 / 4
0.0.321 17 / 4
0.0.320 17 / 4
0.0.319 17 / 4
0.0.318 17 / 4
0.0.317 17 / 4
0.0.316 17 / 4
0.0.315 17 / 4
Showing 100 of 284 Next page →

v0.0.931

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.927

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.923

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.922

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.919

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.918

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.383

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.376

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.375

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.374

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.369

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.358

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.356

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.354

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.352

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.351

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.350

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.349

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.348

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.347

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.346

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.345

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.344

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.343

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.342

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.341

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.340

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.339

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.338

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.337

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.336

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.335

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.334

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.333

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.332

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.331

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.330

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.329

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.328

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.327

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.326

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.325

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.324

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.323

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.322

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.321

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.320

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.319

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.318

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.317

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.316

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.315

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.