← Home

@teambit/dependencies

51
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

teambit-ownershohamgiladdavidfirstranm8guysaaritaymendelerezbitjoshk2redigmayona007

Keywords

bitbit-aspectbit-core-aspectcomponentscollaborationweb

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff large-new-source-files AI (source-diff): Large monorepo package growth matches added dependency-detector modules, not injected code. ai
publish-pattern new-deps-added AI (publish-pattern): New deps are known detection libs/sibling teambit packages consistent with feature refactor. ai
provenance no-provenance AI (provenance): Unchanged from prior approved version; provenance adoption is a future improvement, not a blocker. ai
npm-metadata no-description AI (npm-metadata): Internal monorepo component, description omission is stable/benign. ai
publish-pattern rapid-publish AI (publish-pattern): Monorepo lockstep releases publish many packages minutes apart; normal for teambit. ai
dependencies unvetted-dep:@teambit/typescript.deps-lookups.lookup-typescript AI (dependencies): First-party @teambit scoped package, consistent with Bit monorepo pattern. ai
dependencies unvetted-dep:@teambit/typescript.deps-detectors.detective-typescript AI (dependencies): First-party @teambit scoped package, consistent with Bit monorepo pattern. ai
dependencies unvetted-dep:@teambit/styling.deps-lookups.lookup-styling AI (dependencies): First-party @teambit scoped package, consistent with Bit monorepo pattern. ai
dependencies unvetted-dep:@teambit/styling.deps-detectors.detective-css AI (dependencies): First-party @teambit scoped package, consistent with Bit monorepo pattern. ai
dependencies unvetted-dep:@teambit/styling.deps-detectors.detective-less AI (dependencies): First-party @teambit scoped package, consistent with Bit monorepo pattern. ai
dependencies unvetted-dep:@teambit/styling.deps-detectors.detective-sass AI (dependencies): First-party @teambit scoped package, consistent with Bit monorepo pattern. ai
dependencies unvetted-dep:@teambit/styling.deps-detectors.detective-scss AI (dependencies): First-party @teambit scoped package, consistent with Bit monorepo pattern. ai
dependencies unvetted-dep:@teambit/legacy.logger AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/legacy.bit-map AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/legacy.consumer AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/component-issues AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/legacy.constants AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/component-version AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/component.sources AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/toolbox.path.path AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/legacy.extension-data AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/legacy.consumer-config AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/legacy.dependency-graph AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/toolbox.fs.last-modified AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/component-package-version AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/legacy.consumer-component AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/toolbox.fs.extension-getter AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/node.deps-detectors.detective-es6 AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/legacy.utils AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/component-id AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/bit-error AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/harmony AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. ai
semgrep semgrep:dynamic-require AI (semgrep): Fires in test spec files loading fixture modules — not a runtime risk for this package. ai

Versions (showing 51 of 88)

View all versions
Version Deps Published
1.0.1072 53 / 12
1.0.1064 52 / 12
1.0.1060 52 / 12
1.0.1021 52 / 12
1.0.1006 52 / 12
1.0.990 52 / 12
1.0.974 52 / 12
1.0.972 52 / 12
1.0.971 52 / 12
1.0.970 52 / 12
1.0.968 52 / 12
1.0.614 52 / 12
1.0.347 44 / 14
1.0.331 43 / 14
1.0.330 22 / 11
1.0.329 22 / 11
1.0.328 22 / 11
1.0.327 22 / 11
1.0.326 22 / 11
1.0.325 22 / 11
1.0.324 22 / 11
1.0.323 22 / 11
1.0.322 21 / 11
1.0.321 21 / 11
1.0.320 21 / 11
1.0.319 21 / 11
1.0.318 20 / 11
1.0.317 20 / 11
1.0.316 20 / 11
1.0.315 20 / 11
1.0.314 20 / 11
1.0.313 20 / 11
1.0.312 20 / 11
1.0.311 20 / 11
1.0.310 20 / 11
1.0.309 20 / 11
1.0.308 20 / 11
1.0.307 20 / 11
1.0.306 20 / 11
1.0.305 20 / 11
1.0.304 20 / 11
1.0.303 20 / 11
1.0.302 20 / 11
1.0.301 20 / 11
1.0.300 20 / 11
1.0.299 20 / 11
1.0.298 20 / 11
1.0.297 20 / 11
1.0.296 20 / 11
1.0.295 20 / 11
1.0.294 20 / 11

v1.0.1072

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1064

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1060

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.614

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.347

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.331

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.330

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.329

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.328

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.327

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.326

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.325

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.324

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.323

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.322

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.321

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.320

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.319

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.318

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.317

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.316

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.315

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.314

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.313

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.312

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.311

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.310

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.309

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.308

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.307

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.306

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.305

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.304

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.303

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.302

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.301

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.300

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.299

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.298

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.297

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.296

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.295

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.294

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.