@teambit/dependencies
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@teambit/typescript.deps-detectors.detective-typescript | AI (dependencies): First-party @teambit scoped package, consistent with Bit monorepo pattern. | ai | |
| dependencies | unvetted-dep:@teambit/styling.deps-lookups.lookup-styling | AI (dependencies): First-party @teambit scoped package, consistent with Bit monorepo pattern. | ai | |
| dependencies | unvetted-dep:@teambit/styling.deps-detectors.detective-css | AI (dependencies): First-party @teambit scoped package, consistent with Bit monorepo pattern. | ai | |
| dependencies | unvetted-dep:@teambit/styling.deps-detectors.detective-less | AI (dependencies): First-party @teambit scoped package, consistent with Bit monorepo pattern. | ai | |
| dependencies | unvetted-dep:@teambit/styling.deps-detectors.detective-sass | AI (dependencies): First-party @teambit scoped package, consistent with Bit monorepo pattern. | ai | |
| dependencies | unvetted-dep:@teambit/styling.deps-detectors.detective-scss | AI (dependencies): First-party @teambit scoped package, consistent with Bit monorepo pattern. | ai | |
| dependencies | unvetted-dep:@teambit/typescript.deps-lookups.lookup-typescript | AI (dependencies): First-party @teambit scoped package, consistent with Bit monorepo pattern. | ai | |
| dependencies | unvetted-dep:@teambit/legacy.consumer | AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. | ai | |
| dependencies | unvetted-dep:@teambit/component-issues | AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. | ai | |
| dependencies | unvetted-dep:@teambit/legacy.constants | AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. | ai | |
| dependencies | unvetted-dep:@teambit/component-version | AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. | ai | |
| dependencies | unvetted-dep:@teambit/component.sources | AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. | ai | |
| dependencies | unvetted-dep:@teambit/toolbox.path.path | AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. | ai | |
| dependencies | unvetted-dep:@teambit/legacy.extension-data | AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. | ai | |
| dependencies | unvetted-dep:@teambit/legacy.consumer-config | AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. | ai | |
| dependencies | unvetted-dep:@teambit/legacy.dependency-graph | AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. | ai | |
| dependencies | unvetted-dep:@teambit/toolbox.fs.last-modified | AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. | ai | |
| dependencies | unvetted-dep:@teambit/component-package-version | AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. | ai | |
| dependencies | unvetted-dep:@teambit/legacy.consumer-component | AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. | ai | |
| dependencies | unvetted-dep:@teambit/toolbox.fs.extension-getter | AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. | ai | |
| dependencies | unvetted-dep:@teambit/node.deps-detectors.detective-es6 | AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. | ai | |
| dependencies | unvetted-dep:@teambit/harmony | AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. | ai | |
| dependencies | unvetted-dep:@teambit/bit-error | AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. | ai | |
| dependencies | unvetted-dep:@teambit/component-id | AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. | ai | |
| dependencies | unvetted-dep:@teambit/legacy.utils | AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. | ai | |
| dependencies | unvetted-dep:@teambit/legacy.logger | AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. | ai | |
| dependencies | unvetted-dep:@teambit/legacy.bit-map | AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Fires in test spec files loading fixture modules — not a runtime risk for this package. | ai |
Versions (showing 5 of 5)
| Version | Deps | Published |
|---|---|---|
| 1.0.990 | 52 / 12 | |
| 1.0.972 | 52 / 12 | |
| 1.0.971 | 52 / 12 | |
| 1.0.970 | 52 / 12 | |
| 1.0.968 | 52 / 12 |
v1.0.990
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.972
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.971
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.970
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.