← Home

@teambit/dependencies

88
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

teambit-ownershohamgiladdavidfirstranm8guysaaritaymendelerezbitjoshk2redigmayona007

Keywords

bitbit-aspectbit-core-aspectcomponentscollaborationweb

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff large-new-source-files AI (source-diff): Large monorepo package growth matches added dependency-detector modules, not injected code. ai
publish-pattern new-deps-added AI (publish-pattern): New deps are known detection libs/sibling teambit packages consistent with feature refactor. ai
provenance no-provenance AI (provenance): Unchanged from prior approved version; provenance adoption is a future improvement, not a blocker. ai
npm-metadata no-description AI (npm-metadata): Internal monorepo component, description omission is stable/benign. ai
publish-pattern rapid-publish AI (publish-pattern): Monorepo lockstep releases publish many packages minutes apart; normal for teambit. ai
dependencies unvetted-dep:@teambit/typescript.deps-lookups.lookup-typescript AI (dependencies): First-party @teambit scoped package, consistent with Bit monorepo pattern. ai
dependencies unvetted-dep:@teambit/typescript.deps-detectors.detective-typescript AI (dependencies): First-party @teambit scoped package, consistent with Bit monorepo pattern. ai
dependencies unvetted-dep:@teambit/styling.deps-lookups.lookup-styling AI (dependencies): First-party @teambit scoped package, consistent with Bit monorepo pattern. ai
dependencies unvetted-dep:@teambit/styling.deps-detectors.detective-css AI (dependencies): First-party @teambit scoped package, consistent with Bit monorepo pattern. ai
dependencies unvetted-dep:@teambit/styling.deps-detectors.detective-less AI (dependencies): First-party @teambit scoped package, consistent with Bit monorepo pattern. ai
dependencies unvetted-dep:@teambit/styling.deps-detectors.detective-sass AI (dependencies): First-party @teambit scoped package, consistent with Bit monorepo pattern. ai
dependencies unvetted-dep:@teambit/styling.deps-detectors.detective-scss AI (dependencies): First-party @teambit scoped package, consistent with Bit monorepo pattern. ai
dependencies unvetted-dep:@teambit/legacy.logger AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/legacy.bit-map AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/legacy.consumer AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/component-issues AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/legacy.constants AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/component-version AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/component.sources AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/toolbox.path.path AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/legacy.extension-data AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/legacy.consumer-config AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/legacy.dependency-graph AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/toolbox.fs.last-modified AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/component-package-version AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/legacy.consumer-component AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/toolbox.fs.extension-getter AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/node.deps-detectors.detective-es6 AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/legacy.utils AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/component-id AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/bit-error AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. ai
dependencies unvetted-dep:@teambit/harmony AI (dependencies): First-party @teambit org dependency; stable pattern across all versions. ai
semgrep semgrep:dynamic-require AI (semgrep): Fires in test spec files loading fixture modules — not a runtime risk for this package. ai

Versions (showing 88 of 88)

Version Deps Published
1.0.1072 53 / 12
1.0.1064 52 / 12
1.0.1060 52 / 12
1.0.1021 52 / 12
1.0.1006 52 / 12
1.0.990 52 / 12
1.0.974 52 / 12
1.0.972 52 / 12
1.0.971 52 / 12
1.0.970 52 / 12
1.0.968 52 / 12
1.0.614 52 / 12
1.0.347 44 / 14
1.0.331 43 / 14
1.0.330 22 / 11
1.0.329 22 / 11
1.0.328 22 / 11
1.0.327 22 / 11
1.0.326 22 / 11
1.0.325 22 / 11
1.0.324 22 / 11
1.0.323 22 / 11
1.0.322 21 / 11
1.0.321 21 / 11
1.0.320 21 / 11
1.0.319 21 / 11
1.0.318 20 / 11
1.0.317 20 / 11
1.0.316 20 / 11
1.0.315 20 / 11
1.0.314 20 / 11
1.0.313 20 / 11
1.0.312 20 / 11
1.0.311 20 / 11
1.0.310 20 / 11
1.0.309 20 / 11
1.0.308 20 / 11
1.0.307 20 / 11
1.0.306 20 / 11
1.0.305 20 / 11
1.0.304 20 / 11
1.0.303 20 / 11
1.0.302 20 / 11
1.0.301 20 / 11
1.0.300 20 / 11
1.0.299 20 / 11
1.0.298 20 / 11
1.0.297 20 / 11
1.0.296 20 / 11
1.0.295 20 / 11
1.0.294 20 / 11
1.0.293 20 / 11
1.0.292 20 / 11
1.0.291 20 / 11
1.0.290 20 / 11
1.0.289 20 / 11
1.0.288 20 / 11
1.0.287 20 / 11
1.0.286 20 / 11
1.0.285 20 / 11
1.0.284 20 / 11
1.0.283 20 / 11
1.0.282 20 / 11
1.0.281 20 / 11
1.0.280 20 / 11
1.0.279 20 / 11
1.0.278 20 / 11
1.0.277 20 / 11
1.0.276 20 / 11
1.0.275 20 / 11
1.0.274 20 / 11
1.0.273 20 / 11
1.0.272 20 / 11
1.0.271 20 / 11
1.0.270 20 / 11
1.0.269 20 / 11
1.0.268 20 / 11
1.0.267 20 / 11
1.0.266 20 / 11
1.0.265 20 / 11
1.0.264 20 / 11
1.0.263 20 / 11
1.0.262 20 / 11
1.0.261 20 / 11
1.0.260 20 / 11
1.0.259 20 / 11
1.0.258 20 / 11
1.0.257 20 / 11

v1.0.1072

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1064

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1060

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.614

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.347

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.331

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.330

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.329

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.328

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.327

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.326

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.325

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.324

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.323

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.322

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.321

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.320

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.319

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.318

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.317

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.316

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.315

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.314

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.313

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.312

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.311

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.310

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.309

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.308

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.307

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.306

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.305

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.304

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.303

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.302

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.301

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.300

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.299

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.298

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.297

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.296

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.295

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.294

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.293

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.292

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.291

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.290

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.289

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.288

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.287

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.286

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.285

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.284

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.283

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.282

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.281

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.280

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.279

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.278

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.277

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.276

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.275

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.274

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.273

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.272

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.271

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.270

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.269

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.268

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.267

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.266

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.265

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.264

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.263

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.262

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.261

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.260

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.259

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.258

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: davidfirst → shohamgilad (on 2024-04-30, known maintainer) provenance

This version was published by a different npm account (shohamgilad) than the most recent previously approved version (davidfirst) on 2024-04-30, but shohamgilad is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.257

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.