← Home

@teambit/envs

7
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

teambit-ownershohamgiladdavidfirstranm8guysaaritaymendelerezbitjoshk2redigmayona007

Keywords

bitbit-aspectbit-core-aspectcomponentscollaborationweb

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@teambit/toolbox.array.duplications-finder AI (dependencies): Internal @teambit monorepo dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/legacy.extension-data AI (dependencies): Internal @teambit monorepo dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/legacy.consumer-component AI (dependencies): Internal @teambit monorepo dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/harmony AI (dependencies): Internal @teambit monorepo dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/bit-error AI (dependencies): Internal @teambit monorepo dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/cli-table AI (dependencies): Internal @teambit monorepo dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/component-id AI (dependencies): Internal @teambit monorepo dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/component-issues AI (dependencies): Internal @teambit monorepo dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/component.sources AI (dependencies): Internal @teambit monorepo dep; stable pattern across all versions of this package. ai
provenance no-provenance AI (provenance): Teambit does not publish with Sigstore provenance; consistent across all 2844 versions. ai
npm-metadata no-description AI (npm-metadata): Bit aspect packages consistently omit npm descriptions; stable pattern across all @teambit/* packages. ai

Versions (showing 7 of 7)

Version Deps Published
1.0.995 36 / 4
1.0.972 36 / 4
1.0.971 36 / 4
1.0.970 36 / 4
1.0.969 36 / 4
1.0.968 36 / 4
1.0.925 36 / 4

v1.0.995

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.972

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.971

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.970

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.969

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.