@teambit/eslint
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | new-deps-added | AI (publish-pattern): New dep is first-party @teambit scoped package within same monorepo. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): teambit publishes hundreds of coordinated package versions via CI; rapid publish is expected and stable for this org. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Established package; missing description is stable metadata issue, not malware indicator. | ai | |
| provenance | no-provenance | AI (provenance): Provenance absence is a best-practice gap, not a security blocker for this established package. | ai | |
| dependencies | unvetted-dep:@teambit/component | AI (dependencies): Sibling @teambit/* monorepo dependency; consistent with established Bit platform package. | ai | |
| dependencies | unvetted-dep:@teambit/legacy.constants | AI (dependencies): Sibling @teambit/* monorepo dependency; consistent with established Bit platform package. | ai | |
| dependencies | unvetted-dep:@teambit/workspace-config-files | AI (dependencies): Sibling @teambit/* monorepo dependency; consistent with established Bit platform package. | ai | |
| dependencies | unvetted-dep:@teambit/cli | AI (dependencies): Sibling @teambit/* monorepo dependency; consistent with established Bit platform package. | ai | |
| phantom-deps | phantom-dep:@babel/runtime | AI (phantom-deps): Babel runtime is a transitive/convention dependency common in compiled TS packages. | ai | |
| phantom-deps | phantom-dep:@teambit/component | AI (phantom-deps): Same-org sibling; phantom-dep heuristic unreliable for monorepo packages. | ai | |
| dependencies | unvetted-dep:@teambit/defender.eslint.config-mutator | AI (dependencies): Sibling @teambit/* monorepo dependency; consistent with established Bit platform package. | ai | |
| dependencies | unvetted-dep:@teambit/linter | AI (dependencies): Sibling @teambit/* monorepo dependency; consistent with established Bit platform package. | ai | |
| dependencies | unvetted-dep:@teambit/logger | AI (dependencies): Sibling @teambit/* monorepo dependency; consistent with established Bit platform package. | ai | |
| dependencies | unvetted-dep:@teambit/harmony | AI (dependencies): Sibling @teambit/* monorepo dependency; consistent with established Bit platform package. | ai |
Versions (showing 51 of 285)
| Version | Deps | Published |
|---|---|---|
| 1.0.1065 | 14 / 5 | |
| 1.0.1060 | 14 / 5 | |
| 1.0.1053 | 14 / 5 | |
| 1.0.1049 | 14 / 5 | |
| 1.0.1048 | 14 / 5 | |
| 1.0.1046 | 14 / 5 | |
| 1.0.1045 | 14 / 5 | |
| 1.0.1044 | 14 / 5 | |
| 1.0.1042 | 14 / 5 | |
| 1.0.1041 | 14 / 5 | |
| 1.0.1040 | 14 / 5 | |
| 1.0.1039 | 14 / 5 | |
| 1.0.1037 | 14 / 5 | |
| 1.0.1036 | 14 / 5 | |
| 1.0.1034 | 14 / 5 | |
| 1.0.1027 | 14 / 5 | |
| 1.0.1026 | 14 / 5 | |
| 1.0.1012 | 14 / 5 | |
| 1.0.1010 | 14 / 5 | |
| 1.0.1005 | 14 / 5 | |
| 1.0.999 | 14 / 5 | |
| 1.0.998 | 14 / 5 | |
| 1.0.997 | 14 / 5 | |
| 1.0.995 | 14 / 5 | |
| 1.0.984 | 14 / 5 | |
| 1.0.975 | 14 / 5 | |
| 1.0.972 | 14 / 5 | |
| 1.0.971 | 14 / 5 | |
| 1.0.970 | 14 / 5 | |
| 1.0.968 | 14 / 5 | |
| 1.0.955 | 14 / 5 | |
| 1.0.945 | 14 / 5 | |
| 1.0.944 | 14 / 5 | |
| 1.0.943 | 14 / 5 | |
| 1.0.941 | 14 / 5 | |
| 1.0.940 | 14 / 5 | |
| 1.0.939 | 14 / 5 | |
| 1.0.937 | 14 / 5 | |
| 1.0.935 | 14 / 5 | |
| 1.0.934 | 14 / 5 | |
| 1.0.933 | 14 / 5 | |
| 1.0.932 | 14 / 5 | |
| 1.0.931 | 14 / 5 | |
| 1.0.930 | 14 / 5 | |
| 1.0.929 | 14 / 5 | |
| 1.0.928 | 14 / 5 | |
| 1.0.927 | 14 / 5 | |
| 1.0.926 | 14 / 5 | |
| 1.0.865 | 14 / 5 | |
| 1.0.769 | 14 / 5 | |
| 1.0.765 | 14 / 5 |
v1.0.1065
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1060
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1053
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1049
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1048
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1046
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1045
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1044
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1042
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1041
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1040
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.