@teambit/eslint
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | new-deps-added | AI (publish-pattern): New dep is first-party @teambit scoped package within same monorepo. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): teambit publishes hundreds of coordinated package versions via CI; rapid publish is expected and stable for this org. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Established package; missing description is stable metadata issue, not malware indicator. | ai | |
| provenance | no-provenance | AI (provenance): Provenance absence is a best-practice gap, not a security blocker for this established package. | ai | |
| dependencies | unvetted-dep:@teambit/component | AI (dependencies): Sibling @teambit/* monorepo dependency; consistent with established Bit platform package. | ai | |
| dependencies | unvetted-dep:@teambit/legacy.constants | AI (dependencies): Sibling @teambit/* monorepo dependency; consistent with established Bit platform package. | ai | |
| dependencies | unvetted-dep:@teambit/workspace-config-files | AI (dependencies): Sibling @teambit/* monorepo dependency; consistent with established Bit platform package. | ai | |
| dependencies | unvetted-dep:@teambit/cli | AI (dependencies): Sibling @teambit/* monorepo dependency; consistent with established Bit platform package. | ai | |
| phantom-deps | phantom-dep:@babel/runtime | AI (phantom-deps): Babel runtime is a transitive/convention dependency common in compiled TS packages. | ai | |
| phantom-deps | phantom-dep:@teambit/component | AI (phantom-deps): Same-org sibling; phantom-dep heuristic unreliable for monorepo packages. | ai | |
| dependencies | unvetted-dep:@teambit/defender.eslint.config-mutator | AI (dependencies): Sibling @teambit/* monorepo dependency; consistent with established Bit platform package. | ai | |
| dependencies | unvetted-dep:@teambit/linter | AI (dependencies): Sibling @teambit/* monorepo dependency; consistent with established Bit platform package. | ai | |
| dependencies | unvetted-dep:@teambit/logger | AI (dependencies): Sibling @teambit/* monorepo dependency; consistent with established Bit platform package. | ai | |
| dependencies | unvetted-dep:@teambit/harmony | AI (dependencies): Sibling @teambit/* monorepo dependency; consistent with established Bit platform package. | ai |
Versions (showing 100 of 285)
| Version | Deps | Published |
|---|---|---|
| 1.0.1065 | 14 / 5 | |
| 1.0.1060 | 14 / 5 | |
| 1.0.1053 | 14 / 5 | |
| 1.0.1049 | 14 / 5 | |
| 1.0.1048 | 14 / 5 | |
| 1.0.1046 | 14 / 5 | |
| 1.0.1045 | 14 / 5 | |
| 1.0.1044 | 14 / 5 | |
| 1.0.1042 | 14 / 5 | |
| 1.0.1041 | 14 / 5 | |
| 1.0.1040 | 14 / 5 | |
| 1.0.1039 | 14 / 5 | |
| 1.0.1037 | 14 / 5 | |
| 1.0.1036 | 14 / 5 | |
| 1.0.1034 | 14 / 5 | |
| 1.0.1027 | 14 / 5 | |
| 1.0.1026 | 14 / 5 | |
| 1.0.1012 | 14 / 5 | |
| 1.0.1010 | 14 / 5 | |
| 1.0.1005 | 14 / 5 | |
| 1.0.999 | 14 / 5 | |
| 1.0.998 | 14 / 5 | |
| 1.0.997 | 14 / 5 | |
| 1.0.995 | 14 / 5 | |
| 1.0.984 | 14 / 5 | |
| 1.0.975 | 14 / 5 | |
| 1.0.972 | 14 / 5 | |
| 1.0.971 | 14 / 5 | |
| 1.0.970 | 14 / 5 | |
| 1.0.968 | 14 / 5 | |
| 1.0.955 | 14 / 5 | |
| 1.0.945 | 14 / 5 | |
| 1.0.944 | 14 / 5 | |
| 1.0.943 | 14 / 5 | |
| 1.0.941 | 14 / 5 | |
| 1.0.940 | 14 / 5 | |
| 1.0.939 | 14 / 5 | |
| 1.0.937 | 14 / 5 | |
| 1.0.935 | 14 / 5 | |
| 1.0.934 | 14 / 5 | |
| 1.0.933 | 14 / 5 | |
| 1.0.932 | 14 / 5 | |
| 1.0.931 | 14 / 5 | |
| 1.0.930 | 14 / 5 | |
| 1.0.929 | 14 / 5 | |
| 1.0.928 | 14 / 5 | |
| 1.0.927 | 14 / 5 | |
| 1.0.926 | 14 / 5 | |
| 1.0.865 | 14 / 5 | |
| 1.0.769 | 14 / 5 | |
| 1.0.765 | 14 / 5 | |
| 1.0.762 | 14 / 5 | |
| 1.0.759 | 14 / 5 | |
| 1.0.757 | 14 / 5 | |
| 1.0.749 | 14 / 5 | |
| 1.0.743 | 14 / 5 | |
| 1.0.737 | 14 / 5 | |
| 1.0.728 | 14 / 5 | |
| 1.0.700 | 14 / 5 | |
| 1.0.500 | 14 / 5 | |
| 1.0.488 | 14 / 5 | |
| 1.0.487 | 13 / 5 | |
| 1.0.486 | 13 / 5 | |
| 1.0.485 | 13 / 5 | |
| 1.0.484 | 13 / 5 | |
| 1.0.483 | 13 / 5 | |
| 1.0.482 | 13 / 5 | |
| 1.0.481 | 13 / 5 | |
| 1.0.480 | 13 / 5 | |
| 1.0.479 | 13 / 5 | |
| 1.0.478 | 13 / 5 | |
| 1.0.477 | 13 / 5 | |
| 1.0.476 | 13 / 5 | |
| 1.0.475 | 13 / 5 | |
| 1.0.474 | 13 / 5 | |
| 1.0.473 | 13 / 5 | |
| 1.0.472 | 13 / 5 | |
| 1.0.471 | 13 / 5 | |
| 1.0.470 | 13 / 5 | |
| 1.0.469 | 13 / 5 | |
| 1.0.468 | 13 / 5 | |
| 1.0.467 | 13 / 5 | |
| 1.0.466 | 13 / 5 | |
| 1.0.465 | 13 / 5 | |
| 1.0.464 | 13 / 5 | |
| 1.0.463 | 13 / 5 | |
| 1.0.462 | 13 / 5 | |
| 1.0.461 | 13 / 5 | |
| 1.0.460 | 13 / 5 | |
| 1.0.459 | 13 / 5 | |
| 1.0.458 | 13 / 5 | |
| 1.0.457 | 13 / 5 | |
| 1.0.456 | 13 / 5 | |
| 1.0.455 | 13 / 5 | |
| 1.0.454 | 13 / 5 | |
| 1.0.453 | 13 / 5 | |
| 1.0.452 | 13 / 5 | |
| 1.0.451 | 13 / 5 | |
| 1.0.450 | 13 / 5 | |
| 1.0.449 | 13 / 5 |
v1.0.1065
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1060
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1053
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1049
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1048
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1046
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1045
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1044
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1042
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1041
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1040
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.500
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.488
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (shohamgilad) than the most recent previously approved version (davidfirst) on 2024-12-10, but shohamgilad is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.0.487
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.486
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.485
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.484
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.483
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.482
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.481
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.480
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.479
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.478
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.477
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.476
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.475
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.474
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.473
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.472
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.471
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.470
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.469
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.468
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.467
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.466
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.465
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.464
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.463
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.462
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.461
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.460
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.459
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.458
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.457
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.456
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.455
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.454
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.453
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.452
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.451
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.450
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.449
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.