← Home

@teambit/graph

4
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

teambit-ownershohamgiladdavidfirstranm8guysaaritaymendelerezbitjoshk2redigmayona007

Keywords

bitbit-aspectbit-core-aspectcomponentscollaborationweb

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@teambit/component.ui.component-compare.models.component-compare-props AI (dependencies): Internal @teambit sub-package; consistent with this package's established dependency pattern. ai
dependencies unvetted-dep:@teambit/component.ui.component-compare.models.component-compare-change-type AI (dependencies): Internal @teambit sub-package; consistent with this package's established dependency pattern. ai
dependencies unvetted-dep:@teambit/component.ui.component-compare.status-resolver AI (dependencies): First-party @teambit sibling dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/component.ui.component-compare.context AI (dependencies): First-party @teambit sibling dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/ui-foundation.ui.react-router.use-query AI (dependencies): First-party @teambit sibling dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/harmony AI (dependencies): First-party @teambit sibling dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/component-id AI (dependencies): First-party @teambit sibling dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/scope.remotes AI (dependencies): First-party @teambit sibling dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/envs.ui.env-icon AI (dependencies): First-party @teambit sibling dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/graph.cleargraph AI (dependencies): First-party @teambit sibling dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/base-ui.surfaces.card AI (dependencies): First-party @teambit sibling dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/design.ui.round-loader AI (dependencies): First-party @teambit sibling dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/base-ui.text.muted-text AI (dependencies): First-party @teambit sibling dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/legacy.dependency-graph AI (dependencies): First-party @teambit sibling dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/base-ui.routing.nav-link AI (dependencies): First-party @teambit sibling dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/design.ui.pages.not-found AI (dependencies): First-party @teambit sibling dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/design.ui.styles.ellipsis AI (dependencies): First-party @teambit sibling dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/design.ui.pages.server-error AI (dependencies): First-party @teambit sibling dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/component.ui.deprecation-icon AI (dependencies): First-party @teambit sibling dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/design.skeletons.base-skeleton AI (dependencies): First-party @teambit sibling dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/component.modules.component-url AI (dependencies): First-party @teambit sibling dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/evangelist.input.checkbox.label AI (dependencies): First-party @teambit sibling dep; stable pattern across all versions of this package. ai
provenance no-provenance AI (provenance): Teambit packages do not use Sigstore provenance; consistent across the ecosystem. ai
npm-metadata no-description AI (npm-metadata): Teambit monorepo packages consistently omit npm descriptions; stable false positive for this publisher. ai

Versions (showing 4 of 4)

Version Deps Published
1.0.972 35 / 6
1.0.971 35 / 6
1.0.970 35 / 6
1.0.968 35 / 6

v1.0.972

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.971

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.970

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.