← Home

@teambit/insights

100
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

teambit-ownershohamgiladdavidfirstranm8guysaaritaymendelerezbitjoshk2redigmayona007

Keywords

bitbit-aspectbit-core-aspectcomponentscollaborationweb

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
npm-metadata no-description AI (npm-metadata): Established package with 2946 versions; missing description is stable metadata gap, not malware signal. ai
provenance no-provenance AI (provenance): Provenance absence is a best-practice gap, not a security blocker for established packages. ai
dependencies unvetted-dep:@teambit/issues AI (dependencies): Sibling @teambit/* monorepo dep; stable pattern across all teambit package versions. ai
dependencies unvetted-dep:@teambit/harmony AI (dependencies): Sibling @teambit/* monorepo dep; stable pattern across all teambit package versions. ai
dependencies unvetted-dep:@teambit/bit-error AI (dependencies): Sibling @teambit/* monorepo dep; stable pattern across all teambit package versions. ai
dependencies unvetted-dep:@teambit/cli AI (dependencies): Sibling @teambit/* monorepo dep; stable pattern across all teambit package versions. ai
dependencies unvetted-dep:@teambit/component-id AI (dependencies): Sibling @teambit/* monorepo dep; stable pattern across all teambit package versions. ai
dependencies unvetted-dep:@teambit/component-issues AI (dependencies): Sibling @teambit/* monorepo dep; stable pattern across all teambit package versions. ai
dependencies unvetted-dep:@teambit/component AI (dependencies): Sibling @teambit/* monorepo dep; stable pattern across all teambit package versions. ai
dependencies unvetted-dep:@teambit/graph AI (dependencies): Sibling @teambit/* monorepo dep; stable pattern across all teambit package versions. ai

Versions (showing 100 of 395)

Version Deps Published
1.0.1008 12 / 4
1.0.1007 12 / 4
1.0.1006 12 / 4
1.0.1005 12 / 4
1.0.1004 12 / 4
1.0.1003 12 / 4
1.0.1002 12 / 4
1.0.1001 12 / 4
1.0.1000 12 / 4
1.0.999 12 / 4
1.0.998 12 / 4
1.0.997 12 / 4
1.0.996 12 / 4
1.0.995 12 / 4
1.0.994 12 / 4
1.0.993 12 / 4
1.0.992 12 / 4
1.0.991 12 / 4
1.0.990 12 / 4
1.0.989 12 / 4
1.0.988 12 / 4
1.0.987 12 / 4
1.0.986 12 / 4
1.0.985 12 / 4
1.0.984 12 / 4
1.0.983 12 / 4
1.0.982 12 / 4
1.0.981 12 / 4
1.0.980 12 / 4
1.0.979 12 / 4
1.0.978 12 / 4
1.0.977 12 / 4
1.0.976 12 / 4
1.0.975 12 / 4
1.0.974 12 / 4
1.0.973 12 / 4
1.0.972 12 / 4
1.0.971 12 / 4
1.0.970 12 / 4
1.0.969 12 / 4
1.0.968 12 / 4
1.0.967 12 / 4
1.0.966 12 / 4
1.0.965 12 / 4
1.0.964 12 / 4
1.0.963 12 / 4
1.0.962 12 / 4
1.0.961 12 / 4
1.0.960 12 / 4
1.0.959 12 / 4
1.0.958 12 / 4
1.0.957 12 / 4
1.0.956 12 / 4
1.0.955 12 / 4
1.0.954 12 / 4
1.0.953 12 / 4
1.0.952 12 / 4
1.0.951 12 / 4
1.0.950 12 / 4
1.0.949 12 / 4
1.0.948 12 / 4
1.0.947 12 / 4
1.0.946 12 / 4
1.0.945 12 / 4
1.0.944 12 / 4
1.0.943 12 / 4
1.0.942 12 / 4
1.0.941 12 / 4
1.0.940 12 / 4
1.0.939 12 / 4
1.0.938 12 / 4
1.0.937 12 / 4
1.0.936 12 / 4
1.0.935 12 / 4
1.0.934 12 / 4
1.0.933 12 / 4
1.0.932 12 / 4
1.0.931 12 / 4
1.0.930 12 / 4
1.0.929 12 / 4
1.0.928 12 / 4
1.0.927 12 / 4
1.0.926 12 / 4
1.0.925 12 / 4
1.0.924 12 / 4
1.0.923 12 / 4
1.0.922 12 / 4
1.0.921 12 / 4
1.0.920 12 / 4
1.0.919 12 / 4
1.0.918 12 / 4
1.0.917 12 / 4
1.0.916 12 / 4
1.0.915 12 / 4
1.0.914 12 / 4
1.0.913 12 / 4
1.0.912 12 / 4
1.0.911 12 / 4
1.0.910 12 / 4
1.0.909 12 / 4
Showing 100 of 395 Next page →

v1.0.1008

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1007

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1006

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1005

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1004

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1003

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1002

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1001

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1000

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.999

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.998

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.997

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.996

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.995

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.994

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.993

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.992

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.991

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.990

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.989

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.988

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.987

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.986

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.985

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.984

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.983

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.982

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.981

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.980

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.979

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.978

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.977

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.976

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.975

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.974

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.973

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.972

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.971

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.970

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.925

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.924

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.923

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.922

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.921

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.920

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.919

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.918

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.917

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.916

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.915

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.914

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.913

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.912

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.911

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.910

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.909

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.