← Home

@teambit/merge-lanes

51
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

teambit-ownershohamgiladdavidfirstranm8guysaaritaymendelerezbitjoshk2redigmayona007

Keywords

bitbit-aspectbit-core-aspectcomponentscollaborationweb

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@teambit/legacy.cli.prompts AI (dependencies): Same @teambit org scope; consistent with this package's established dependency pattern. ai
dependencies unvetted-dep:@teambit/harmony.modules.feature-toggle AI (dependencies): Same @teambit org scope; consistent with this package's established dependency pattern. ai
publish-pattern rapid-publish AI (publish-pattern): teambit uses automated CI/CD releasing many packages rapidly; consistent pattern across 2437+ versions. ai
dependencies unvetted-dep:@teambit/bit-error AI (dependencies): Same-org @teambit/* sibling package from the teambit/bit monorepo; stable pattern across versions. ai
dependencies unvetted-dep:@teambit/component-id AI (dependencies): Same-org @teambit/* sibling package from the teambit/bit monorepo; stable pattern across versions. ai
dependencies unvetted-dep:@teambit/legacy.scope AI (dependencies): Same-org @teambit/* sibling package from the teambit/bit monorepo; stable pattern across versions. ai
dependencies unvetted-dep:@teambit/legacy.consumer AI (dependencies): Same-org @teambit/* sibling package from the teambit/bit monorepo; stable pattern across versions. ai
dependencies unvetted-dep:@teambit/legacy.constants AI (dependencies): Same-org @teambit/* sibling package from the teambit/bit monorepo; stable pattern across versions. ai
dependencies unvetted-dep:@teambit/component.snap-distance AI (dependencies): Same-org @teambit/* sibling package from the teambit/bit monorepo; stable pattern across versions. ai
dependencies unvetted-dep:@teambit/harmony.modules.get-basic-log AI (dependencies): Same-org @teambit/* sibling package from the teambit/bit monorepo; stable pattern across versions. ai
dependencies unvetted-dep:@teambit/component.modules.merge-helper AI (dependencies): Same-org @teambit/* sibling package from the teambit/bit monorepo; stable pattern across versions. ai
dependencies unvetted-dep:@teambit/legacy.bit-map AI (dependencies): Same-org @teambit/* sibling package from the teambit/bit monorepo; stable pattern across versions. ai
dependencies unvetted-dep:@teambit/harmony AI (dependencies): Same-org @teambit/* sibling package from the teambit/bit monorepo; stable pattern across versions. ai
dependencies unvetted-dep:@teambit/lane-id AI (dependencies): Same-org @teambit/* sibling package from the teambit/bit monorepo; stable pattern across versions. ai
npm-metadata no-description AI (npm-metadata): Bit ecosystem packages routinely omit npm descriptions; not a malware indicator here. ai
phantom-deps phantom-dep:@teambit/component.snap-distance AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic unreliable for Bit's modular monorepo structure. ai
provenance no-provenance AI (provenance): Teambit publishes thousands of packages without Sigstore provenance; consistent across the ecosystem. ai

Versions (showing 51 of 56)

View all versions
Version Deps Published
1.0.1025 31 / 4
1.0.1014 31 / 4
1.0.1006 31 / 4
1.0.1000 31 / 4
1.0.999 31 / 4
1.0.998 31 / 4
1.0.997 31 / 4
1.0.996 31 / 4
1.0.995 31 / 4
1.0.994 31 / 4
1.0.993 31 / 4
1.0.988 31 / 4
1.0.987 31 / 4
1.0.986 31 / 4
1.0.985 31 / 4
1.0.984 31 / 4
1.0.983 31 / 4
1.0.982 31 / 4
1.0.981 31 / 4
1.0.980 31 / 4
1.0.979 31 / 4
1.0.978 31 / 4
1.0.976 31 / 4
1.0.975 31 / 4
1.0.974 31 / 4
1.0.973 31 / 4
1.0.972 31 / 4
1.0.971 31 / 4
1.0.970 31 / 4
1.0.968 31 / 4
1.0.966 31 / 4
1.0.965 31 / 4
1.0.964 31 / 4
1.0.963 31 / 4
1.0.962 31 / 4
1.0.960 31 / 4
1.0.958 31 / 4
1.0.957 31 / 4
1.0.956 31 / 4
1.0.955 31 / 4
1.0.954 31 / 4
1.0.953 31 / 4
1.0.951 31 / 4
1.0.950 31 / 4
1.0.949 31 / 4
1.0.947 31 / 4
1.0.946 31 / 4
1.0.945 31 / 4
1.0.944 31 / 4
1.0.941 31 / 4
1.0.940 31 / 4

v1.0.1025

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1014

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1006

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1000

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.999

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.998

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.997

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.996

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.995

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.994

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.993

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.988

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.987

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.986

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.985

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.