← Home

@teambit/merging

45
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

teambit-ownershohamgiladdavidfirstranm8guysaaritaymendelerezbitjoshk2redigmayona007

Keywords

bitbit-aspectbit-core-aspectcomponentscollaborationweb

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern rapid-publish AI (publish-pattern): teambit publishes many packages simultaneously via automated CI; rapid publish is a stable pattern for this org. ai
dependencies unvetted-dep:@teambit/legacy.consumer AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/component.snap-distance AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/legacy.consumer-component AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/component.modules.merge-helper AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/pkg.modules.component-package-name AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/harmony AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/lane-id AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/bit-error AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/component-id AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/legacy.scope AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/legacy.constants AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/toolbox.path.path AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/legacy.component-list AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/legacy.extension-data AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. ai
phantom-deps phantom-dep:@teambit/legacy.extension-data AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic unreliable for monorepo indirect usage. ai
phantom-deps phantom-dep:@teambit/legacy.consumer-component AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic unreliable for monorepo indirect usage. ai
provenance no-provenance AI (provenance): Teambit does not publish with Sigstore provenance; stable pattern across their packages. ai
npm-metadata no-description AI (npm-metadata): Teambit monorepo packages consistently omit descriptions; not a malware signal here. ai

Versions (showing 45 of 45)

Version Deps Published
1.0.1009 34 / 3
1.0.984 34 / 3
1.0.983 34 / 3
1.0.982 34 / 3
1.0.981 34 / 3
1.0.980 34 / 3
1.0.979 34 / 3
1.0.978 34 / 3
1.0.974 34 / 3
1.0.973 34 / 3
1.0.972 34 / 3
1.0.970 34 / 3
1.0.969 34 / 3
1.0.968 34 / 3
1.0.967 34 / 3
1.0.966 34 / 3
1.0.965 34 / 3
1.0.963 34 / 3
1.0.961 34 / 3
1.0.960 34 / 3
1.0.959 34 / 3
1.0.957 34 / 3
1.0.955 34 / 3
1.0.954 34 / 3
1.0.953 34 / 3
1.0.950 34 / 3
1.0.949 34 / 3
1.0.948 34 / 3
1.0.946 34 / 3
1.0.945 34 / 3
1.0.943 34 / 3
1.0.942 34 / 3
1.0.940 34 / 3
1.0.939 34 / 3
1.0.938 34 / 3
1.0.937 34 / 3
1.0.936 34 / 3
1.0.934 34 / 3
1.0.933 34 / 3
1.0.932 34 / 3
1.0.931 34 / 3
1.0.930 34 / 3
1.0.929 34 / 3
1.0.928 34 / 3
1.0.926 34 / 3

v1.0.1009

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.984

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.983

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.982

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.981

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.980

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.979

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.978

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.974

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.973

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.972

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.