@teambit/merging
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@teambit/legacy.logger | AI (dependencies): Same-org internal monorepo dependency, no malicious behavior. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): All new deps are first-party @teambit/* packages from internal refactor, not third-party additions. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Monorepo maintainer list churn; publisher is known teambit maintainer with long track record. | ai | |
| dependencies | unvetted-dep:@teambit/component.sources | AI (dependencies): First-party teambit monorepo package, not third-party. | ai | |
| dependencies | unvetted-dep:@teambit/toolbox.crypto.sha1 | AI (dependencies): First-party teambit monorepo package, same publisher track record. | ai | |
| dependencies | unvetted-dep:@teambit/git.modules.git-executable | AI (dependencies): First-party teambit monorepo package, same publisher track record. | ai | |
| dependencies | unvetted-dep:@teambit/legacy.utils | AI (dependencies): First-party teambit monorepo package, same publisher track record. | ai | |
| dependencies | unvetted-dep:@teambit/legacy.cli.prompts | AI (dependencies): First-party teambit monorepo package, same publisher track record. | ai | |
| dependencies | unvetted-dep:@teambit/toolbox.string.eol | AI (dependencies): First-party teambit monorepo package, same publisher track record. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): teambit publishes many packages simultaneously via automated CI; rapid publish is a stable pattern for this org. | ai | |
| dependencies | unvetted-dep:@teambit/legacy.extension-data | AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. | ai | |
| dependencies | unvetted-dep:@teambit/legacy.consumer-component | AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. | ai | |
| dependencies | unvetted-dep:@teambit/component.modules.merge-helper | AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. | ai | |
| dependencies | unvetted-dep:@teambit/pkg.modules.component-package-name | AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. | ai | |
| dependencies | unvetted-dep:@teambit/component.snap-distance | AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. | ai | |
| dependencies | unvetted-dep:@teambit/harmony | AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. | ai | |
| dependencies | unvetted-dep:@teambit/lane-id | AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. | ai | |
| dependencies | unvetted-dep:@teambit/bit-error | AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. | ai | |
| dependencies | unvetted-dep:@teambit/component-id | AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. | ai | |
| dependencies | unvetted-dep:@teambit/legacy.scope | AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. | ai | |
| dependencies | unvetted-dep:@teambit/legacy.consumer | AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. | ai | |
| dependencies | unvetted-dep:@teambit/legacy.constants | AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. | ai | |
| dependencies | unvetted-dep:@teambit/toolbox.path.path | AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. | ai | |
| dependencies | unvetted-dep:@teambit/legacy.component-list | AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Teambit monorepo packages consistently omit descriptions; not a malware signal here. | ai | |
| phantom-deps | phantom-dep:@teambit/legacy.consumer-component | AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic unreliable for monorepo indirect usage. | ai | |
| phantom-deps | phantom-dep:@teambit/legacy.extension-data | AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic unreliable for monorepo indirect usage. | ai | |
| provenance | no-provenance | AI (provenance): Teambit does not publish with Sigstore provenance; stable pattern across their packages. | ai |
Versions (showing 100 of 159)
| Version | Deps | Published |
|---|---|---|
| 1.0.1068 | 34 / 3 | |
| 1.0.1067 | 34 / 3 | |
| 1.0.1029 | 34 / 3 | |
| 1.0.1024 | 34 / 3 | |
| 1.0.1009 | 34 / 3 | |
| 1.0.984 | 34 / 3 | |
| 1.0.983 | 34 / 3 | |
| 1.0.982 | 34 / 3 | |
| 1.0.981 | 34 / 3 | |
| 1.0.980 | 34 / 3 | |
| 1.0.979 | 34 / 3 | |
| 1.0.978 | 34 / 3 | |
| 1.0.974 | 34 / 3 | |
| 1.0.973 | 34 / 3 | |
| 1.0.972 | 34 / 3 | |
| 1.0.970 | 34 / 3 | |
| 1.0.969 | 34 / 3 | |
| 1.0.968 | 34 / 3 | |
| 1.0.967 | 34 / 3 | |
| 1.0.966 | 34 / 3 | |
| 1.0.965 | 34 / 3 | |
| 1.0.963 | 34 / 3 | |
| 1.0.961 | 34 / 3 | |
| 1.0.960 | 34 / 3 | |
| 1.0.959 | 34 / 3 | |
| 1.0.957 | 34 / 3 | |
| 1.0.955 | 34 / 3 | |
| 1.0.954 | 34 / 3 | |
| 1.0.953 | 34 / 3 | |
| 1.0.950 | 34 / 3 | |
| 1.0.949 | 34 / 3 | |
| 1.0.948 | 34 / 3 | |
| 1.0.946 | 34 / 3 | |
| 1.0.945 | 34 / 3 | |
| 1.0.943 | 34 / 3 | |
| 1.0.942 | 34 / 3 | |
| 1.0.940 | 34 / 3 | |
| 1.0.939 | 34 / 3 | |
| 1.0.938 | 34 / 3 | |
| 1.0.937 | 34 / 3 | |
| 1.0.936 | 34 / 3 | |
| 1.0.934 | 34 / 3 | |
| 1.0.933 | 34 / 3 | |
| 1.0.932 | 34 / 3 | |
| 1.0.931 | 34 / 3 | |
| 1.0.930 | 34 / 3 | |
| 1.0.929 | 34 / 3 | |
| 1.0.928 | 34 / 3 | |
| 1.0.926 | 34 / 3 | |
| 1.0.836 | 34 / 3 | |
| 1.0.697 | 34 / 3 | |
| 1.0.635 | 40 / 3 | |
| 1.0.486 | 31 / 3 | |
| 1.0.474 | 31 / 3 | |
| 1.0.468 | 31 / 3 | |
| 1.0.440 | 31 / 3 | |
| 1.0.434 | 31 / 3 | |
| 1.0.425 | 31 / 3 | |
| 1.0.421 | 31 / 3 | |
| 1.0.419 | 31 / 3 | |
| 1.0.414 | 31 / 3 | |
| 1.0.412 | 31 / 3 | |
| 1.0.408 | 31 / 4 | |
| 1.0.401 | 31 / 4 | |
| 1.0.395 | 31 / 4 | |
| 1.0.391 | 31 / 4 | |
| 1.0.385 | 31 / 4 | |
| 1.0.381 | 31 / 4 | |
| 1.0.380 | 31 / 4 | |
| 1.0.378 | 31 / 4 | |
| 1.0.375 | 31 / 4 | |
| 1.0.363 | 31 / 4 | |
| 1.0.360 | 31 / 4 | |
| 1.0.358 | 31 / 4 | |
| 1.0.357 | 31 / 4 | |
| 1.0.354 | 31 / 4 | |
| 1.0.352 | 31 / 4 | |
| 1.0.348 | 31 / 4 | |
| 1.0.346 | 31 / 4 | |
| 1.0.344 | 31 / 4 | |
| 1.0.340 | 31 / 4 | |
| 1.0.339 | 31 / 4 | |
| 1.0.334 | 31 / 4 | |
| 1.0.332 | 29 / 4 | |
| 1.0.331 | 29 / 4 | |
| 1.0.330 | 22 / 4 | |
| 1.0.329 | 22 / 4 | |
| 1.0.328 | 22 / 4 | |
| 1.0.327 | 22 / 4 | |
| 1.0.326 | 22 / 4 | |
| 1.0.325 | 22 / 4 | |
| 1.0.324 | 22 / 4 | |
| 1.0.323 | 22 / 4 | |
| 1.0.322 | 22 / 4 | |
| 1.0.321 | 22 / 4 | |
| 1.0.320 | 22 / 4 | |
| 1.0.319 | 22 / 4 | |
| 1.0.318 | 22 / 4 | |
| 1.0.317 | 21 / 4 | |
| 1.0.316 | 21 / 4 |
v1.0.1068
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1067
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.836
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (teambit-owner) than the most recent previously approved version (davidfirst) on 2025-12-03, but teambit-owner is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.0.697
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (teambit-owner) than the most recent previously approved version (davidfirst) on 2025-08-12, but teambit-owner is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.0.635
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (teambit-owner) than the most recent previously approved version (davidfirst) on 2025-06-20, but teambit-owner is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.0.486
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.474
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.468
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.440
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.434
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.425
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.421
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.419
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.414
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.412
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.408
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.401
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.395
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.391
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.385
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.381
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.380
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.378
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.375
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.363
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.360
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.358
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.357
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.354
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.352
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.348
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.346
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.344
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.340
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.339
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.334
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.332
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.331
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.330
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.329
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.328
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.327
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.326
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.325
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.324
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.323
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.322
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.321
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.320
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.319
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.318
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.317
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.316
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.