← Home

@teambit/merging

100
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

teambit-ownershohamgiladdavidfirstranm8guysaaritaymendelerezbitjoshk2redigmayona007

Keywords

bitbit-aspectbit-core-aspectcomponentscollaborationweb

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@teambit/legacy.logger AI (dependencies): Same-org internal monorepo dependency, no malicious behavior. ai
publish-pattern new-deps-added AI (publish-pattern): All new deps are first-party @teambit/* packages from internal refactor, not third-party additions. ai
maintainer-change maintainer-removed AI (maintainer-change): Monorepo maintainer list churn; publisher is known teambit maintainer with long track record. ai
dependencies unvetted-dep:@teambit/component.sources AI (dependencies): First-party teambit monorepo package, not third-party. ai
dependencies unvetted-dep:@teambit/toolbox.crypto.sha1 AI (dependencies): First-party teambit monorepo package, same publisher track record. ai
dependencies unvetted-dep:@teambit/git.modules.git-executable AI (dependencies): First-party teambit monorepo package, same publisher track record. ai
dependencies unvetted-dep:@teambit/legacy.utils AI (dependencies): First-party teambit monorepo package, same publisher track record. ai
dependencies unvetted-dep:@teambit/legacy.cli.prompts AI (dependencies): First-party teambit monorepo package, same publisher track record. ai
dependencies unvetted-dep:@teambit/toolbox.string.eol AI (dependencies): First-party teambit monorepo package, same publisher track record. ai
publish-pattern rapid-publish AI (publish-pattern): teambit publishes many packages simultaneously via automated CI; rapid publish is a stable pattern for this org. ai
dependencies unvetted-dep:@teambit/legacy.extension-data AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/legacy.consumer-component AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/component.modules.merge-helper AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/pkg.modules.component-package-name AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/component.snap-distance AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/harmony AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/lane-id AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/bit-error AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/component-id AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/legacy.scope AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/legacy.consumer AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/legacy.constants AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/toolbox.path.path AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/legacy.component-list AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. ai
npm-metadata no-description AI (npm-metadata): Teambit monorepo packages consistently omit descriptions; not a malware signal here. ai
phantom-deps phantom-dep:@teambit/legacy.consumer-component AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic unreliable for monorepo indirect usage. ai
phantom-deps phantom-dep:@teambit/legacy.extension-data AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic unreliable for monorepo indirect usage. ai
provenance no-provenance AI (provenance): Teambit does not publish with Sigstore provenance; stable pattern across their packages. ai

Versions (showing 100 of 159)

Version Deps Published
1.0.1068 34 / 3
1.0.1067 34 / 3
1.0.1029 34 / 3
1.0.1024 34 / 3
1.0.1009 34 / 3
1.0.984 34 / 3
1.0.983 34 / 3
1.0.982 34 / 3
1.0.981 34 / 3
1.0.980 34 / 3
1.0.979 34 / 3
1.0.978 34 / 3
1.0.974 34 / 3
1.0.973 34 / 3
1.0.972 34 / 3
1.0.970 34 / 3
1.0.969 34 / 3
1.0.968 34 / 3
1.0.967 34 / 3
1.0.966 34 / 3
1.0.965 34 / 3
1.0.963 34 / 3
1.0.961 34 / 3
1.0.960 34 / 3
1.0.959 34 / 3
1.0.957 34 / 3
1.0.955 34 / 3
1.0.954 34 / 3
1.0.953 34 / 3
1.0.950 34 / 3
1.0.949 34 / 3
1.0.948 34 / 3
1.0.946 34 / 3
1.0.945 34 / 3
1.0.943 34 / 3
1.0.942 34 / 3
1.0.940 34 / 3
1.0.939 34 / 3
1.0.938 34 / 3
1.0.937 34 / 3
1.0.936 34 / 3
1.0.934 34 / 3
1.0.933 34 / 3
1.0.932 34 / 3
1.0.931 34 / 3
1.0.930 34 / 3
1.0.929 34 / 3
1.0.928 34 / 3
1.0.926 34 / 3
1.0.836 34 / 3
1.0.697 34 / 3
1.0.635 40 / 3
1.0.486 31 / 3
1.0.474 31 / 3
1.0.468 31 / 3
1.0.440 31 / 3
1.0.434 31 / 3
1.0.425 31 / 3
1.0.421 31 / 3
1.0.419 31 / 3
1.0.414 31 / 3
1.0.412 31 / 3
1.0.408 31 / 4
1.0.401 31 / 4
1.0.395 31 / 4
1.0.391 31 / 4
1.0.385 31 / 4
1.0.381 31 / 4
1.0.380 31 / 4
1.0.378 31 / 4
1.0.375 31 / 4
1.0.363 31 / 4
1.0.360 31 / 4
1.0.358 31 / 4
1.0.357 31 / 4
1.0.354 31 / 4
1.0.352 31 / 4
1.0.348 31 / 4
1.0.346 31 / 4
1.0.344 31 / 4
1.0.340 31 / 4
1.0.339 31 / 4
1.0.334 31 / 4
1.0.332 29 / 4
1.0.331 29 / 4
1.0.330 22 / 4
1.0.329 22 / 4
1.0.328 22 / 4
1.0.327 22 / 4
1.0.326 22 / 4
1.0.325 22 / 4
1.0.324 22 / 4
1.0.323 22 / 4
1.0.322 22 / 4
1.0.321 22 / 4
1.0.320 22 / 4
1.0.319 22 / 4
1.0.318 22 / 4
1.0.317 21 / 4
1.0.316 21 / 4
Showing 100 of 159 Next page →

v1.0.1068

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1067

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.836

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: davidfirst → teambit-owner (on 2025-12-03, known maintainer) provenance

This version was published by a different npm account (teambit-owner) than the most recent previously approved version (davidfirst) on 2025-12-03, but teambit-owner is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.697

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: davidfirst → teambit-owner (on 2025-08-12, known maintainer) provenance

This version was published by a different npm account (teambit-owner) than the most recent previously approved version (davidfirst) on 2025-08-12, but teambit-owner is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.635

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: davidfirst → teambit-owner (on 2025-06-20, known maintainer) provenance

This version was published by a different npm account (teambit-owner) than the most recent previously approved version (davidfirst) on 2025-06-20, but teambit-owner is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.486

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.474

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.468

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.440

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.434

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.425

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.421

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.419

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.414

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.412

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.408

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.401

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.395

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.391

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.385

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.381

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.380

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.378

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.375

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.363

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.360

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.358

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.357

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.354

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.352

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.348

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.346

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.344

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.340

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.339

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.334

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.332

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.331

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.330

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.329

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.328

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.327

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.326

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.325

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.324

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.323

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.322

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.321

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.320

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.319

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.318

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.317

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.316

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.