← Home

@teambit/merging

59
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

teambit-ownershohamgiladdavidfirstranm8guysaaritaymendelerezbitjoshk2redigmayona007

Keywords

bitbit-aspectbit-core-aspectcomponentscollaborationweb

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@teambit/legacy.logger AI (dependencies): Same-org internal monorepo dependency, no malicious behavior. ai
publish-pattern new-deps-added AI (publish-pattern): All new deps are first-party @teambit/* packages from internal refactor, not third-party additions. ai
maintainer-change maintainer-removed AI (maintainer-change): Monorepo maintainer list churn; publisher is known teambit maintainer with long track record. ai
dependencies unvetted-dep:@teambit/component.sources AI (dependencies): First-party teambit monorepo package, not third-party. ai
dependencies unvetted-dep:@teambit/toolbox.crypto.sha1 AI (dependencies): First-party teambit monorepo package, same publisher track record. ai
dependencies unvetted-dep:@teambit/git.modules.git-executable AI (dependencies): First-party teambit monorepo package, same publisher track record. ai
dependencies unvetted-dep:@teambit/legacy.utils AI (dependencies): First-party teambit monorepo package, same publisher track record. ai
dependencies unvetted-dep:@teambit/legacy.cli.prompts AI (dependencies): First-party teambit monorepo package, same publisher track record. ai
dependencies unvetted-dep:@teambit/toolbox.string.eol AI (dependencies): First-party teambit monorepo package, same publisher track record. ai
publish-pattern rapid-publish AI (publish-pattern): teambit publishes many packages simultaneously via automated CI; rapid publish is a stable pattern for this org. ai
dependencies unvetted-dep:@teambit/legacy.extension-data AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/legacy.consumer-component AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/component.modules.merge-helper AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/pkg.modules.component-package-name AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/component.snap-distance AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/harmony AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/lane-id AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/bit-error AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/component-id AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/legacy.scope AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/legacy.consumer AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/legacy.constants AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/toolbox.path.path AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@teambit/legacy.component-list AI (dependencies): Internal @teambit ecosystem dep; stable pattern across all versions of this package. ai
npm-metadata no-description AI (npm-metadata): Teambit monorepo packages consistently omit descriptions; not a malware signal here. ai
phantom-deps phantom-dep:@teambit/legacy.consumer-component AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic unreliable for monorepo indirect usage. ai
phantom-deps phantom-dep:@teambit/legacy.extension-data AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic unreliable for monorepo indirect usage. ai
provenance no-provenance AI (provenance): Teambit does not publish with Sigstore provenance; stable pattern across their packages. ai

Versions (showing 59 of 159)

Version Deps Published
1.0.315 21 / 4
1.0.314 21 / 4
1.0.313 21 / 4
1.0.312 21 / 4
1.0.311 21 / 4
1.0.310 21 / 4
1.0.309 21 / 4
1.0.308 21 / 4
1.0.307 21 / 4
1.0.306 21 / 4
1.0.305 21 / 4
1.0.304 21 / 4
1.0.303 21 / 4
1.0.302 21 / 4
1.0.301 21 / 4
1.0.300 21 / 4
1.0.299 21 / 4
1.0.298 21 / 4
1.0.297 21 / 4
1.0.296 21 / 4
1.0.295 21 / 4
1.0.294 21 / 4
1.0.293 21 / 4
1.0.292 21 / 4
1.0.291 21 / 4
1.0.290 21 / 4
1.0.289 21 / 4
1.0.288 21 / 4
1.0.287 21 / 4
1.0.286 21 / 4
1.0.285 21 / 4
1.0.284 21 / 4
1.0.283 21 / 4
1.0.282 21 / 4
1.0.281 21 / 4
1.0.280 21 / 4
1.0.279 21 / 4
1.0.278 21 / 4
1.0.277 21 / 4
1.0.276 21 / 4
1.0.275 21 / 4
1.0.274 21 / 4
1.0.273 21 / 4
1.0.272 21 / 4
1.0.271 21 / 4
1.0.270 21 / 4
1.0.269 21 / 4
1.0.268 21 / 4
1.0.267 21 / 4
1.0.266 21 / 4
1.0.265 21 / 4
1.0.264 21 / 4
1.0.263 21 / 4
1.0.262 21 / 4
1.0.261 21 / 4
1.0.260 21 / 4
1.0.259 21 / 4
1.0.258 21 / 4
1.0.257 21 / 4

v1.0.315

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.314

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.313

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.312

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.311

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.310

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.309

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.308

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.307

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.306

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.305

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.304

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.303

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.302

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.301

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.300

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.299

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.298

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.297

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.296

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.295

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.294

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.293

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.292

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.291

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.290

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.289

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.288

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.287

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.286

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.285

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.284

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.283

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.282

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.281

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.280

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.279

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.278

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.277

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.276

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.275

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.274

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.273

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.272

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.271

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.270

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.269

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.268

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.267

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.266

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.265

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.264

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.263

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.262

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.261

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.260

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: shohamgilad → davidfirst (on 2024-05-02, known maintainer) provenance

This version was published by a different npm account (davidfirst) than the most recent previously approved version (shohamgilad) on 2024-05-02, but davidfirst is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.259

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: shohamgilad → davidfirst (on 2024-05-01, known maintainer) provenance

This version was published by a different npm account (davidfirst) than the most recent previously approved version (shohamgilad) on 2024-05-01, but davidfirst is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.258

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.257

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.