← Home

@teambit/mover

51
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

teambit-ownershohamgiladdavidfirstranm8guysaaritaymendelerezbitjoshk2redigmayona007

Keywords

bitbit-aspectbit-core-aspectcomponentscollaborationweb

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern rapid-publish AI (publish-pattern): teambit uses automated CI/CD releasing many packages rapidly; stable pattern across thousands of approved versions. ai
dependencies unvetted-dep:@teambit/harmony AI (dependencies): Sibling @teambit/* package from the same monorepo; unvetted status is a registry coverage gap, not a risk. ai
dependencies unvetted-dep:@teambit/bit-error AI (dependencies): Sibling @teambit/* package from the same monorepo; unvetted status is a registry coverage gap, not a risk. ai
dependencies unvetted-dep:@teambit/workspace AI (dependencies): Sibling @teambit/* package from the same monorepo; unvetted status is a registry coverage gap, not a risk. ai
dependencies unvetted-dep:@teambit/legacy.utils AI (dependencies): Sibling @teambit/* package from the same monorepo; unvetted status is a registry coverage gap, not a risk. ai
dependencies unvetted-dep:@teambit/legacy.bit-map AI (dependencies): Sibling @teambit/* package from the same monorepo; unvetted status is a registry coverage gap, not a risk. ai
dependencies unvetted-dep:@teambit/cli AI (dependencies): Sibling @teambit/* package from the same monorepo; unvetted status is a registry coverage gap, not a risk. ai
dependencies unvetted-dep:@teambit/legacy.consumer-component AI (dependencies): Sibling @teambit/* package from the same monorepo; unvetted status is a registry coverage gap, not a risk. ai
dependencies unvetted-dep:@teambit/workspace.modules.node-modules-linker AI (dependencies): Sibling @teambit/* package from the same monorepo; unvetted status is a registry coverage gap, not a risk. ai
npm-metadata no-description AI (npm-metadata): Monorepo component package; missing description is a cosmetic issue, not a malware signal. ai
provenance no-provenance AI (provenance): Established teambit/bit monorepo predates widespread provenance adoption; absence is expected. ai
dependencies unvetted-dep:@teambit/component.sources AI (dependencies): Sibling @teambit/* package from the same monorepo; unvetted status is a registry coverage gap, not a risk. ai

Versions (showing 51 of 312)

View all versions
Version Deps Published
1.0.1060 12 / 4
1.0.1038 12 / 4
1.0.1033 12 / 4
1.0.1032 12 / 4
1.0.1031 12 / 4
1.0.1030 12 / 4
1.0.1029 12 / 4
1.0.1026 12 / 4
1.0.1025 12 / 4
1.0.1024 12 / 4
1.0.1023 12 / 4
1.0.1022 12 / 4
1.0.1021 12 / 4
1.0.1020 12 / 4
1.0.1019 12 / 4
1.0.1018 12 / 4
1.0.1017 12 / 4
1.0.1016 12 / 4
1.0.1015 12 / 4
1.0.1014 12 / 4
1.0.1013 12 / 4
1.0.1012 12 / 4
1.0.1011 12 / 4
1.0.1010 12 / 4
1.0.1009 12 / 4
1.0.1008 12 / 4
1.0.1007 12 / 4
1.0.1006 12 / 4
1.0.1005 12 / 4
1.0.1004 12 / 4
1.0.1003 12 / 4
1.0.1002 12 / 4
1.0.1001 12 / 4
1.0.1000 12 / 4
1.0.999 12 / 4
1.0.998 12 / 4
1.0.997 12 / 4
1.0.996 12 / 4
1.0.995 12 / 4
1.0.994 12 / 4
1.0.993 12 / 4
1.0.992 12 / 4
1.0.991 12 / 4
1.0.990 12 / 4
1.0.989 12 / 4
1.0.987 12 / 4
1.0.986 12 / 4
1.0.985 12 / 4
1.0.984 12 / 4
1.0.983 12 / 4
1.0.981 12 / 4

v1.0.1060

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.