@teambit/new-component-helper
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | rapid-publish | AI (publish-pattern): teambit publishes hundreds of coordinated packages in rapid succession as part of automated monorepo releases; stable pattern. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Scoped @teambit package; missing description is stable pattern for internal components. | ai | |
| provenance | no-provenance | AI (provenance): Established publisher; provenance absence is not a blocker for this package's context. | ai | |
| dependencies | unvetted-dep:@teambit/tracker | AI (dependencies): Sibling @teambit monorepo package; unvetted status is a registry gap, not a security concern. | ai | |
| dependencies | unvetted-dep:@teambit/bit-error | AI (dependencies): Sibling @teambit monorepo package; unvetted status is a registry gap, not a security concern. | ai | |
| dependencies | unvetted-dep:@teambit/component | AI (dependencies): Sibling @teambit monorepo package; unvetted status is a registry gap, not a security concern. | ai | |
| dependencies | unvetted-dep:@teambit/workspace | AI (dependencies): Sibling @teambit monorepo package; unvetted status is a registry gap, not a security concern. | ai | |
| dependencies | unvetted-dep:@teambit/component-id | AI (dependencies): Sibling @teambit monorepo package; unvetted status is a registry gap, not a security concern. | ai | |
| dependencies | unvetted-dep:@teambit/cli | AI (dependencies): Sibling @teambit monorepo package; unvetted status is a registry gap, not a security concern. | ai | |
| dependencies | unvetted-dep:@teambit/component-writer | AI (dependencies): Sibling @teambit monorepo package; unvetted status is a registry gap, not a security concern. | ai | |
| dependencies | unvetted-dep:@teambit/legacy.constants | AI (dependencies): Sibling @teambit monorepo package; unvetted status is a registry gap, not a security concern. | ai | |
| dependencies | unvetted-dep:@teambit/component.sources | AI (dependencies): Sibling @teambit monorepo package; unvetted status is a registry gap, not a security concern. | ai | |
| dependencies | unvetted-dep:@teambit/toolbox.path.path | AI (dependencies): Sibling @teambit monorepo package; unvetted status is a registry gap, not a security concern. | ai | |
| dependencies | unvetted-dep:@teambit/toolbox.fs.is-dir-empty | AI (dependencies): Sibling @teambit monorepo package; unvetted status is a registry gap, not a security concern. | ai | |
| dependencies | unvetted-dep:@teambit/legacy-bit-id | AI (dependencies): Sibling @teambit monorepo package; unvetted status is a registry gap, not a security concern. | ai | |
| dependencies | unvetted-dep:@teambit/envs | AI (dependencies): Sibling @teambit monorepo package; unvetted status is a registry gap, not a security concern. | ai | |
| dependencies | unvetted-dep:@teambit/harmony | AI (dependencies): Sibling @teambit monorepo package; unvetted status is a registry gap, not a security concern. | ai |
Versions (showing 100 of 262)
| Version | Deps | Published |
|---|---|---|
| 1.0.881 | 16 / 3 | |
| 1.0.880 | 16 / 3 | |
| 1.0.879 | 16 / 3 | |
| 1.0.878 | 16 / 3 | |
| 1.0.877 | 16 / 3 | |
| 1.0.876 | 16 / 3 | |
| 1.0.875 | 16 / 3 | |
| 1.0.874 | 16 / 3 | |
| 1.0.873 | 16 / 3 | |
| 1.0.872 | 16 / 3 | |
| 1.0.871 | 16 / 3 | |
| 1.0.870 | 16 / 3 | |
| 1.0.869 | 16 / 3 | |
| 1.0.868 | 16 / 3 | |
| 1.0.867 | 16 / 3 | |
| 1.0.866 | 16 / 3 | |
| 1.0.865 | 16 / 3 | |
| 1.0.864 | 16 / 3 | |
| 1.0.863 | 16 / 3 | |
| 1.0.862 | 16 / 3 | |
| 1.0.861 | 16 / 3 | |
| 1.0.860 | 16 / 3 | |
| 1.0.859 | 16 / 3 | |
| 1.0.858 | 16 / 3 | |
| 1.0.857 | 16 / 3 | |
| 1.0.856 | 16 / 3 | |
| 1.0.855 | 16 / 3 | |
| 1.0.854 | 16 / 3 | |
| 1.0.853 | 16 / 3 | |
| 1.0.852 | 16 / 3 | |
| 1.0.851 | 16 / 3 | |
| 1.0.850 | 16 / 3 | |
| 1.0.849 | 16 / 3 | |
| 1.0.848 | 16 / 3 | |
| 1.0.847 | 16 / 3 | |
| 1.0.846 | 16 / 3 | |
| 1.0.845 | 16 / 3 | |
| 1.0.844 | 16 / 3 | |
| 1.0.843 | 16 / 3 | |
| 1.0.842 | 16 / 3 | |
| 1.0.841 | 16 / 3 | |
| 1.0.840 | 16 / 3 | |
| 1.0.839 | 16 / 3 | |
| 1.0.838 | 16 / 3 | |
| 1.0.837 | 16 / 3 | |
| 1.0.836 | 16 / 3 | |
| 1.0.835 | 16 / 3 | |
| 1.0.834 | 16 / 3 | |
| 1.0.833 | 16 / 3 | |
| 1.0.832 | 16 / 3 | |
| 1.0.831 | 16 / 3 | |
| 1.0.830 | 16 / 3 | |
| 1.0.829 | 16 / 3 | |
| 1.0.828 | 16 / 3 | |
| 1.0.827 | 16 / 3 | |
| 1.0.826 | 16 / 3 | |
| 1.0.825 | 16 / 3 | |
| 1.0.824 | 16 / 3 | |
| 1.0.823 | 16 / 3 | |
| 1.0.822 | 16 / 3 | |
| 1.0.821 | 16 / 3 | |
| 1.0.820 | 16 / 3 | |
| 1.0.819 | 16 / 3 | |
| 1.0.818 | 16 / 3 | |
| 1.0.817 | 16 / 3 | |
| 1.0.816 | 16 / 3 | |
| 1.0.815 | 16 / 3 | |
| 1.0.814 | 16 / 3 | |
| 1.0.813 | 16 / 3 | |
| 1.0.812 | 16 / 3 | |
| 1.0.811 | 16 / 3 | |
| 1.0.810 | 16 / 3 | |
| 1.0.809 | 16 / 3 | |
| 1.0.808 | 16 / 3 | |
| 1.0.807 | 16 / 3 | |
| 1.0.806 | 16 / 3 | |
| 1.0.805 | 16 / 3 | |
| 1.0.804 | 16 / 3 | |
| 1.0.803 | 16 / 3 | |
| 1.0.802 | 16 / 3 | |
| 1.0.801 | 16 / 3 | |
| 1.0.800 | 16 / 3 | |
| 1.0.799 | 16 / 3 | |
| 1.0.798 | 16 / 3 | |
| 1.0.797 | 16 / 3 | |
| 1.0.612 | 17 / 3 | |
| 1.0.611 | 17 / 3 | |
| 1.0.610 | 17 / 3 | |
| 1.0.330 | 13 / 4 | |
| 1.0.329 | 13 / 4 | |
| 1.0.328 | 13 / 4 | |
| 1.0.327 | 13 / 4 | |
| 1.0.326 | 13 / 4 | |
| 1.0.325 | 13 / 4 | |
| 1.0.324 | 13 / 4 | |
| 1.0.323 | 13 / 4 | |
| 1.0.322 | 13 / 4 | |
| 1.0.321 | 13 / 4 | |
| 1.0.320 | 13 / 4 | |
| 1.0.319 | 13 / 4 |
v1.0.330
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.329
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.328
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.327
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.326
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.325
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.324
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.323
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.322
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.321
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.320
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.319
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.