@teambit/panels
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): davidfirst is a long-standing trusted publisher (178 approved, 0 rejected) within the teambit ecosystem. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Auto-generated @teambit component packages routinely omit descriptions; stable pattern across 1500+ versions. | ai | |
| provenance | no-provenance | AI (provenance): teambit publishes hundreds of packages without provenance; consistent across the ecosystem. | ai |
Versions (showing 51 of 473)
| Version | Deps | Published |
|---|---|---|
| 0.0.1358 | 4 / 4 | |
| 0.0.1357 | 4 / 4 | |
| 0.0.1356 | 4 / 4 | |
| 0.0.1355 | 4 / 4 | |
| 0.0.1354 | 4 / 4 | |
| 0.0.1353 | 4 / 4 | |
| 0.0.1352 | 4 / 4 | |
| 0.0.1351 | 4 / 4 | |
| 0.0.1350 | 4 / 4 | |
| 0.0.1349 | 4 / 4 | |
| 0.0.1348 | 4 / 4 | |
| 0.0.1347 | 4 / 4 | |
| 0.0.1346 | 4 / 4 | |
| 0.0.1345 | 4 / 4 | |
| 0.0.1344 | 4 / 4 | |
| 0.0.1343 | 4 / 4 | |
| 0.0.1342 | 4 / 4 | |
| 0.0.1341 | 4 / 4 | |
| 0.0.1340 | 4 / 4 | |
| 0.0.1339 | 4 / 4 | |
| 0.0.1338 | 4 / 4 | |
| 0.0.1337 | 4 / 4 | |
| 0.0.1336 | 4 / 4 | |
| 0.0.1335 | 4 / 4 | |
| 0.0.1334 | 4 / 4 | |
| 0.0.1333 | 4 / 4 | |
| 0.0.1332 | 4 / 4 | |
| 0.0.1331 | 4 / 4 | |
| 0.0.1330 | 4 / 4 | |
| 0.0.1329 | 4 / 4 | |
| 0.0.1328 | 4 / 4 | |
| 0.0.1327 | 4 / 4 | |
| 0.0.1326 | 4 / 4 | |
| 0.0.1325 | 4 / 4 | |
| 0.0.1324 | 4 / 4 | |
| 0.0.1323 | 4 / 4 | |
| 0.0.1322 | 4 / 4 | |
| 0.0.1321 | 4 / 4 | |
| 0.0.1320 | 4 / 4 | |
| 0.0.1319 | 4 / 4 | |
| 0.0.1318 | 4 / 4 | |
| 0.0.1317 | 4 / 4 | |
| 0.0.1316 | 4 / 4 | |
| 0.0.1315 | 4 / 4 | |
| 0.0.1314 | 4 / 4 | |
| 0.0.1313 | 4 / 4 | |
| 0.0.1312 | 4 / 4 | |
| 0.0.1311 | 4 / 4 | |
| 0.0.1310 | 4 / 4 | |
| 0.0.1309 | 4 / 4 | |
| 0.0.1308 | 4 / 4 |
v0.0.1358
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1357
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1356
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1355
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1354
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1353
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1352
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1351
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1350
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1349
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1348
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.