← Home

@teambit/pnpm

51
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

teambit-ownershohamgiladdavidfirstranm8guysaaritaymendelerezbitjoshk2redigmayona007

Keywords

bitbit-aspectbit-core-aspectcomponentscollaborationweb

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern new-deps-added AI (publish-pattern): First-party @teambit replacement dep, part of normal monorepo refactor. ai
publish-pattern rapid-publish AI (publish-pattern): Teambit uses automated CI publishing across 3000+ versions; rapid publish is normal for this monorepo. ai
dependencies unvetted-dep:@pnpm/list AI (dependencies): Known @pnpm ecosystem package; stable dependency for this package. ai
dependencies unvetted-dep:@pnpm/logger AI (dependencies): Known @pnpm ecosystem package; stable dependency for this package. ai
dependencies unvetted-dep:@pnpm/worker AI (dependencies): Known @pnpm ecosystem package; stable dependency for this package. ai
dependencies unvetted-dep:@teambit/harmony AI (dependencies): Known @teambit ecosystem package; stable dependency for this package. ai
dependencies unvetted-dep:@teambit/bit-error AI (dependencies): Known @teambit ecosystem package; stable dependency for this package. ai
dependencies unvetted-dep:credentials-by-uri AI (dependencies): Standard pnpm credential helper; expected dependency for a pnpm wrapper. ai
dependencies unvetted-dep:@pnpm/sort-packages AI (dependencies): Known @pnpm ecosystem package; stable dependency for this package. ai
dependencies unvetted-dep:@teambit/legacy.logger AI (dependencies): Known @teambit ecosystem package; stable dependency for this package. ai
dependencies unvetted-dep:@teambit/pkg.config.auth AI (dependencies): Known @teambit ecosystem package; stable dependency for this package. ai
dependencies unvetted-dep:@pnpm/core AI (dependencies): Known @pnpm ecosystem package; stable dependency for this package. ai
dependencies unvetted-dep:@teambit/ui-foundation.ui.use-box.menu AI (dependencies): Known @teambit ecosystem package; stable dependency for this package. ai
dependencies unvetted-dep:@teambit/harmony.modules.feature-toggle AI (dependencies): Known @teambit ecosystem package; stable dependency for this package. ai
dependencies unvetted-dep:@teambit/toolbox.string.strip-trailing-char AI (dependencies): Known @teambit ecosystem package; stable dependency for this package. ai
dependencies unvetted-dep:@pnpm/plugin-trusted-deps AI (dependencies): Known @pnpm ecosystem package; stable dependency for this package. ai
dependencies unvetted-dep:@teambit/legacy.constants AI (dependencies): Known @teambit ecosystem package; stable dependency for this package. ai
dependencies unvetted-dep:@pnpm/workspace.pkgs-graph AI (dependencies): Known @pnpm ecosystem package; stable dependency for this package. ai
dependencies unvetted-dep:@pnpm/plugin-commands-rebuild AI (dependencies): Known @pnpm ecosystem package; stable dependency for this package. ai
dependencies unvetted-dep:@teambit/pkg.entities.registry AI (dependencies): Known @teambit ecosystem package; stable dependency for this package. ai
dependencies unvetted-dep:@teambit/component-package-version AI (dependencies): Known @teambit ecosystem package; stable dependency for this package. ai
dependencies unvetted-dep:@teambit/dependencies.pnpm.dep-path AI (dependencies): Known @teambit ecosystem package; stable dependency for this package. ai
npm-metadata no-description AI (npm-metadata): Established @teambit/* ecosystem package; missing description is a consistent pattern across their packages, not a malware signal. ai
phantom-deps phantom-dep:@pnpm/package-store AI (phantom-deps): @pnpm/package-store is a legitimate declared dependency used indirectly; false positive for this package. ai
provenance no-provenance AI (provenance): Teambit publishes thousands of versions without provenance; consistent pattern, not a risk indicator. ai

Versions (showing 51 of 61)

View all versions
Version Deps Published
1.0.1106 46 / 7
1.0.1100 46 / 7
1.0.1099 46 / 7
1.0.1091 46 / 7
1.0.1060 46 / 7
1.0.1059 46 / 7
1.0.1054 46 / 7
1.0.1038 46 / 7
1.0.999 46 / 7
1.0.998 46 / 7
1.0.997 46 / 7
1.0.995 46 / 7
1.0.950 46 / 7
1.0.949 46 / 7
1.0.776 45 / 7
1.0.774 45 / 7
1.0.773 45 / 7
1.0.767 45 / 7
1.0.694 45 / 7
1.0.664 45 / 7
1.0.656 45 / 7
1.0.461 35 / 7
1.0.295 34 / 8
1.0.294 34 / 8
1.0.293 34 / 8
1.0.292 34 / 8
1.0.291 34 / 8
1.0.290 34 / 8
1.0.289 34 / 8
1.0.288 34 / 8
1.0.287 34 / 8
1.0.286 34 / 8
1.0.285 34 / 8
1.0.284 34 / 8
1.0.283 34 / 8
1.0.282 34 / 8
1.0.281 34 / 8
1.0.280 34 / 8
1.0.279 34 / 8
1.0.278 34 / 8
1.0.277 34 / 8
1.0.276 34 / 8
1.0.275 34 / 8
1.0.274 34 / 8
1.0.273 34 / 8
1.0.272 34 / 8
1.0.271 34 / 8
1.0.270 34 / 8
1.0.269 34 / 8
1.0.268 34 / 8
1.0.267 34 / 8

v1.0.1106

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1100

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1099

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1091

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.461

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.295

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.294

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.293

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.292

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.291

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.290

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.289

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.288

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.287

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.286

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.285

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.284

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.283

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.282

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.281

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.280

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.279

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.278

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.277

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.276

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.275

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.274

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.273

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.272

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.271

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.270

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.269

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.268

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.267

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.