@teambit/sign
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@teambit/scope.objects | AI (dependencies): Same-org internal Teambit package, part of routine monorepo dependency split. | ai | |
| dependencies | unvetted-dep:@teambit/scope.remotes | AI (dependencies): Same-org internal Teambit package, part of routine monorepo dependency split. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Established internal package; missing description is stable pattern. | ai | |
| provenance | no-provenance | AI (provenance): Monorepo package; provenance adoption is org-level decision, not per-package risk. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New deps are first-party @teambit packages, part of monorepo refactor. | ai | |
| dependencies | unvetted-dep:@teambit/harmony.modules.get-basic-log | AI (dependencies): First-party @teambit monorepo dep. | ai | |
| dependencies | unvetted-dep:@teambit/harmony.modules.feature-toggle | AI (dependencies): First-party @teambit monorepo dep. | ai | |
| dependencies | unvetted-dep:@teambit/scope.network | AI (dependencies): First-party @teambit monorepo dep, lockstep versioned with this package. | ai | |
| phantom-deps | phantom-dep:@teambit/legacy.consumer-component | AI (phantom-deps): Same-org scope dep, likely used indirectly; heuristic false positive. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Artifact of sparse registry import history for a high-frequency lockstep release train. | ai | |
| dependencies | unvetted-dep:@teambit/legacy.constants | AI (dependencies): First-party @teambit monorepo dep. | ai | |
| dependencies | unvetted-dep:@teambit/bit.get-bit-version | AI (dependencies): First-party @teambit monorepo dep. | ai | |
| dependencies | unvetted-dep:@teambit/scope.remote-actions | AI (dependencies): First-party @teambit monorepo dep. | ai | |
| dependencies | unvetted-dep:@teambit/legacy.consumer-component | AI (dependencies): First-party @teambit monorepo dep. | ai |
Versions (showing 18 of 18)
| Version | Deps | Published |
|---|---|---|
| 1.0.580 | 23 / 2 | |
| 1.0.576 | 23 / 2 | |
| 1.0.528 | 22 / 2 | |
| 1.0.500 | 23 / 2 | |
| 1.0.497 | 23 / 2 | |
| 1.0.473 | 17 / 2 | |
| 1.0.458 | 17 / 2 | |
| 1.0.457 | 17 / 2 | |
| 1.0.429 | 17 / 2 | |
| 1.0.422 | 17 / 2 | |
| 1.0.399 | 17 / 3 | |
| 1.0.342 | 16 / 3 | |
| 1.0.341 | 16 / 3 | |
| 1.0.339 | 16 / 3 | |
| 1.0.336 | 16 / 3 | |
| 1.0.335 | 16 / 3 | |
| 1.0.334 | 16 / 3 | |
| 1.0.259 | 14 / 3 |
v1.0.580
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.576
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.528
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.500
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.497
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.473
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.458
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.457
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.429
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.422
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.399
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.342
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.341
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.339
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.336
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.335
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.334
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.259
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.