← Home

@teambit/tester

85
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

teambit-ownershohamgiladdavidfirstranm8guysaaritaymendelerezbitjoshk2redigmayona007

Keywords

bitbit-aspectbit-core-aspectcomponentscollaborationweb

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
maintainer-change maintainer-removed AI (maintainer-change): Known publisher, monorepo maintainer churn is normal for teambit packages. ai
publish-pattern new-deps-added AI (publish-pattern): New dep is first-party @teambit package, consistent with monorepo pattern. ai
publish-pattern rapid-publish AI (publish-pattern): teambit publishes many coordinated packages simultaneously; rapid publish is a normal release pattern for this monorepo. ai
dependencies unvetted-dep:@teambit/toolbox.path.path AI (dependencies): First-party teambit scoped utility; consistent with the package's existing dependency pattern. ai
dependencies unvetted-dep:@teambit/defender.ui.test-compare AI (dependencies): First-party @teambit sub-package; same publisher ecosystem. ai
npm-metadata no-description AI (npm-metadata): Teambit component packages routinely omit descriptions; stable false positive for this package. ai
dependencies unvetted-dep:@teambit/defender.ui.test-compare-section AI (dependencies): First-party @teambit sub-package; same publisher ecosystem. ai
dependencies unvetted-dep:@teambit/evangelist.elements.icon AI (dependencies): First-party @teambit sub-package; same publisher ecosystem. ai
provenance no-provenance AI (provenance): Teambit publishes without Sigstore provenance; consistent across all versions. ai
dependencies unvetted-dep:@teambit/design.ui.pill-label AI (dependencies): First-party @teambit sub-package; same publisher ecosystem. ai
dependencies unvetted-dep:@teambit/defender.ui.test-page AI (dependencies): First-party @teambit sub-package; same publisher ecosystem. ai
dependencies unvetted-dep:@teambit/dev-files AI (dependencies): Sibling @teambit/* package from the same monorepo; structural false positive for this package. ai
dependencies unvetted-dep:@teambit/workspace AI (dependencies): Sibling @teambit/* package from the same monorepo; structural false positive for this package. ai
dependencies unvetted-dep:@teambit/component-id AI (dependencies): Sibling @teambit/* package from the same monorepo; structural false positive for this package. ai
dependencies unvetted-dep:@teambit/tests-results AI (dependencies): Sibling @teambit/* package from the same monorepo; structural false positive for this package. ai
dependencies unvetted-dep:@teambit/ui AI (dependencies): Sibling @teambit/* package from the same monorepo; structural false positive for this package. ai
dependencies unvetted-dep:@teambit/component-compare AI (dependencies): Sibling @teambit/* package from the same monorepo; structural false positive for this package. ai
dependencies unvetted-dep:@teambit/component.sources AI (dependencies): Sibling @teambit/* package from the same monorepo; structural false positive for this package. ai
dependencies unvetted-dep:@teambit/design.ui.tooltip AI (dependencies): Sibling @teambit/* package from the same monorepo; structural false positive for this package. ai
dependencies unvetted-dep:@teambit/toolbox.time.timer AI (dependencies): Sibling @teambit/* package from the same monorepo; structural false positive for this package. ai
dependencies unvetted-dep:@teambit/legacy.constants AI (dependencies): Sibling @teambit/* package from the same monorepo; structural false positive for this package. ai
dependencies unvetted-dep:@teambit/cli AI (dependencies): Sibling @teambit/* package from the same monorepo; structural false positive for this package. ai
dependencies unvetted-dep:@teambit/docs AI (dependencies): Sibling @teambit/* package from the same monorepo; structural false positive for this package. ai
dependencies unvetted-dep:@teambit/envs AI (dependencies): Sibling @teambit/* package from the same monorepo; structural false positive for this package. ai
dependencies unvetted-dep:@teambit/logger AI (dependencies): Sibling @teambit/* package from the same monorepo; structural false positive for this package. ai
dependencies unvetted-dep:@teambit/builder AI (dependencies): Sibling @teambit/* package from the same monorepo; structural false positive for this package. ai
dependencies unvetted-dep:@teambit/graphql AI (dependencies): Sibling @teambit/* package from the same monorepo; structural false positive for this package. ai
dependencies unvetted-dep:@teambit/harmony AI (dependencies): Sibling @teambit/* package from the same monorepo; structural false positive for this package. ai
dependencies unvetted-dep:@teambit/compiler AI (dependencies): Sibling @teambit/* package from the same monorepo; structural false positive for this package. ai
dependencies unvetted-dep:@teambit/bit-error AI (dependencies): Sibling @teambit/* package from the same monorepo; structural false positive for this package. ai
dependencies unvetted-dep:@teambit/component AI (dependencies): Sibling @teambit/* package from the same monorepo; structural false positive for this package. ai

Versions (showing 85 of 185)

Version Deps Published
1.0.355 29 / 7
1.0.354 29 / 7
1.0.353 29 / 7
1.0.352 29 / 7
1.0.351 29 / 7
1.0.349 29 / 7
1.0.345 29 / 7
1.0.342 29 / 7
1.0.340 29 / 7
1.0.337 29 / 7
1.0.331 28 / 7
1.0.330 27 / 7
1.0.329 27 / 7
1.0.328 27 / 7
1.0.327 27 / 7
1.0.326 27 / 7
1.0.325 27 / 7
1.0.324 27 / 7
1.0.323 27 / 7
1.0.322 27 / 7
1.0.321 27 / 7
1.0.320 27 / 7
1.0.319 27 / 7
1.0.318 27 / 7
1.0.317 27 / 7
1.0.316 27 / 7
1.0.315 27 / 7
1.0.314 27 / 7
1.0.313 27 / 7
1.0.312 27 / 7
1.0.311 27 / 7
1.0.310 27 / 7
1.0.309 27 / 7
1.0.308 27 / 7
1.0.307 27 / 7
1.0.306 27 / 7
1.0.305 27 / 7
1.0.304 27 / 7
1.0.303 27 / 7
1.0.302 27 / 7
1.0.301 27 / 7
1.0.300 27 / 7
1.0.299 27 / 7
1.0.298 27 / 7
1.0.297 27 / 7
1.0.296 27 / 7
1.0.295 27 / 7
1.0.294 27 / 7
1.0.293 27 / 7
1.0.292 27 / 7
1.0.291 27 / 7
1.0.290 27 / 7
1.0.289 27 / 7
1.0.288 27 / 7
1.0.287 27 / 7
1.0.286 27 / 7
1.0.285 27 / 7
1.0.284 27 / 7
1.0.283 27 / 7
1.0.282 27 / 7
1.0.281 27 / 7
1.0.280 27 / 7
1.0.279 27 / 7
1.0.278 27 / 7
1.0.277 27 / 7
1.0.276 27 / 7
1.0.275 27 / 7
1.0.274 27 / 7
1.0.273 27 / 7
1.0.272 27 / 7
1.0.271 27 / 7
1.0.270 27 / 7
1.0.269 27 / 7
1.0.268 27 / 7
1.0.267 27 / 7
1.0.266 27 / 7
1.0.265 27 / 7
1.0.264 27 / 7
1.0.263 27 / 7
1.0.262 27 / 7
1.0.261 27 / 7
1.0.260 27 / 7
1.0.259 27 / 7
1.0.258 27 / 7
1.0.257 27 / 7

v1.0.355

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.354

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.353

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.352

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.351

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.349

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.345

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.342

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.340

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.337

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.331

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.330

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.329

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.328

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.327

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.326

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.325

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.324

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.323

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.322

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.321

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.320

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.319

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.318

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.317

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.316

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.315

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.314

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.313

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.312

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.311

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.310

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.309

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.308

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.307

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.306

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.305

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.304

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.303

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.302

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.301

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.300

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.299

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.298

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.297

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.296

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.295

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.294

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.293

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.292

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.291

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.290

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.289

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.288

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.287

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.286

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.285

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.284

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.283

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.282

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.281

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.280

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.279

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.278

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.277

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.276

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.275

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.274

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.273

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.272

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.271

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.270

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.269

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.268

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.267

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.266

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.265

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.264

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.263

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.262

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.261

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.260

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: shohamgilad → davidfirst (on 2024-05-02, known maintainer) provenance

This version was published by a different npm account (davidfirst) than the most recent previously approved version (shohamgilad) on 2024-05-02, but davidfirst is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.259

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: shohamgilad → davidfirst (on 2024-05-01, known maintainer) provenance

This version was published by a different npm account (davidfirst) than the most recent previously approved version (shohamgilad) on 2024-05-01, but davidfirst is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.258

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.257

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.