@teambit/tracker
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@teambit/toolbox.promise.map-pool | AI (dependencies): Same-org first-party monorepo dep, consistent with existing @teambit deps. | ai | |
| dependencies | unvetted-dep:@teambit/harmony.modules.concurrency | AI (dependencies): Same-org first-party monorepo dep, consistent with existing @teambit deps. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Reflects monorepo module split, no injected/obfuscated code found. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): First-party @teambit dep from same monorepo, benign pattern for this package. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): teambit uses automated CI releases across many packages simultaneously; rapid publish is normal for this publisher. | ai | |
| dependencies | unvetted-dep:array-difference | AI (dependencies): Legitimate utility dep in established teambit/bit monorepo package. | ai | |
| dependencies | unvetted-dep:@teambit/bit-error | AI (dependencies): Sibling @teambit/* dep; stable monorepo publishing pattern. | ai | |
| dependencies | unvetted-dep:@teambit/workspace | AI (dependencies): Sibling @teambit/* dep; stable monorepo publishing pattern. | ai | |
| dependencies | unvetted-dep:@teambit/component-id | AI (dependencies): Sibling @teambit/* dep; stable monorepo publishing pattern. | ai | |
| dependencies | unvetted-dep:@teambit/legacy.utils | AI (dependencies): Sibling @teambit/* dep; stable monorepo publishing pattern. | ai | |
| dependencies | unvetted-dep:@teambit/legacy-bit-id | AI (dependencies): Sibling @teambit/* dep; stable monorepo publishing pattern. | ai | |
| dependencies | unvetted-dep:@teambit/legacy.logger | AI (dependencies): Sibling @teambit/* dep; stable monorepo publishing pattern. | ai | |
| dependencies | unvetted-dep:firstline | AI (dependencies): Legitimate utility dep in established teambit/bit monorepo package. | ai | |
| dependencies | unvetted-dep:@teambit/legacy.consumer | AI (dependencies): Sibling @teambit/* dep; stable monorepo publishing pattern. | ai | |
| dependencies | unvetted-dep:@teambit/legacy.analytics | AI (dependencies): Sibling @teambit/* dep; stable monorepo publishing pattern. | ai | |
| dependencies | unvetted-dep:@teambit/legacy.constants | AI (dependencies): Sibling @teambit/* dep; stable monorepo publishing pattern. | ai | |
| dependencies | unvetted-dep:@teambit/workspace.modules.node-modules-linker | AI (dependencies): Sibling @teambit/* dep; stable monorepo publishing pattern. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Established monorepo component; missing description is a cosmetic issue, not a risk signal. | ai | |
| provenance | no-provenance | AI (provenance): Teambit publishes 2000+ versions without provenance; consistent pattern, not a risk signal. | ai | |
| dependencies | unvetted-dep:@teambit/legacy.bit-map | AI (dependencies): Sibling @teambit/* dep; stable monorepo publishing pattern. | ai | |
| dependencies | unvetted-dep:@teambit/cli | AI (dependencies): Sibling @teambit/* dep; stable monorepo publishing pattern. | ai | |
| dependencies | unvetted-dep:@teambit/envs | AI (dependencies): Sibling @teambit/* dep; stable monorepo publishing pattern. | ai | |
| dependencies | unvetted-dep:@teambit/logger | AI (dependencies): Sibling @teambit/* dep; stable monorepo publishing pattern. | ai | |
| dependencies | unvetted-dep:@teambit/harmony | AI (dependencies): Sibling @teambit/* dep; stable monorepo publishing pattern. | ai |
Versions (showing 51 of 117)
| Version | Deps | Published |
|---|---|---|
| 1.0.1066 | 25 / 4 | |
| 1.0.1064 | 23 / 4 | |
| 1.0.1060 | 23 / 4 | |
| 1.0.1054 | 23 / 4 | |
| 1.0.1021 | 23 / 4 | |
| 1.0.975 | 23 / 4 | |
| 1.0.972 | 23 / 4 | |
| 1.0.971 | 23 / 4 | |
| 1.0.970 | 23 / 4 | |
| 1.0.968 | 23 / 4 | |
| 1.0.955 | 23 / 4 | |
| 1.0.509 | 22 / 4 | |
| 1.0.456 | 19 / 4 | |
| 1.0.455 | 19 / 4 | |
| 1.0.447 | 19 / 4 | |
| 1.0.443 | 19 / 4 | |
| 1.0.441 | 19 / 4 | |
| 1.0.439 | 19 / 4 | |
| 1.0.436 | 19 / 4 | |
| 1.0.434 | 19 / 4 | |
| 1.0.433 | 19 / 4 | |
| 1.0.432 | 19 / 4 | |
| 1.0.430 | 19 / 4 | |
| 1.0.407 | 19 / 5 | |
| 1.0.405 | 19 / 5 | |
| 1.0.402 | 19 / 5 | |
| 1.0.400 | 19 / 5 | |
| 1.0.391 | 19 / 5 | |
| 1.0.389 | 19 / 5 | |
| 1.0.386 | 19 / 5 | |
| 1.0.385 | 19 / 5 | |
| 1.0.383 | 19 / 5 | |
| 1.0.381 | 19 / 5 | |
| 1.0.379 | 19 / 5 | |
| 1.0.371 | 19 / 5 | |
| 1.0.363 | 19 / 5 | |
| 1.0.357 | 19 / 5 | |
| 1.0.355 | 19 / 5 | |
| 1.0.354 | 19 / 5 | |
| 1.0.352 | 19 / 5 | |
| 1.0.350 | 19 / 5 | |
| 1.0.348 | 19 / 5 | |
| 1.0.345 | 19 / 5 | |
| 1.0.344 | 19 / 5 | |
| 1.0.340 | 19 / 5 | |
| 1.0.338 | 19 / 5 | |
| 1.0.336 | 19 / 5 | |
| 1.0.334 | 19 / 5 | |
| 1.0.332 | 19 / 5 | |
| 1.0.330 | 16 / 5 | |
| 1.0.329 | 16 / 5 |
v1.0.1066
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1064
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1060
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1054
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.509
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.456
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.455
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.447
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.443
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.441
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.439
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.436
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.434
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.433
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.432
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.430
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.407
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.405
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.402
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.400
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.391
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.389
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.386
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.385
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.383
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.381
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.379
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.371
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.363
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.357
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.355
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.354
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.352
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.350
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.348
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.345
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.344
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.340
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.338
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.336
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.334
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.332
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.330
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.329
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.