@teambit/ui-foundation.ui.side-bar
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | rapid-publish | AI (publish-pattern): Automated monorepo publishing cadence, not indicative of compromise. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): First-party @teambit dependency, typical of monorepo lockstep releases. | ai | |
| provenance | publisher-changed | AI (provenance): davidfirst is a long-standing trusted teambit publisher with 206 approved packages; transition is consistent with org maintainer rotation. | ai | |
| dependencies | unvetted-dep:@teambit/base-react.navigation.link | AI (dependencies): Same @teambit org scope; consistent with this package's dependency pattern across all versions. | ai | |
| phantom-deps | phantom-dep:@teambit/base-ui.theme.colors | AI (phantom-deps): Same org scope; declared but not directly imported is a common pattern in Bit component packages. | ai | |
| provenance | no-provenance | AI (provenance): teambit publishes without Sigstore provenance consistently; not a risk indicator for this publisher. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Established teambit component package; missing description is a consistent pattern across their 600+ versions. | ai |
Versions (showing 51 of 61)
| Version | Deps | Published |
|---|---|---|
| 0.0.945 | 18 / 9 | |
| 0.0.944 | 18 / 9 | |
| 0.0.943 | 18 / 9 | |
| 0.0.942 | 18 / 9 | |
| 0.0.941 | 18 / 9 | |
| 0.0.940 | 18 / 3 | |
| 0.0.939 | 17 / 4 | |
| 0.0.938 | 17 / 4 | |
| 0.0.937 | 17 / 4 | |
| 0.0.936 | 17 / 4 | |
| 0.0.935 | 16 / 3 | |
| 0.0.934 | 16 / 3 | |
| 0.0.933 | 16 / 3 | |
| 0.0.932 | 16 / 3 | |
| 0.0.931 | 16 / 3 | |
| 0.0.930 | 16 / 3 | |
| 0.0.929 | 16 / 3 | |
| 0.0.928 | 16 / 3 | |
| 0.0.927 | 16 / 3 | |
| 0.0.926 | 16 / 3 | |
| 0.0.925 | 16 / 3 | |
| 0.0.924 | 16 / 3 | |
| 0.0.923 | 16 / 3 | |
| 0.0.922 | 16 / 3 | |
| 0.0.921 | 16 / 3 | |
| 0.0.920 | 16 / 3 | |
| 0.0.919 | 16 / 3 | |
| 0.0.918 | 16 / 3 | |
| 0.0.917 | 16 / 3 | |
| 0.0.916 | 16 / 3 | |
| 0.0.915 | 16 / 3 | |
| 0.0.914 | 16 / 3 | |
| 0.0.913 | 16 / 3 | |
| 0.0.912 | 16 / 3 | |
| 0.0.911 | 16 / 3 | |
| 0.0.910 | 16 / 3 | |
| 0.0.909 | 17 / 3 | |
| 0.0.908 | 16 / 3 | |
| 0.0.906 | 16 / 3 | |
| 0.0.905 | 16 / 3 | |
| 0.0.904 | 16 / 3 | |
| 0.0.903 | 16 / 3 | |
| 0.0.902 | 16 / 3 | |
| 0.0.901 | 16 / 3 | |
| 0.0.900 | 16 / 3 | |
| 0.0.899 | 16 / 3 | |
| 0.0.898 | 16 / 3 | |
| 0.0.897 | 16 / 3 | |
| 0.0.896 | 16 / 3 | |
| 0.0.895 | 16 / 3 | |
| 0.0.894 | 16 / 3 |
v0.0.945
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.944
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.943
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.942
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.941
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.940
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.939
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.938
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.908
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (teambit-owner) than the most recent previously approved version (davidfirst) on 2025-04-16, but teambit-owner is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.0.906
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.905
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.904
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.903
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.902
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.901
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.900
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.899
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.898
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.897
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.896
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.895
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.894
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.