← Home

@teambit/webpack

51
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

teambit-ownershohamgiladdavidfirstranm8guysaaritaymendelerezbitjoshk2redigmayona007

Keywords

bitbit-aspectbit-core-aspectcomponentscollaborationweb

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern new-deps-added AI (publish-pattern): First-party @teambit sibling dep, normal for this monorepo's lockstep releases. ai
publish-pattern rapid-publish AI (publish-pattern): teambit/bit monorepo publishes many packages in rapid succession via CI automation; stable pattern across 3000+ versions. ai
dependencies unvetted-dep:@teambit/logger AI (dependencies): Core @teambit ecosystem dependency; stable across versions. ai
dependencies unvetted-dep:@teambit/pubsub AI (dependencies): Core @teambit ecosystem dependency; stable across versions. ai
dependencies unvetted-dep:@teambit/bundler AI (dependencies): Core @teambit ecosystem dependency; stable across versions. ai
dependencies unvetted-dep:@teambit/harmony AI (dependencies): Core @teambit ecosystem dependency; stable across versions. ai
dependencies unvetted-dep:@teambit/bit-error AI (dependencies): Core @teambit ecosystem dependency; stable across versions. ai
dependencies unvetted-dep:@teambit/workspace AI (dependencies): Core @teambit ecosystem dependency; stable across versions. ai
dependencies unvetted-dep:webpack-assets-manifest AI (dependencies): Standard webpack plugin; expected dependency for this package. ai
dependencies unvetted-dep:@teambit/toolbox.path.path AI (dependencies): Core @teambit ecosystem utility; stable across versions. ai
dependencies unvetted-dep:@teambit/cli AI (dependencies): Core @teambit ecosystem dependency; consistent with package purpose across all versions. ai
dependencies unvetted-dep:@teambit/webpack.modules.config-mutator AI (dependencies): Core @teambit/webpack sub-module; stable across versions. ai
dependencies unvetted-dep:@teambit/webpack.modules.generate-externals AI (dependencies): Core @teambit/webpack sub-module; stable across versions. ai
dependencies unvetted-dep:@teambit/preview.cli.dev-server-events-listener AI (dependencies): Core @teambit ecosystem dependency; stable across versions. ai
dependencies unvetted-dep:@teambit/webpack.modules.generate-expose-loaders AI (dependencies): Core @teambit/webpack sub-module; stable across versions. ai
dependencies unvetted-dep:@teambit/webpack.plugins.inject-head-webpack-plugin AI (dependencies): Core @teambit/webpack sub-module; stable across versions. ai
npm-metadata no-description AI (npm-metadata): Established package with homepage and keywords; missing description is cosmetic for this ecosystem. ai
provenance no-provenance AI (provenance): Long-established package predating provenance attestation; no provenance is expected for this publisher. ai
dependencies unvetted-dep:inject-body-webpack-plugin AI (dependencies): Standard webpack plugin; expected dependency for this package. ai
dependencies unvetted-dep:expose-loader AI (dependencies): Standard webpack loader; expected dependency for this webpack aspect package. ai

Versions (showing 51 of 87)

View all versions
Version Deps Published
1.0.1064 48 / 5
1.0.1060 48 / 5
1.0.1021 48 / 5
1.0.1018 48 / 5
1.0.996 48 / 5
1.0.972 48 / 5
1.0.971 48 / 5
1.0.970 48 / 5
1.0.968 48 / 5
1.0.925 48 / 5
1.0.870 48 / 5
1.0.488 48 / 5
1.0.331 47 / 7
1.0.330 46 / 7
1.0.329 46 / 7
1.0.328 46 / 7
1.0.327 46 / 7
1.0.326 46 / 7
1.0.325 46 / 7
1.0.324 46 / 7
1.0.323 46 / 7
1.0.322 46 / 7
1.0.321 46 / 7
1.0.320 45 / 7
1.0.319 45 / 7
1.0.318 45 / 7
1.0.317 45 / 7
1.0.316 45 / 7
1.0.315 45 / 7
1.0.314 45 / 7
1.0.313 45 / 7
1.0.312 45 / 7
1.0.311 45 / 7
1.0.310 45 / 7
1.0.309 45 / 7
1.0.308 45 / 7
1.0.307 45 / 7
1.0.306 45 / 7
1.0.305 45 / 7
1.0.304 45 / 7
1.0.303 45 / 7
1.0.302 45 / 7
1.0.301 45 / 7
1.0.300 45 / 7
1.0.299 45 / 7
1.0.298 45 / 7
1.0.297 45 / 7
1.0.296 45 / 7
1.0.295 45 / 7
1.0.294 45 / 7
1.0.293 45 / 7

v1.0.1064

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1060

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.488

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: davidfirst → shohamgilad (on 2024-12-10, known maintainer) provenance

This version was published by a different npm account (shohamgilad) than the most recent previously approved version (davidfirst) on 2024-12-10, but shohamgilad is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.331

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.330

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.329

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.328

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.327

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.326

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.325

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.324

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.323

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.322

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.321

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.320

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.319

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.318

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.317

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.316

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.315

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.314

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.313

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.312

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.311

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.310

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.309

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.308

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.307

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.306

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.305

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.304

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.303

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.302

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.301

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.300

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.299

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.298

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.297

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.296

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.295

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.294

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.293

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.