← Home

@teambit/webpack

5
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

teambit-ownershohamgiladdavidfirstranm8guysaaritaymendelerezbitjoshk2redigmayona007

Keywords

bitbit-aspectbit-core-aspectcomponentscollaborationweb

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@teambit/cli AI (dependencies): Core @teambit ecosystem dependency; consistent with package purpose across all versions. ai
dependencies unvetted-dep:expose-loader AI (dependencies): Standard webpack loader; expected dependency for this webpack aspect package. ai
dependencies unvetted-dep:@teambit/logger AI (dependencies): Core @teambit ecosystem dependency; stable across versions. ai
dependencies unvetted-dep:@teambit/pubsub AI (dependencies): Core @teambit ecosystem dependency; stable across versions. ai
dependencies unvetted-dep:@teambit/bundler AI (dependencies): Core @teambit ecosystem dependency; stable across versions. ai
dependencies unvetted-dep:@teambit/harmony AI (dependencies): Core @teambit ecosystem dependency; stable across versions. ai
dependencies unvetted-dep:@teambit/bit-error AI (dependencies): Core @teambit ecosystem dependency; stable across versions. ai
dependencies unvetted-dep:@teambit/workspace AI (dependencies): Core @teambit ecosystem dependency; stable across versions. ai
dependencies unvetted-dep:webpack-assets-manifest AI (dependencies): Standard webpack plugin; expected dependency for this package. ai
dependencies unvetted-dep:@teambit/toolbox.path.path AI (dependencies): Core @teambit ecosystem utility; stable across versions. ai
dependencies unvetted-dep:inject-body-webpack-plugin AI (dependencies): Standard webpack plugin; expected dependency for this package. ai
dependencies unvetted-dep:@teambit/webpack.modules.config-mutator AI (dependencies): Core @teambit/webpack sub-module; stable across versions. ai
dependencies unvetted-dep:@teambit/webpack.modules.generate-externals AI (dependencies): Core @teambit/webpack sub-module; stable across versions. ai
dependencies unvetted-dep:@teambit/preview.cli.dev-server-events-listener AI (dependencies): Core @teambit ecosystem dependency; stable across versions. ai
dependencies unvetted-dep:@teambit/webpack.modules.generate-expose-loaders AI (dependencies): Core @teambit/webpack sub-module; stable across versions. ai
dependencies unvetted-dep:@teambit/webpack.plugins.inject-head-webpack-plugin AI (dependencies): Core @teambit/webpack sub-module; stable across versions. ai
npm-metadata no-description AI (npm-metadata): Established package with homepage and keywords; missing description is cosmetic for this ecosystem. ai
provenance no-provenance AI (provenance): Long-established package predating provenance attestation; no provenance is expected for this publisher. ai

Versions (showing 5 of 5)

Version Deps Published
1.0.972 48 / 5
1.0.971 48 / 5
1.0.970 48 / 5
1.0.968 48 / 5
1.0.925 48 / 5

v1.0.972

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.971

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.970

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.925

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.