@teambit/worker
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): davidfirst is an established Teambit publisher with 178 approvals; transition from teambit-owner appears to be a routine org account change. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Teambit packages consistently omit descriptions; stable pattern across 1691 versions. | ai | |
| provenance | no-provenance | AI (provenance): Teambit's automated publishing pipeline does not use Sigstore provenance; consistent across all versions. | ai |
Versions (showing 51 of 473)
| Version | Deps | Published |
|---|---|---|
| 0.0.1660 | 3 / 2 | |
| 0.0.1659 | 3 / 2 | |
| 0.0.1658 | 3 / 2 | |
| 0.0.1657 | 3 / 2 | |
| 0.0.1656 | 3 / 2 | |
| 0.0.1655 | 3 / 2 | |
| 0.0.1654 | 3 / 2 | |
| 0.0.1653 | 3 / 2 | |
| 0.0.1652 | 3 / 2 | |
| 0.0.1651 | 3 / 2 | |
| 0.0.1650 | 3 / 2 | |
| 0.0.1649 | 3 / 2 | |
| 0.0.1648 | 3 / 2 | |
| 0.0.1647 | 3 / 2 | |
| 0.0.1646 | 3 / 2 | |
| 0.0.1645 | 3 / 2 | |
| 0.0.1644 | 3 / 2 | |
| 0.0.1643 | 3 / 2 | |
| 0.0.1642 | 3 / 2 | |
| 0.0.1641 | 3 / 2 | |
| 0.0.1640 | 3 / 2 | |
| 0.0.1639 | 3 / 2 | |
| 0.0.1638 | 3 / 2 | |
| 0.0.1637 | 3 / 2 | |
| 0.0.1636 | 3 / 2 | |
| 0.0.1635 | 3 / 2 | |
| 0.0.1634 | 3 / 2 | |
| 0.0.1633 | 3 / 2 | |
| 0.0.1632 | 3 / 2 | |
| 0.0.1631 | 3 / 2 | |
| 0.0.1630 | 3 / 2 | |
| 0.0.1629 | 3 / 2 | |
| 0.0.1628 | 3 / 2 | |
| 0.0.1627 | 3 / 2 | |
| 0.0.1626 | 3 / 2 | |
| 0.0.1625 | 3 / 2 | |
| 0.0.1624 | 3 / 2 | |
| 0.0.1623 | 3 / 2 | |
| 0.0.1622 | 3 / 2 | |
| 0.0.1621 | 3 / 2 | |
| 0.0.1620 | 3 / 2 | |
| 0.0.1619 | 3 / 2 | |
| 0.0.1618 | 3 / 2 | |
| 0.0.1617 | 3 / 2 | |
| 0.0.1616 | 3 / 2 | |
| 0.0.1615 | 3 / 2 | |
| 0.0.1614 | 3 / 2 | |
| 0.0.1613 | 3 / 2 | |
| 0.0.1612 | 3 / 2 | |
| 0.0.1611 | 3 / 2 | |
| 0.0.1610 | 3 / 2 |
v0.0.1660
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1659
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1658
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1657
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1656
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1655
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1654
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1653
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1652
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1651
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1650
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1649
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.