← Home

@teambit/workspace.modules.node-modules-linker

41
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

teambit-ownershohamgiladdavidfirstranm8guysaaritaymendelerezbitjoshk2redigmayona007

Keywords

bitcomponentscollaborationwebreactreact-componentsangularangular-components

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
maintainer-change maintainer-removed AI (maintainer-change): Teambit org package with strong publisher track record; maintainer rotation is routine for this org. ai
dependencies unvetted-dep:@teambit/legacy.utils AI (dependencies): Internal teambit monorepo package from verified publisher; stable false positive. ai
dependencies unvetted-dep:@teambit/legacy.logger AI (dependencies): Internal teambit monorepo package from verified publisher; stable false positive. ai
dependencies unvetted-dep:@teambit/legacy.bit-map AI (dependencies): Internal teambit monorepo package from verified publisher; stable false positive. ai
dependencies unvetted-dep:@teambit/legacy.consumer AI (dependencies): Internal teambit monorepo package from verified publisher; stable false positive. ai
dependencies unvetted-dep:@teambit/legacy.constants AI (dependencies): Internal teambit monorepo package from verified publisher; stable false positive. ai
dependencies unvetted-dep:@teambit/workspace.root-components AI (dependencies): Internal teambit monorepo package from verified publisher; stable false positive. ai
dependencies unvetted-dep:@teambit/pkg.modules.component-package-name AI (dependencies): Internal teambit monorepo package from verified publisher; stable false positive. ai
dependencies unvetted-dep:@teambit/component.sources AI (dependencies): Internal teambit monorepo package from verified publisher; stable false positive. ai
dependencies unvetted-dep:@teambit/toolbox.path.path AI (dependencies): Internal teambit monorepo package from verified publisher; stable false positive. ai
dependencies unvetted-dep:@teambit/legacy.consumer-component AI (dependencies): Internal teambit monorepo package from verified publisher; stable false positive. ai
npm-metadata no-description AI (npm-metadata): Teambit publishes many scoped internal packages without descriptions; stable pattern across versions. ai
provenance no-provenance AI (provenance): Teambit does not use Sigstore provenance; consistent across all their packages. ai

Versions (showing 41 of 41)

Version Deps Published
0.0.348 16 / 5
0.0.347 16 / 5
0.0.346 16 / 5
0.0.345 16 / 5
0.0.343 16 / 5
0.0.342 16 / 5
0.0.341 16 / 5
0.0.340 16 / 5
0.0.338 16 / 5
0.0.337 16 / 5
0.0.336 16 / 5
0.0.335 16 / 5
0.0.334 16 / 5
0.0.333 16 / 5
0.0.330 16 / 5
0.0.327 16 / 5
0.0.321 16 / 5
0.0.319 16 / 5
0.0.314 16 / 5
0.0.310 16 / 5
0.0.308 16 / 5
0.0.306 16 / 5
0.0.304 16 / 5
0.0.302 16 / 5
0.0.301 16 / 5
0.0.300 16 / 5
0.0.299 16 / 5
0.0.298 16 / 5
0.0.297 16 / 5
0.0.293 16 / 5
0.0.292 16 / 5
0.0.291 16 / 5
0.0.290 16 / 5
0.0.289 16 / 5
0.0.288 16 / 5
0.0.287 16 / 5
0.0.285 16 / 5
0.0.282 16 / 5
0.0.280 16 / 5
0.0.279 16 / 5
0.0.278 16 / 5

v0.0.348

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.347

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.346

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.345

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.343

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.342

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.335

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.333

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.330

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.327

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.321

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.319

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.314

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.310

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.308

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.306

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.304

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.302

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.301

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.300

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.299

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.298

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.297

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.293

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.292

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.291

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.290

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.289

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.288

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.287

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.285

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.282

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.280

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.279

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.278

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.