← Home

@finos/legend-application-marketplace

Legend Marketplace application core

51
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

finos-adminmaootexodusneil.slinger

Keywords

legendlegend-applicationlegend-marketplacesearchdiscovery

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@types/react AI (phantom-deps): Framework-scoped type package loaded by convention in React projects. ai
phantom-deps phantom-dep:@types/react-dom AI (phantom-deps): Framework-scoped type package loaded by convention in React projects. ai
dependencies unvetted-dep:@finos/legend-art AI (dependencies): Sibling FINOS legend-studio monorepo package; stable across versions. ai
dependencies unvetted-dep:@finos/legend-lego AI (dependencies): Sibling FINOS legend-studio monorepo package; stable across versions. ai
dependencies unvetted-dep:react-oidc-context AI (dependencies): Standard OIDC React library; legitimate dependency. ai
dependencies unvetted-dep:@finos/legend-graph AI (dependencies): Sibling FINOS legend-studio monorepo package; stable across versions. ai
dependencies unvetted-dep:@finos/legend-shared AI (dependencies): Sibling FINOS legend-studio monorepo package; stable across versions. ai
dependencies unvetted-dep:@finos/legend-storage AI (dependencies): Sibling FINOS legend-studio monorepo package; stable across versions. ai
dependencies unvetted-dep:@finos/legend-application AI (dependencies): Sibling FINOS legend-studio monorepo package; stable across versions. ai
dependencies unvetted-dep:@finos/legend-code-editor AI (dependencies): Sibling FINOS legend-studio monorepo package; stable across versions. ai
dependencies unvetted-dep:@finos/legend-server-depot AI (dependencies): Sibling FINOS legend-studio monorepo package; stable across versions. ai
dependencies unvetted-dep:serializr AI (dependencies): Well-known serialization library; no advisories, legitimate dependency for this FINOS package. ai
dependencies unvetted-dep:@finos/legend-server-marketplace AI (dependencies): Sibling FINOS legend-studio monorepo package; stable across versions. ai
dependencies unvetted-dep:@finos/legend-extension-dsl-data-space AI (dependencies): Sibling FINOS legend-studio monorepo package; stable across versions. ai
dependencies unvetted-dep:@finos/legend-extension-dsl-data-product AI (dependencies): Sibling FINOS legend-studio monorepo package; stable across versions. ai
phantom-deps phantom-dep:yaml AI (phantom-deps): Config-file reference pattern; false positive for monorepo build tooling. ai
phantom-deps phantom-dep:dompurify AI (phantom-deps): Config-file reference pattern; false positive for monorepo build tooling. ai
phantom-deps phantom-dep:react-dnd AI (phantom-deps): Config-file reference pattern; false positive for monorepo build tooling. ai
phantom-deps phantom-dep:mobx-utils AI (phantom-deps): Config-file reference pattern; false positive for monorepo build tooling. ai
phantom-deps phantom-dep:node-diff3 AI (phantom-deps): Config-file reference pattern; false positive for monorepo build tooling. ai
dependencies unvetted-dep:@finos/legend-server-lakehouse AI (dependencies): Sibling FINOS legend-studio monorepo package; stable across versions. ai
dependencies unvetted-dep:node-diff3 AI (dependencies): Standard diff library; legitimate dependency for this FINOS package. ai

Versions (showing 51 of 111)

View all versions
Version Deps Published
0.2.20 30 / 10
0.2.19 30 / 10
0.2.17 30 / 10
0.2.16 30 / 10
0.2.15 30 / 10
0.2.14 30 / 10
0.2.13 30 / 10
0.2.12 30 / 10
0.2.11 30 / 10
0.2.10 30 / 10
0.2.9 30 / 10
0.2.8 30 / 10
0.2.7 30 / 10
0.2.6 30 / 10
0.2.5 30 / 10
0.2.4 30 / 10
0.2.3 30 / 10
0.2.2 30 / 10
0.2.1 30 / 10
0.2.0 30 / 10
0.1.85 30 / 10
0.1.84 30 / 10
0.1.30 31 / 9
0.1.29 31 / 9
0.1.28 31 / 9
0.1.27 31 / 9
0.1.26 31 / 9
0.1.25 31 / 9
0.1.24 31 / 9
0.1.23 31 / 9
0.1.22 31 / 9
0.1.21 31 / 9
0.1.20 31 / 9
0.1.19 31 / 9
0.1.18 31 / 9
0.1.17 31 / 9
0.1.16 31 / 9
0.1.15 31 / 9
0.1.14 31 / 9
0.1.13 30 / 9
0.1.12 29 / 9
0.1.11 29 / 9
0.1.10 29 / 9
0.1.9 28 / 9
0.1.8 28 / 9
0.1.7 28 / 9
0.1.6 28 / 9
0.1.5 28 / 9
0.1.4 28 / 9
0.1.3 28 / 9
0.1.2 28 / 9

v0.2.20

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.19

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.16

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.85

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.84

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.30

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.29

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.28

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.27

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.26

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.25

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.24

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.23

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.22

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.21

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.20

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.19

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.18

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.16

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.