@finos/legend-art
Legend shared visual components and component utilities
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:react-reflex | AI (dependencies): react-reflex is a standard React layout component; no malware indicators. | ai | |
| dependencies | unvetted-dep:@fontsource/ubuntu-mono | AI (dependencies): Fontsource packages are well-known font distribution libraries; no risk. | ai | |
| dependencies | unvetted-dep:@fontsource/roboto-serif | AI (dependencies): Fontsource packages are well-known font distribution libraries; no risk. | ai | |
| phantom-deps | phantom-dep:@fontsource/roboto | AI (phantom-deps): Font packages are CSS-only side-effect imports; not directly imported in JS. | ai | |
| phantom-deps | phantom-dep:@fontsource/raleway | AI (phantom-deps): Font packages are CSS-only side-effect imports; not directly imported in JS. | ai | |
| phantom-deps | phantom-dep:@types/react-window | AI (phantom-deps): Type-only package; stable false positive for this UI library. | ai | |
| phantom-deps | phantom-dep:@fontsource/roboto-mono | AI (phantom-deps): Font packages are CSS-only side-effect imports. | ai | |
| phantom-deps | phantom-dep:react-dom | AI (phantom-deps): UI component library; react-dom is a peer/framework dep loaded by convention, not directly imported. | ai | |
| phantom-deps | phantom-dep:@fontsource/roboto-serif | AI (phantom-deps): Font packages are CSS-only side-effect imports. | ai | |
| phantom-deps | phantom-dep:@fontsource/jetbrains-mono | AI (phantom-deps): Font packages are CSS-only side-effect imports. | ai | |
| phantom-deps | phantom-dep:@fontsource/roboto-condensed | AI (phantom-deps): Font packages are CSS-only side-effect imports. | ai | |
| phantom-deps | phantom-dep:@fontsource/ubuntu-mono | AI (phantom-deps): Font packages are CSS-only side-effect imports. | ai | |
| phantom-deps | phantom-dep:@types/react | AI (phantom-deps): Type-only package loaded by convention in TS projects; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@emotion/styled | AI (phantom-deps): MUI/emotion styling dep referenced in config; expected for a UI component library. | ai |
Versions (showing 51 of 131)
| Version | Deps | Published |
|---|---|---|
| 7.1.157 | 35 / 10 | |
| 7.1.156 | 35 / 10 | |
| 7.1.155 | 35 / 10 | |
| 7.1.154 | 35 / 10 | |
| 7.1.153 | 35 / 10 | |
| 7.1.152 | 35 / 10 | |
| 7.1.151 | 35 / 10 | |
| 7.1.150 | 35 / 10 | |
| 7.1.149 | 35 / 10 | |
| 7.1.148 | 35 / 10 | |
| 7.1.147 | 35 / 10 | |
| 7.1.146 | 35 / 10 | |
| 7.1.145 | 35 / 10 | |
| 7.1.144 | 35 / 10 | |
| 7.1.143 | 35 / 10 | |
| 7.1.142 | 35 / 10 | |
| 7.1.141 | 35 / 10 | |
| 7.1.140 | 35 / 10 | |
| 7.1.139 | 35 / 10 | |
| 7.1.138 | 35 / 10 | |
| 7.1.137 | 35 / 10 | |
| 7.1.136 | 35 / 10 | |
| 7.1.135 | 35 / 10 | |
| 7.1.134 | 35 / 10 | |
| 7.1.133 | 35 / 10 | |
| 7.1.132 | 35 / 10 | |
| 7.1.131 | 35 / 10 | |
| 7.1.130 | 35 / 10 | |
| 7.1.129 | 35 / 10 | |
| 7.1.128 | 35 / 10 | |
| 7.1.127 | 35 / 10 | |
| 7.1.126 | 35 / 10 | |
| 7.1.125 | 35 / 10 | |
| 7.1.124 | 35 / 10 | |
| 7.1.123 | 35 / 10 | |
| 7.1.122 | 35 / 10 | |
| 7.1.121 | 35 / 10 | |
| 7.1.120 | 35 / 10 | |
| 7.1.119 | 35 / 10 | |
| 7.1.118 | 35 / 10 | |
| 7.1.117 | 35 / 10 | |
| 7.1.116 | 35 / 10 | |
| 7.1.115 | 35 / 10 | |
| 7.1.114 | 35 / 10 | |
| 7.1.113 | 35 / 10 | |
| 7.1.112 | 35 / 10 | |
| 7.1.111 | 35 / 10 | |
| 7.1.110 | 35 / 10 | |
| 7.1.109 | 35 / 10 | |
| 7.1.108 | 35 / 10 | |
| 7.1.107 | 35 / 10 |
v7.1.157
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.1.156
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.1.155
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.1.145
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.1.144
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.1.143
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.1.142
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.1.141
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.1.140
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.1.139
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.1.138
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.1.137
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.1.136
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.1.135
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.1.134
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.1.133
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.1.132
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.1.131
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.1.130
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.