← Home

@finos/legend-extension-dsl-diagram

Legend extension for Diagram DSL

51
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

finos-adminmaoo

Keywords

legendlegend-extensiondsldsl-diagram

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:serializr AI (dependencies): serializr is a well-known serialization library; stable legitimate dependency for this package. ai
phantom-deps phantom-dep:react-dnd AI (phantom-deps): Declared runtime dep used transitively in UI components; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:react-dom AI (phantom-deps): Standard React ecosystem dep declared for peer/transitive use; stable false positive. ai
phantom-deps phantom-dep:@types/react AI (phantom-deps): Framework-scoped type package; convention-loaded, not directly imported. ai
phantom-deps phantom-dep:@finos/legend-storage AI (phantom-deps): Same-org monorepo sibling; phantom-dep heuristic unreliable for monorepo packages. ai
phantom-deps phantom-dep:@finos/legend-code-editor AI (phantom-deps): Same-org monorepo sibling; phantom-dep heuristic unreliable for monorepo packages. ai

Versions (showing 51 of 469)

View all versions
Version Deps Published
8.1.255 13 / 11
8.1.254 13 / 11
8.1.253 13 / 11
8.1.252 13 / 11
8.1.251 13 / 11
8.1.250 13 / 11
8.1.249 13 / 11
8.1.248 13 / 11
8.1.247 13 / 11
8.1.246 13 / 11
8.1.245 13 / 11
8.1.244 13 / 11
8.1.243 13 / 11
8.1.242 13 / 11
8.1.241 13 / 11
8.1.240 13 / 11
8.1.239 13 / 11
8.1.238 13 / 11
8.1.237 13 / 11
8.1.236 13 / 11
8.1.235 13 / 11
8.1.234 13 / 11
8.1.233 13 / 11
8.1.232 13 / 11
8.1.231 13 / 11
8.1.230 13 / 11
8.1.229 13 / 11
8.1.228 13 / 11
8.1.227 13 / 11
8.1.226 13 / 11
8.1.225 13 / 11
8.1.224 13 / 11
8.1.223 13 / 11
8.1.222 13 / 11
8.1.221 13 / 11
8.1.220 13 / 11
8.1.219 13 / 11
8.1.218 13 / 11
8.1.217 13 / 11
8.1.216 13 / 11
8.1.215 13 / 11
8.1.214 13 / 11
8.1.213 13 / 11
8.1.211 13 / 11
8.1.210 13 / 11
8.1.209 13 / 11
8.1.208 13 / 11
8.1.207 13 / 11
8.1.206 13 / 11
8.1.205 13 / 11
8.1.204 13 / 11

v8.1.255

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.1.254

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.1.253

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.1.252

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.1.251

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.1.250

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.1.249

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.1.248

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.1.247

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.1.246

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.