← Home

@finos/legend-extension-dsl-service

Legend extension for Service DSL

100
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

finos-adminmaoo

Keywords

legendlegend-extensiondsldsl-service

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:serializr AI (dependencies): serializr is a legitimate, widely-used serialization library; stable dependency for this package. ai
phantom-deps phantom-dep:serializr AI (phantom-deps): serializr is a declared runtime dep; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:@types/react AI (phantom-deps): Framework-scoped type package; convention-loaded, stable false positive for this package. ai
provenance no-provenance AI (provenance): Established FINOS org package; lack of Sigstore provenance is consistent across all 533 versions. ai

Versions (showing 100 of 492)

Version Deps Published
1.0.394 18 / 9
1.0.393 18 / 9
1.0.392 18 / 9
1.0.391 18 / 9
1.0.390 18 / 9
1.0.389 18 / 9
1.0.388 18 / 9
1.0.387 18 / 9
1.0.386 18 / 9
1.0.385 18 / 9
1.0.384 18 / 9
1.0.383 18 / 9
1.0.382 18 / 9
1.0.381 18 / 9
1.0.380 18 / 9
1.0.379 18 / 9
1.0.378 18 / 9
1.0.377 18 / 9
1.0.376 18 / 9
1.0.375 18 / 9
1.0.374 18 / 9
1.0.373 18 / 9
1.0.372 18 / 9
1.0.371 18 / 9
1.0.370 18 / 9
1.0.369 18 / 9
1.0.368 18 / 9
1.0.367 18 / 9
1.0.366 18 / 9
1.0.365 18 / 9
1.0.364 18 / 9
1.0.363 18 / 9
1.0.362 18 / 9
1.0.361 18 / 9
1.0.360 18 / 9
1.0.359 18 / 9
1.0.358 18 / 9
1.0.357 18 / 9
1.0.356 18 / 9
1.0.355 18 / 9
1.0.354 18 / 9
1.0.353 18 / 9
1.0.352 18 / 9
1.0.351 18 / 9
1.0.350 18 / 9
1.0.349 18 / 9
1.0.348 18 / 9
1.0.347 18 / 9
1.0.346 18 / 9
1.0.345 18 / 9
1.0.344 18 / 9
1.0.343 18 / 9
1.0.342 18 / 9
1.0.341 18 / 9
1.0.340 18 / 9
1.0.339 18 / 9
1.0.338 18 / 9
1.0.337 18 / 9
1.0.336 18 / 9
1.0.335 18 / 9
1.0.334 18 / 9
1.0.333 18 / 9
1.0.332 18 / 9
1.0.331 18 / 9
1.0.330 18 / 9
1.0.329 18 / 9
1.0.328 18 / 9
1.0.327 18 / 9
1.0.326 18 / 9
1.0.325 18 / 9
1.0.324 18 / 9
1.0.323 18 / 9
1.0.322 18 / 9
1.0.321 18 / 9
1.0.320 18 / 9
1.0.319 18 / 9
1.0.318 18 / 9
1.0.317 18 / 9
1.0.316 18 / 9
1.0.315 18 / 9
1.0.314 18 / 9
1.0.313 18 / 9
1.0.312 18 / 9
1.0.311 18 / 9
1.0.310 18 / 9
1.0.309 18 / 9
1.0.308 18 / 9
1.0.307 18 / 9
1.0.306 18 / 9
1.0.305 18 / 9
1.0.304 18 / 9
1.0.303 18 / 9
1.0.302 18 / 9
1.0.301 18 / 9
1.0.300 18 / 9
1.0.299 18 / 9
1.0.298 18 / 9
1.0.297 18 / 9
1.0.296 18 / 9
1.0.295 18 / 9
Showing 100 of 492 Next page →

v1.0.316

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.315

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.314

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.313

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.312

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.311

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.310

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.309

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.308

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.307

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.306

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.305

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.304

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.303

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.302

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.301

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.300

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.299

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.298

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.297

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.296

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.295

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.